Skip to content
Threat Feed

Tag

Web Application Vulnerability

67 briefs RSS
high advisory

CVE-2026-92807: Arbitrary Function Invocation in Save as PDF Plugin for WordPress

The Save as PDF Plugin for WordPress up to version 4.6.1 is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated Contributor-level users to trigger sensitive data disclosure.

Save as PDF Plugin web-application-vulnerability wordpress cve-2026-92807
1r 1t 1c
high advisory

Unauthenticated SQL Injection in Chanjet CRM (CVE-2021-48008)

Chanjet CRM contains an unauthenticated SQL injection vulnerability in the webservice endpoint, enabling remote attackers to extract sensitive data via the site_id parameter.

CRM web-application-vulnerability sql-injection cve-2021-48008
1r 1t 1c
high threat

Unauthenticated SQL Injection in Weaver E-cology

Weaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.

E-cology web-application-vulnerability sqli remote-execution
1r 2t 1c
high advisory

SQL Injection in Location Manager Plugin for WordPress

The Location Manager plugin for WordPress is vulnerable to unauthenticated SQL injection via REST API parameters, allowing remote attackers to extract sensitive database information.

Location Manager web-application-vulnerability sql-injection wordpress
1r 1t 1c
high advisory

Grav Privilege Escalation via Group Blueprint ACL Bypass

A missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.

Grav +2 privilege-escalation cms vulnerability web-application-vulnerability path-traversal cve-2026-74907 twig security-misconfiguration
1r 3t 1c
high advisory

Remote Code Execution in SiYuan via Malicious Bookmark Labels

SiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.

SiYuan +2 vulnerability rce electron xss web-application-vulnerability sql-injection data-exfiltration web-vulnerability +1
1r 5t 1c updated
high advisory

Authorization Bypass in metasfresh DocumentAttachmentsRestController and CommentsRestController

Authenticated attackers can exploit improper record-level authorization checks in metasfresh ERP to perform unauthorized read, write, and delete operations on attachments and comments.

metasfresh ERP web-application-vulnerability authorization-bypass erp
1t
medium advisory

CVE-2026-90937 Configuration Injection in Froxlor

Froxlor versions before 2.2.5 contain a vulnerability allowing authenticated users to inject arbitrary Nginx or Apache configuration directives via unvalidated newline characters in subdomain redirect URLs.

froxlor web-application-vulnerability configuration-injection server-hijacking
1t 1c
high advisory

SQL Injection in Sticky Chat Widget WordPress Plugin

The Sticky Chat Widget plugin for WordPress (<= 1.4.2) is vulnerable to unauthenticated SQL injection via the 'scw_save_form_data' AJAX action, allowing potential exfiltration of sensitive database information.

Sticky Chat Widget web-application-vulnerability sqli wordpress
1r 1t 1c
high advisory

Authentication Bypass in Newfold WordPress Plugins via wp-module-data

An authentication bypass vulnerability in the wp-module-data library used by multiple Newfold plugins allows unauthenticated attackers to forge administrative access tokens and take over WordPress sites.

Crazy Domains +4 web-application-vulnerability wordpress cve-2026-80099
1r 1t 1c
high advisory

Stored Cross-Site Scripting in WPBot WordPress Plugin

The WPBot - AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in versions up to 8.7.3, allowing unauthenticated attackers to execute arbitrary web scripts.

WPBot – AI ChatBot for Live Support, Lead Generation, AI Services xss web-application-vulnerability wordpress cve-2026-83593
1r 1t 1c
high advisory

XenForo OAuth2 Authorization Code Reuse Vulnerability

XenForo versions prior to 2.3.13 contain an OAuth2 authorization code reuse vulnerability (CVE-2026-73311) that allows attackers to obtain unauthorized token pairs by submitting previously used codes.

XenForo web-application vulnerability authentication-bypass cve-2026-73309 web-application-vulnerability
3r 3t 1c
high advisory

Arbitrary File Upload and RCE in Lara Dashboard

Lara Dashboard versions prior to 1.3.2 are vulnerable to arbitrary file upload via the core-upgrades endpoint, allowing unauthorized administrators to achieve remote code execution.

Lara Dashboard +2 web-application-vulnerability rce file-upload path-traversal web-vulnerability
3r 2t 1c updated
high advisory

Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme

The Nokri Job Board WordPress theme (<= 1.6.4) is vulnerable to privilege escalation via a missing capability check in the 'nokri_account_member_permissions' function, allowing authenticated subscribers to escalate access.

Nokri – Job Board WordPress Theme wordpress privilege-escalation web-application-vulnerability
1t 1c
high advisory

Blind SQL Injection Vulnerability in GOLDENHORN ONEIT

A blind SQL injection vulnerability (CVE-2026-18198) in TAC Information Services GOLDENHORN ONEIT allows unauthenticated attackers to execute arbitrary SQL queries.

GOLDENHORN ONEIT web-application-vulnerability sql-injection cve-2026-18198
2t 1c
high advisory

SQL Injection Vulnerability in Hospital Information System 1.0

An unauthenticated SQL injection vulnerability in the Hospital Information System 1.0 allows remote attackers to execute unauthorized database queries via the Search parameter in addReq.php.

Hospital Information System web-application-vulnerability sql-injection cve-2026-85397 vulnerability web
2r 1t 1c
high advisory

Authorization Bypass in Checkmate via Missing Role Guard Middleware

Checkmate versions through 3.11.0 contain an authorization bypass vulnerability (CVE-2026-85390) that allows read-only users to perform unauthorized administrative actions by accessing restricted routes.

Checkmate privilege-escalation web-application-vulnerability
1t 1c
high advisory

Kill Bill Administrative Endpoint Permission Bypass

Kill Bill versions 0.24.21 and earlier contain a security misconfiguration where authenticated users with minimal account:read privileges can perform unauthorized administrative actions.

Kill Bill web-application-vulnerability privilege-escalation access-control
1t 1c
high advisory

Authorization Bypass in Craft CMS assets/move-asset Endpoint

Craft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.

Craft CMS +3 cms web-vulnerability authorization-bypass web-application vulnerability privilege-escalation web-application-vulnerability rce +1
2r 4t 1c updated
high advisory

Unrestricted File Upload Vulnerability in ShopEx ECShop

ShopEx ECShop versions up to 2.5.1 contain an unrestricted file upload vulnerability in the check_img_type function that allows unauthenticated remote attackers to upload malicious files via the pack_img argument.

ECShop web-application-vulnerability remote-code-execution file-upload web-vulnerability sql-injection cve-2026-82922
2r 2t 1c
critical advisory

Path Traversal Vulnerability in Dokploy

Dokploy versions up to 0.29.7 are vulnerable to remote path traversal via the writeTraefikConfigInPath function, allowing attackers to access arbitrary files on the system.

Dokploy web-application-vulnerability path-traversal cve-2026-82954
1t 1c
high threat

Missing Authorization in Kirby CMS REST API Chunked Upload Handler

Authenticated users without file upload permissions can exploit a missing authorization check in Kirby CMS to exhaust server storage via incomplete chunked file uploads, leading to denial-of-service.

exploited Kirby CMS +1 web-application denial-of-service api-security web-application-vulnerability path-traversal cms
1r 1t 1c
high threat

C-MOR Video Surveillance Directory Traversal Vulnerability

C-MOR Video Surveillance versions up to 6.0104 are vulnerable to an unauthenticated directory traversal attack in the show-movies.pml component, allowing remote attackers to read arbitrary files.

exploited C-MOR Video Surveillance webapps directory-traversal cve-2026-51134 surveillance web-application-vulnerability xss
2r 2t
critical advisory

ToolJet Multi-Tenancy Broken Access Control

ToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.

ToolJet webserver broken-access-control vulnerability web-application-vulnerability authorization-bypass privilege-escalation web-application authentication-bypass +1
4t 1c
high advisory

Remote Code Injection in SeaCMS Template Engine

SeaCMS versions 13.6 and earlier contain a code injection vulnerability in the search.php file, allowing remote attackers to execute arbitrary code via the searchtype parameter.

SeaCMS web-vulnerability rce webserver web-application-vulnerability sql-injection cve-2026-82600
2r 2t 1c updated
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
critical advisory

Remote Code Execution in Sigma Forms Pro Plugin for WordPress

The Sigma Forms Pro plugin for WordPress is vulnerable to unauthenticated remote code execution due to improper validation of file uploads and insecure capability management within the handle_form_submission function.

Sigma Forms Pro web-application-vulnerability wordpress rce file-upload
1r 1t 1c
critical threat

Unauthenticated RCE via Server-Side Template Injection in Atlassian Jira

An unauthenticated remote code execution vulnerability (CVE-2019-11581) exists in the 'ContactAdministrators' form of Atlassian Jira Server due to insecure Velocity template rendering of the 'subject' parameter.

exploited Jira Server web-application-vulnerability rce ssti jira
1r 2t 1c
high advisory

SSRF Vulnerability in Qwen-Agent Document Parsing

Qwen-Agent version 0.0.34 and earlier contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to force the server to perform arbitrary internal HTTP requests and exfiltrate metadata service content.

Qwen-Agent ssrf vulnerability cloud path-traversal arbitrary-file-read web-application-vulnerability
2t 1c
high advisory

Unauthenticated Directory Traversal in Yamcs

Yamcs versions prior to 5.11.13 contain an unauthenticated directory traversal vulnerability in the HTTP request handling components that allows remote attackers to read arbitrary files from the underlying host.

yamcs-core +2 web-vulnerability directory-traversal cve-2026-55552 privilege-escalation web-application-vulnerability
2r 3t 1c
high advisory

Broken Access Control in Snipe-IT Asset Maintenance API

An authenticated user in a multi-company Snipe-IT deployment can exploit an authorization flaw in the asset maintenance update API to re-parent records to assets owned by other companies, breaking tenant isolation.

Snipe-IT +2 web-application privilege-escalation multi-tenant web-application-vulnerability path-traversal cve-2026-55474 authorization-bypass asset-management
2r 2t 1c
high advisory

Pimcore Studio API Privilege Escalation via Class Definition Endpoint

An insufficient permission check in the Pimcore studio-backend-bundle allows authenticated users with standard object-editing privileges to create class definitions, leading to unauthorized schema modification and server-side file creation.

studio-backend-bundle +3 privilege-escalation cms vulnerability account-takeover cve-2026-55207 web-application-vulnerability
3r 4t 1c
high advisory

Stored Cross-Site Scripting in TranslatePress WordPress Plugin

The TranslatePress plugin for WordPress is vulnerable to unauthenticated stored XSS through improper sanitization of comment data, allowing attackers to inject persistent malicious scripts.

Translate Multilingual sites with AI Translation web-application-vulnerability xss wordpress
2t 1c
high threat

Remote Code Execution in GLPI Fields Plugin (CVE-2026-23489)

CVE-2026-23489 is a blind remote code execution vulnerability in the GLPI Fields plugin (<= 1.23.2) that allows authenticated attackers to execute arbitrary PHP code via the dropdown-generation feature.

exploited Fields Plugin remote-code-execution web-application-vulnerability
1r 2t 1c
high advisory

Unauthenticated Data Source Access in Baserow Application Builder

A vulnerability in Baserow's Application Builder allows unauthenticated attackers to bypass permission checks and retrieve sensitive data by leveraging improperly handled access control logic.

Baserow web-application-vulnerability access-control-bypass cve-2026-81335
1r 1t 1c
high threat

Authentication Bypass in APITable InternalUserController

APITable versions up to 1.13.0-beta.1 contain an authentication bypass vulnerability in the InternalUserController, allowing unauthenticated attackers to permanently delete user accounts currently in a cooling-off period.

exploited APITable +1 authentication-bypass web-application-vulnerability data-destruction information-disclosure cloud
1r 2t 1c updated
critical threat

OS Command Injection in ClipBucket V5 Installer

ClipBucket V5 versions 5.5.1 through 5.5.3-#153 contain an OS command injection vulnerability in the web installer, allowing unauthenticated remote code execution via the php_cli_filepath parameter.

exploited clipbucket-v5 remote-code-execution web-application-vulnerability
1r 2t 1c
high advisory

Dolibarr Members REST API Improper Authorization Vulnerability

An improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.

Dolibarr +2 vulnerability rest-api privilege-escalation cve-2026-71504 sqli web-vulnerability cve-2026-81730 path-traversal +1
2r 2t 1c updated
high advisory

Authorization Bypass in Ghostwriter Report Template Swap Endpoint

Ghostwriter versions prior to 7.1.2 are vulnerable to an authorization bypass via the report template swap endpoint, allowing authenticated attackers to enumerate and exfiltrate sensitive client-scoped template contents.

Ghostwriter web-application-vulnerability authorization-bypass cve-2026-78203
1t 1c
high advisory

Authentication Bypass in open-wearables

An unauthenticated remote code execution vulnerability (CVE-2026-78154) in open-wearables versions 0.6.2 and earlier allows attackers to bypass authentication in the invitation code redemption endpoint.

open-wearables authentication-bypass cve-2026-78154 web-application-vulnerability
1r 1c
high advisory

SQL Injection in Barangay Resident Profiling Management System

An unauthenticated SQL injection vulnerability in the Barangay Resident Profiling Management System version 1.0 allows remote attackers to execute arbitrary database queries via the 'Search' argument in residents.php.

Barangay Resident Profiling Management System web-application-vulnerability sql-injection cve-2026-78143
1r 1t 1c
high advisory

CVE-2026-58003: Cross-Site Request Forgery in WWBN AVideo

WWBN AVideo versions through commit 9c39d8c8 contain a CSRF vulnerability in the releaseVideoNow.json.php endpoint that allows unauthenticated attackers to force administrative users to publish embargoed videos.

AVideo +1 web-application csrf cve-2026-58003 web-application-vulnerability authorization-bypass cve-2026-59256
1r 1t 1c
critical advisory

Authentication Bypass in Headroom LLM Proxy via Header Spoofing

The Headroom LLM proxy improperly derives memory ownership from the unauthenticated 'x-headroom-user-id' request header, allowing attackers to perform unauthorized read and write operations on arbitrary user LLM memory.

LLM proxy identity-spoofing cve web-application-vulnerability web-application ssrf vulnerability
2r 2t 1c
critical advisory

Unauthenticated Remote Code Execution in ICEcoder 8.1

ICEcoder version 8.1 contains a critical vulnerability allowing unauthenticated remote code execution via a crafted HTTP POST request to the terminal endpoint that chains authentication and CSRF bypasses.

ICEcoder web-application-vulnerability rce cve-2026-63722
1r 2t 1c
high advisory

SQL Injection in The Gallery by BestWebSoft WordPress Plugin

The Gallery by BestWebSoft plugin for WordPress up to version 4.7.9 contains an SQL injection vulnerability via the '_gallery_order_{post_id}' parameter allowing authenticated attackers with Editor-level access to extract database information.

The Gallery web-application-vulnerability wordpress sqli
1t 1c
high advisory

SQL Injection Vulnerability in Evergreen OpenSRF Service

Evergreen versions up to 3.17-beta1 contain a SQL injection vulnerability in the OpenSRF service, allowing remote unauthenticated attackers to execute arbitrary database queries.

OpenSRF Service web-application-vulnerability sql-injection cve-2026-19926
1r 1t 1c
high threat

SQL Injection in SourceCodester Class and Exam Timetabling System

SourceCodester Class and Exam Timetabling System 1.0 contains an unauthenticated SQL injection vulnerability in edit_teacher.php that allows remote attackers to compromise database integrity.

exploited Class and Exam Timetabling System +1 web-application-vulnerability sql-injection cve-2026-75079
2r 1t 1c updated
high advisory

Command Injection in Cockpit CMS FFmpeg Integration

Cockpit CMS versions 2.14.0 and prior are vulnerable to authenticated command injection via malicious filenames processed by the FFmpeg integration.

Cockpit CMS web-application-vulnerability remote-code-execution injection cockpit-cms
1r 1t 1c
high advisory

Remote Code Execution in Grav CMS Flex Objects Plugin

Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.

Grav CMS +2 web-application-vulnerability rce ssti cms privilege-escalation web-application remote-code-execution cve-2026-75827
2r 6t 1c updated
critical advisory

Remote Code Execution in Grav API Plugin via Privilege Escalation

The Grav API plugin before version 1.0.13 fails to enforce API key scope restrictions in ConfigController, enabling remote code execution via injected scheduler commands.

Grav API plugin remote-code-execution privilege-escalation web-application-vulnerability
1r 3t 1c updated
high advisory

Authentication Scope Bypass in Grav API Plugin Leading to RCE

An API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.

grav-plugin-api +2 web-vulnerability rce ssti grav-cms web-application-vulnerability cve-2026-75829
1r 3t 1c updated
high advisory

NoSQL Injection Vulnerability in Budibase MongoDB Integration

Budibase versions prior to 3.40.0 are vulnerable to NoSQL injection in the MongoDB datasource due to improper handling of user-supplied parameters, allowing unauthorized data access and potential server-side execution.

Budibase +2 ssrf web-vulnerability web-application privilege-escalation auth-bypass web-application-vulnerability authorization-bypass cloud-security
1r 3t 5c updated
high advisory

Arbitrary File Deletion in GeoDirectory Plugin

The GeoDirectory WordPress plugin contains an arbitrary file deletion vulnerability (CVE-2026-19091) allowing authenticated attackers to delete critical files and potentially achieve remote code execution.

GeoDirectory web-application-vulnerability wordpress arbitrary-file-deletion
1t 1c
critical advisory

Unauthenticated Path Traversal in DB-GPT

DB-GPT version 0.8.1 is vulnerable to an unauthenticated path traversal attack allowing remote code execution via a crafted user_id HTTP header.

PoC DB-GPT web-application-vulnerability path-traversal rce
1r 1t 1c updated
high advisory

CodeIgniter Path Traversal via UploadedFile::move()

CodeIgniter Framework versions prior to 4.7.4 contain a path traversal vulnerability in the UploadedFile::move() method that allows attackers to write files to arbitrary filesystem locations when unsanitized client filenames are processed.

CodeIgniter Framework web-application-vulnerability path-traversal codeigniter
2t 1c
high advisory

Stored XSS Vulnerability in FormGent WordPress Plugin

An unauthenticated stored cross-site scripting vulnerability in FormGent versions 1.9.2 and below allows attackers to inject malicious scripts into form fields that execute upon viewing.

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More web-application-vulnerability wordpress xss
1r 1t 1c
high advisory

Arbitrary File Deletion Vulnerability in WordPress File Manager Plugin

The WordPress File Manager plugin (versions 6.0-6.9) contains an arbitrary file deletion vulnerability allowing authenticated attackers to delete critical server files and achieve remote code execution.

File Manager web-application-vulnerability wordpress remote-code-execution arbitrary-file-deletion
1r 2t 1c
high advisory

CSRF Vulnerability in Search Analytics for WP Plugin

The Search Analytics for WP plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability in the process_bulk_action function that allows authenticated administrators to be tricked into deleting arbitrary search-term records.

Search Analytics for WP web-application-vulnerability wordpress csrf
1c
high threat

SQL Injection in ESAFENET CDG

A publicly exploitable SQL injection vulnerability in ESAFENET CDG allows unauthenticated remote attackers to execute arbitrary database queries via the keyid parameter.

exploited CDG web-application-vulnerability sqli remote-code-execution
1r 2t 1c
high advisory

Remote Code Execution in OpenEMR Document Category Tree

OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.

OpenEMR +1 web-application-vulnerability remote-code-execution healthcare cve-2026-39931 sql-injection web-application vulnerability authentication-bypass +1
8t 1c
high advisory

Thumbor Path Traversal via URL Decoding Bypass

Thumbor version 7.7.7 and earlier is vulnerable to arbitrary file read via a path traversal flaw in file_loader.py, where security checks are performed before decoding percent-encoded traversal sequences.

Thumbor web-application-vulnerability hmac-bypass image-processing cve-2026-53501 ssrf web-application input-validation
1r 2t 1c 1i
high advisory

Authenticated Remote Code Execution in Wolf CMS

Wolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.

PoC Wolf CMS remote-code-execution web-application-vulnerability
1r 3t 2c updated
high advisory

Authorization Bypass in Subscriptions for WooCommerce Plugin

An authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.

Subscriptions for WooCommerce wordpress plugin web-application-vulnerability cve-2026-15397
1r 2t 1c
high advisory

CVE-2018-25326: Google Drive for WordPress Path Traversal Vulnerability

Google Drive for WordPress 2.2 is vulnerable to path traversal (CVE-2018-25326), allowing unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter.

Google Drive for WordPress 2.2 path traversal wordpress CVE-2018-25326 web application vulnerability
2r 1t 1c
medium advisory

Pega Platform Vulnerability Allows Cross-Site Scripting

A remote, anonymous attacker can exploit a vulnerability in Pega Platform to perform a cross-site scripting (XSS) attack, potentially leading to session hijacking or malicious script execution in a user's browser.

Pega Platform cross-site scripting web application vulnerability
2r 1t
medium advisory

Proticaret E-Commerce Reflected XSS Vulnerability (CVE-2026-3953)

A reflected cross-site scripting (XSS) vulnerability exists in Gosoft Software Industry and Trade Ltd. Co.'s Proticaret E-Commerce software (versions v5.0.0 before V 6.0.1767.1383) due to improper neutralization of input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

Proticaret E-Commerce xss cross-site scripting reflected xss web application vulnerability
2r 1t 1c
critical threat

Shenzhen Libituo Technology LBT-T300-HW1 Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in Shenzhen Libituo Technology LBT-T300-HW1 version 1.2.8 and earlier, allowing remote attackers to execute arbitrary code by manipulating the Channel/ApCliSsid argument in the start_lan function of the /apply.cgi file.

LBT-T300-HW1 buffer overflow remote code execution web application vulnerability
2r 1t 1c