Tag
critical
advisory
Pachno 1.0.6 XML External Entity Injection Vulnerability
2 rules 2 TTPs 1 CVE 1 IOCPachno 1.0.6 is vulnerable to XML external entity injection, allowing unauthenticated attackers to read arbitrary files by injecting malicious XML entities into wiki content due to unsafe XML parsing in the TextParser helper.
xxe
cve-2026-40042
pachno
web-application
2r
2t
1c
1i
medium
advisory
Pachno 1.0.6 Stored Cross-Site Scripting Vulnerability
2 rules 1 TTP 1 CVEPachno 1.0.6 is vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious HTML or scripts into POST parameters, which are then stored and executed in user browser sessions due to improper sanitization.
Pachno
xss
web-application
2r
1t
1c