Skip to content
Threat Feed

Tag

Web Application Vulnerability

9 briefs RSS
high advisory

Security Updates for cPanel and WP Squared

WebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.

WP Squared +1 web-application-vulnerability vulnerability-management
2c
high advisory

Remote Code Execution in OpenEMR Document Category Tree

OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.

OpenEMR +1 web-application-vulnerability remote-code-execution healthcare cve-2026-39931 sql-injection web-application vulnerability authentication-bypass +1
8t 1c
high advisory

Thumbor Path Traversal via URL Decoding Bypass

Thumbor version 7.7.7 and earlier is vulnerable to arbitrary file read via a path traversal flaw in file_loader.py, where security checks are performed before decoding percent-encoded traversal sequences.

Thumbor web-application-vulnerability hmac-bypass image-processing cve-2026-53501 ssrf web-application input-validation
1r 2t 1c 1i
high advisory

Authenticated Remote Code Execution in Wolf CMS

Wolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.

Wolf CMS remote-code-execution web-application-vulnerability
1r 3t
high advisory

Authorization Bypass in Subscriptions for WooCommerce Plugin

An authorization flaw in the Subscriptions for WooCommerce WordPress plugin allows authenticated users with shop manager privileges to remotely install and activate arbitrary plugins.

Subscriptions for WooCommerce wordpress plugin web-application-vulnerability cve-2026-15397
1r 2t 1c
high advisory

CVE-2018-25326: Google Drive for WordPress Path Traversal Vulnerability

Google Drive for WordPress 2.2 is vulnerable to path traversal (CVE-2018-25326), allowing unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter.

Google Drive for WordPress 2.2 path traversal wordpress CVE-2018-25326 web application vulnerability
2r 1t 1c
medium advisory

Pega Platform Vulnerability Allows Cross-Site Scripting

A remote, anonymous attacker can exploit a vulnerability in Pega Platform to perform a cross-site scripting (XSS) attack, potentially leading to session hijacking or malicious script execution in a user's browser.

Pega Platform cross-site scripting web application vulnerability
2r 1t
medium advisory

Proticaret E-Commerce Reflected XSS Vulnerability (CVE-2026-3953)

A reflected cross-site scripting (XSS) vulnerability exists in Gosoft Software Industry and Trade Ltd. Co.'s Proticaret E-Commerce software (versions v5.0.0 before V 6.0.1767.1383) due to improper neutralization of input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.

Proticaret E-Commerce xss cross-site scripting reflected xss web application vulnerability
2r 1t 1c
critical threat

Shenzhen Libituo Technology LBT-T300-HW1 Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in Shenzhen Libituo Technology LBT-T300-HW1 version 1.2.8 and earlier, allowing remote attackers to execute arbitrary code by manipulating the Channel/ApCliSsid argument in the start_lan function of the /apply.cgi file.

LBT-T300-HW1 buffer overflow remote code execution web application vulnerability
2r 1t 1c