Tag
CVE-2026-92807: Arbitrary Function Invocation in Save as PDF Plugin for WordPress
1 rule 1 TTP 1 CVEThe Save as PDF Plugin for WordPress up to version 4.6.1 is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated Contributor-level users to trigger sensitive data disclosure.
Unauthenticated SQL Injection in Chanjet CRM (CVE-2021-48008)
1 rule 1 TTP 1 CVEChanjet CRM contains an unauthenticated SQL injection vulnerability in the webservice endpoint, enabling remote attackers to extract sensitive data via the site_id parameter.
Unauthenticated SQL Injection in Weaver E-cology
1 rule 2 TTPs 1 CVEWeaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.
SQL Injection in Location Manager Plugin for WordPress
1 rule 1 TTP 1 CVEThe Location Manager plugin for WordPress is vulnerable to unauthenticated SQL injection via REST API parameters, allowing remote attackers to extract sensitive database information.
Grav Privilege Escalation via Group Blueprint ACL Bypass
1 rule 3 TTPs 1 CVEA missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.
Remote Code Execution in SiYuan via Malicious Bookmark Labels
1 rule 5 TTPs 1 CVESiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.
Authorization Bypass in metasfresh DocumentAttachmentsRestController and CommentsRestController
1 TTPAuthenticated attackers can exploit improper record-level authorization checks in metasfresh ERP to perform unauthorized read, write, and delete operations on attachments and comments.
CVE-2026-90937 Configuration Injection in Froxlor
1 TTP 1 CVEFroxlor versions before 2.2.5 contain a vulnerability allowing authenticated users to inject arbitrary Nginx or Apache configuration directives via unvalidated newline characters in subdomain redirect URLs.
SQL Injection in Sticky Chat Widget WordPress Plugin
1 rule 1 TTP 1 CVEThe Sticky Chat Widget plugin for WordPress (<= 1.4.2) is vulnerable to unauthenticated SQL injection via the 'scw_save_form_data' AJAX action, allowing potential exfiltration of sensitive database information.
Authentication Bypass in Newfold WordPress Plugins via wp-module-data
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in the wp-module-data library used by multiple Newfold plugins allows unauthenticated attackers to forge administrative access tokens and take over WordPress sites.
Stored Cross-Site Scripting in WPBot WordPress Plugin
1 rule 1 TTP 1 CVEThe WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in versions up to 8.7.3, allowing unauthenticated attackers to execute arbitrary web scripts.
XenForo OAuth2 Authorization Code Reuse Vulnerability
3 rules 3 TTPs 1 CVEXenForo versions prior to 2.3.13 contain an OAuth2 authorization code reuse vulnerability (CVE-2026-73311) that allows attackers to obtain unauthorized token pairs by submitting previously used codes.
Arbitrary File Upload and RCE in Lara Dashboard
3 rules 2 TTPs 1 CVELara Dashboard versions prior to 1.3.2 are vulnerable to arbitrary file upload via the core-upgrades endpoint, allowing unauthorized administrators to achieve remote code execution.
Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme
1 TTP 1 CVEThe Nokri Job Board WordPress theme (<= 1.6.4) is vulnerable to privilege escalation via a missing capability check in the 'nokri_account_member_permissions' function, allowing authenticated subscribers to escalate access.
Blind SQL Injection Vulnerability in GOLDENHORN ONEIT
2 TTPs 1 CVEA blind SQL injection vulnerability (CVE-2026-18198) in TAC Information Services GOLDENHORN ONEIT allows unauthenticated attackers to execute arbitrary SQL queries.
SQL Injection Vulnerability in Hospital Information System 1.0
2 rules 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability in the Hospital Information System 1.0 allows remote attackers to execute unauthorized database queries via the Search parameter in addReq.php.
Authorization Bypass in Checkmate via Missing Role Guard Middleware
1 TTP 1 CVECheckmate versions through 3.11.0 contain an authorization bypass vulnerability (CVE-2026-85390) that allows read-only users to perform unauthorized administrative actions by accessing restricted routes.
Kill Bill Administrative Endpoint Permission Bypass
1 TTP 1 CVEKill Bill versions 0.24.21 and earlier contain a security misconfiguration where authenticated users with minimal account:read privileges can perform unauthorized administrative actions.
Authorization Bypass in Craft CMS assets/move-asset Endpoint
2 rules 4 TTPs 1 CVECraft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.
Unrestricted File Upload Vulnerability in ShopEx ECShop
2 rules 2 TTPs 1 CVEShopEx ECShop versions up to 2.5.1 contain an unrestricted file upload vulnerability in the check_img_type function that allows unauthenticated remote attackers to upload malicious files via the pack_img argument.
Path Traversal Vulnerability in Dokploy
1 TTP 1 CVEDokploy versions up to 0.29.7 are vulnerable to remote path traversal via the writeTraefikConfigInPath function, allowing attackers to access arbitrary files on the system.
Missing Authorization in Kirby CMS REST API Chunked Upload Handler
1 rule 1 TTP 1 CVEAuthenticated users without file upload permissions can exploit a missing authorization check in Kirby CMS to exhaust server storage via incomplete chunked file uploads, leading to denial-of-service.
C-MOR Video Surveillance Directory Traversal Vulnerability
2 rules 2 TTPsC-MOR Video Surveillance versions up to 6.0104 are vulnerable to an unauthenticated directory traversal attack in the show-movies.pml component, allowing remote attackers to read arbitrary files.
ToolJet Multi-Tenancy Broken Access Control
4 TTPs 1 CVEToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.
Remote Code Injection in SeaCMS Template Engine
2 rules 2 TTPs 1 CVESeaCMS versions 13.6 and earlier contain a code injection vulnerability in the search.php file, allowing remote attackers to execute arbitrary code via the searchtype parameter.
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
7 rules 15 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
Remote Code Execution in Sigma Forms Pro Plugin for WordPress
1 rule 1 TTP 1 CVEThe Sigma Forms Pro plugin for WordPress is vulnerable to unauthenticated remote code execution due to improper validation of file uploads and insecure capability management within the handle_form_submission function.
Unauthenticated RCE via Server-Side Template Injection in Atlassian Jira
1 rule 2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2019-11581) exists in the 'ContactAdministrators' form of Atlassian Jira Server due to insecure Velocity template rendering of the 'subject' parameter.
SSRF Vulnerability in Qwen-Agent Document Parsing
2 TTPs 1 CVEQwen-Agent version 0.0.34 and earlier contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to force the server to perform arbitrary internal HTTP requests and exfiltrate metadata service content.
Unauthenticated Directory Traversal in Yamcs
2 rules 3 TTPs 1 CVEYamcs versions prior to 5.11.13 contain an unauthenticated directory traversal vulnerability in the HTTP request handling components that allows remote attackers to read arbitrary files from the underlying host.
Broken Access Control in Snipe-IT Asset Maintenance API
2 rules 2 TTPs 1 CVEAn authenticated user in a multi-company Snipe-IT deployment can exploit an authorization flaw in the asset maintenance update API to re-parent records to assets owned by other companies, breaking tenant isolation.
Pimcore Studio API Privilege Escalation via Class Definition Endpoint
3 rules 4 TTPs 1 CVEAn insufficient permission check in the Pimcore studio-backend-bundle allows authenticated users with standard object-editing privileges to create class definitions, leading to unauthorized schema modification and server-side file creation.
Stored Cross-Site Scripting in TranslatePress WordPress Plugin
2 TTPs 1 CVEThe TranslatePress plugin for WordPress is vulnerable to unauthenticated stored XSS through improper sanitization of comment data, allowing attackers to inject persistent malicious scripts.
Remote Code Execution in GLPI Fields Plugin (CVE-2026-23489)
1 rule 2 TTPs 1 CVECVE-2026-23489 is a blind remote code execution vulnerability in the GLPI Fields plugin (<= 1.23.2) that allows authenticated attackers to execute arbitrary PHP code via the dropdown-generation feature.
Unauthenticated Data Source Access in Baserow Application Builder
1 rule 1 TTP 1 CVEA vulnerability in Baserow's Application Builder allows unauthenticated attackers to bypass permission checks and retrieve sensitive data by leveraging improperly handled access control logic.
Authentication Bypass in APITable InternalUserController
1 rule 2 TTPs 1 CVEAPITable versions up to 1.13.0-beta.1 contain an authentication bypass vulnerability in the InternalUserController, allowing unauthenticated attackers to permanently delete user accounts currently in a cooling-off period.
OS Command Injection in ClipBucket V5 Installer
1 rule 2 TTPs 1 CVEClipBucket V5 versions 5.5.1 through 5.5.3-#153 contain an OS command injection vulnerability in the web installer, allowing unauthenticated remote code execution via the php_cli_filepath parameter.
Dolibarr Members REST API Improper Authorization Vulnerability
2 rules 2 TTPs 1 CVEAn improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.
Authorization Bypass in Ghostwriter Report Template Swap Endpoint
1 TTP 1 CVEGhostwriter versions prior to 7.1.2 are vulnerable to an authorization bypass via the report template swap endpoint, allowing authenticated attackers to enumerate and exfiltrate sensitive client-scoped template contents.
Authentication Bypass in open-wearables
1 rule 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-78154) in open-wearables versions 0.6.2 and earlier allows attackers to bypass authentication in the invitation code redemption endpoint.
SQL Injection in Barangay Resident Profiling Management System
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability in the Barangay Resident Profiling Management System version 1.0 allows remote attackers to execute arbitrary database queries via the 'Search' argument in residents.php.
CVE-2026-58003: Cross-Site Request Forgery in WWBN AVideo
1 rule 1 TTP 1 CVEWWBN AVideo versions through commit 9c39d8c8 contain a CSRF vulnerability in the releaseVideoNow.json.php endpoint that allows unauthenticated attackers to force administrative users to publish embargoed videos.
Authentication Bypass in Headroom LLM Proxy via Header Spoofing
2 rules 2 TTPs 1 CVEThe Headroom LLM proxy improperly derives memory ownership from the unauthenticated 'x-headroom-user-id' request header, allowing attackers to perform unauthorized read and write operations on arbitrary user LLM memory.
Unauthenticated Remote Code Execution in ICEcoder 8.1
1 rule 2 TTPs 1 CVEICEcoder version 8.1 contains a critical vulnerability allowing unauthenticated remote code execution via a crafted HTTP POST request to the terminal endpoint that chains authentication and CSRF bypasses.
SQL Injection in The Gallery by BestWebSoft WordPress Plugin
1 TTP 1 CVEThe Gallery by BestWebSoft plugin for WordPress up to version 4.7.9 contains an SQL injection vulnerability via the '_gallery_order_{post_id}' parameter allowing authenticated attackers with Editor-level access to extract database information.
SQL Injection Vulnerability in Evergreen OpenSRF Service
1 rule 1 TTP 1 CVEEvergreen versions up to 3.17-beta1 contain a SQL injection vulnerability in the OpenSRF service, allowing remote unauthenticated attackers to execute arbitrary database queries.
SQL Injection in SourceCodester Class and Exam Timetabling System
2 rules 1 TTP 1 CVESourceCodester Class and Exam Timetabling System 1.0 contains an unauthenticated SQL injection vulnerability in edit_teacher.php that allows remote attackers to compromise database integrity.
Command Injection in Cockpit CMS FFmpeg Integration
1 rule 1 TTP 1 CVECockpit CMS versions 2.14.0 and prior are vulnerable to authenticated command injection via malicious filenames processed by the FFmpeg integration.
Remote Code Execution in Grav CMS Flex Objects Plugin
2 rules 6 TTPs 1 CVEAuthenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.
Remote Code Execution in Grav API Plugin via Privilege Escalation
1 rule 3 TTPs 1 CVEThe Grav API plugin before version 1.0.13 fails to enforce API key scope restrictions in ConfigController, enabling remote code execution via injected scheduler commands.
Authentication Scope Bypass in Grav API Plugin Leading to RCE
1 rule 3 TTPs 1 CVEAn API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.
NoSQL Injection Vulnerability in Budibase MongoDB Integration
1 rule 3 TTPs 5 CVEsBudibase versions prior to 3.40.0 are vulnerable to NoSQL injection in the MongoDB datasource due to improper handling of user-supplied parameters, allowing unauthorized data access and potential server-side execution.
Arbitrary File Deletion in GeoDirectory Plugin
1 TTP 1 CVEThe GeoDirectory WordPress plugin contains an arbitrary file deletion vulnerability (CVE-2026-19091) allowing authenticated attackers to delete critical files and potentially achieve remote code execution.
Unauthenticated Path Traversal in DB-GPT
1 rule 1 TTP 1 CVEDB-GPT version 0.8.1 is vulnerable to an unauthenticated path traversal attack allowing remote code execution via a crafted user_id HTTP header.
CodeIgniter Path Traversal via UploadedFile::move()
2 TTPs 1 CVECodeIgniter Framework versions prior to 4.7.4 contain a path traversal vulnerability in the UploadedFile::move() method that allows attackers to write files to arbitrary filesystem locations when unsanitized client filenames are processed.
Stored XSS Vulnerability in FormGent WordPress Plugin
1 rule 1 TTP 1 CVEAn unauthenticated stored cross-site scripting vulnerability in FormGent versions 1.9.2 and below allows attackers to inject malicious scripts into form fields that execute upon viewing.
Arbitrary File Deletion Vulnerability in WordPress File Manager Plugin
1 rule 2 TTPs 1 CVEThe WordPress File Manager plugin (versions 6.0-6.9) contains an arbitrary file deletion vulnerability allowing authenticated attackers to delete critical server files and achieve remote code execution.
CSRF Vulnerability in Search Analytics for WP Plugin
1 CVEThe Search Analytics for WP plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability in the process_bulk_action function that allows authenticated administrators to be tricked into deleting arbitrary search-term records.
SQL Injection in ESAFENET CDG
1 rule 2 TTPs 1 CVEA publicly exploitable SQL injection vulnerability in ESAFENET CDG allows unauthenticated remote attackers to execute arbitrary database queries via the keyid parameter.
Remote Code Execution in OpenEMR Document Category Tree
8 TTPs 1 CVEOpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.
Thumbor Path Traversal via URL Decoding Bypass
1 rule 2 TTPs 1 CVE 1 IOCThumbor version 7.7.7 and earlier is vulnerable to arbitrary file read via a path traversal flaw in file_loader.py, where security checks are performed before decoding percent-encoded traversal sequences.
Authenticated Remote Code Execution in Wolf CMS
1 rule 3 TTPs 2 CVEsWolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.
Authorization Bypass in Subscriptions for WooCommerce Plugin
1 rule 2 TTPs 1 CVEAn authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.
CVE-2018-25326: Google Drive for WordPress Path Traversal Vulnerability
2 rules 1 TTP 1 CVEGoogle Drive for WordPress 2.2 is vulnerable to path traversal (CVE-2018-25326), allowing unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter.
Pega Platform Vulnerability Allows Cross-Site Scripting
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Pega Platform to perform a cross-site scripting (XSS) attack, potentially leading to session hijacking or malicious script execution in a user's browser.
Proticaret E-Commerce Reflected XSS Vulnerability (CVE-2026-3953)
2 rules 1 TTP 1 CVEA reflected cross-site scripting (XSS) vulnerability exists in Gosoft Software Industry and Trade Ltd. Co.'s Proticaret E-Commerce software (versions v5.0.0 before V 6.0.1767.1383) due to improper neutralization of input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.
Shenzhen Libituo Technology LBT-T300-HW1 Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA buffer overflow vulnerability exists in Shenzhen Libituo Technology LBT-T300-HW1 version 1.2.8 and earlier, allowing remote attackers to execute arbitrary code by manipulating the Channel/ApCliSsid argument in the start_lan function of the /apply.cgi file.