Skip to content
Threat Feed

CPE

Cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*

5 briefs RSS
medium advisory

Information Disclosure Vulnerability in Gitea

A vulnerability in Gitea allows a remote, unauthenticated attacker to exploit an information disclosure flaw, potentially exposing sensitive repository or system data.

Gitea
1t 1c
high advisory

Remote Code Execution in Craft CMS via HMAC Signature Misuse

Craft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a critical vulnerability allowing authenticated users to achieve remote code execution by injecting malicious payloads into improperly validated redirect parameters.

PoC Craft CMS +1 cve authorization graphql web-vulnerability
3t 2c updated
medium advisory

Information Disclosure Vulnerability in MISP

An authenticated remote attacker can exploit a vulnerability in MISP to gain unauthorized access to sensitive information due to improper access controls.

MISP
1t 1c
high advisory

Authorization Bypass in Craft CMS assets/move-asset Endpoint

Craft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.

Craft CMS +3 cms web-vulnerability authorization-bypass web-application vulnerability privilege-escalation web-application-vulnerability rce +1
2r 4t 1c updated
critical threat

iCagenda Unrestricted File Upload Vulnerability Leading to RCE (CVE-2026-48939)

Attackers are actively exploiting CVE-2026-48939, an unrestricted file upload vulnerability in iCagenda, to upload malicious PHP code and achieve remote code execution on affected web servers.

exploited PoC iCagenda +19 web-application rce file-upload cve
1r 2t 5c 7i updated