Skip to content
Threat Feed

Tag

Web-Vulnerability

219 briefs RSS
critical advisory

Flowise Unauthenticated RCE via Environment Variable Bypass

Flowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.

Flowise +4 rce injection cve-2026-69263 python-injection authentication-bypass oauth cve-2026-70478 web-vulnerability +7
6r 11t 2c
critical advisory

SQL Injection in Sequelize Oracle Dialect

Sequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.

Sequelize web-vulnerability sqli npm cve-2026-69240
1t
high advisory

Cross-Site Scripting Vulnerability in Angular Server-Side Rendering

A Cross-Site Scripting (XSS) vulnerability in @angular/platform-server (CVE-2026-69149) allows script injection via improper serialization of fallback raw-content elements during server-side rendering.

platform-server +3 xss web-vulnerability angular
1t 1c
critical advisory

SQL Injection in SiYuan fullTextSearchAssetContent Endpoint

SiYuan versions before 3.7.3 contain a critical SQL injection vulnerability in the fullTextSearchAssetContent endpoint, allowing unauthenticated attackers to execute arbitrary SQL commands on the backend asset-content database.

SiYuan sql-injection web-vulnerability path-traversal cve-2026-69086 web-application
3r 2t 1c
high advisory

Authorization Bypass in @better-auth/stripe

An authorization bypass vulnerability in @better-auth/stripe allows authenticated users to perform unauthorized subscription actions and access billing data of other organizations via ID parameter confusion.

@better-auth/stripe authorization-bypass web-vulnerability billing
1c
high advisory

Remote Code Execution in Kali Forms WordPress Plugin

Unauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.

Kali Forms — Contact Form & Drag-and-Drop Builder web-vulnerability wordpress rce
1r 2t 1c
critical advisory

Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport

The dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.

dynatrace-mcp-server authentication-bypass mcp dynatrace web-vulnerability
1r
high advisory

Leantime Authenticated LFI and SSRF via Blueprints

Leantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.

Leantime lfi ssrf cve-2026-66415 web-vulnerability csrf cve-2026-66416
1t 1c
high advisory

Authentication Bypass in FTC E-Commerce Management Panel

A missing authentication vulnerability in FTC E-Commerce Management Panel versions prior to 1.0.2 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access.

FTC E-Commerce Management Panel authentication-bypass cve-2026-12722 web-vulnerability
1c
high advisory

Reflected XSS in IBM Tivoli System Automation and WebSphere Application Server

IBM Tivoli System Automation Application Manager 4.1 and WebSphere Application Server are affected by a reflected cross-site scripting vulnerability in the administrative console login page that allows unauthenticated attackers to execute arbitrary JavaScript.

Tivoli System Automation Application Manager +1 xss web-vulnerability cve-2026-11707
1r 1c
high advisory

BuddyPress Insecure Deserialization Vulnerability

An insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.

BuddyPress wordpress deserialization rce web-vulnerability
1t
high threat

Multiple Vulnerabilities in Apache Traffic Server

Multiple vulnerabilities in Apache Traffic Server can be exploited by a remote, anonymous attacker to bypass security measures, disclose or manipulate data, trigger a denial-of-service, and potentially achieve code execution.

exploited Apache Traffic Server web-vulnerability rce dos data-manipulation apache
2t
high advisory

CVE-2026-16597 - GTM4WP WordPress Plugin Vulnerable to Stored XSS via WooCommerce Billing Fields

The GTM4WP (Google Tag Manager) plugin for WordPress, in versions up to and including 1.22.3, is vulnerable to stored cross-site scripting (XSS) via CVE-2026-16597, allowing unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields during a guest checkout, which execute when a user accesses the compromised page.

GTM4WP +1 wordpress plugin xss web-vulnerability e-commerce
1r 1t 1c
critical advisory

Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin

A critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.

Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin wordpress authentication-bypass web-vulnerability
1r 3t 1c
critical advisory

WordPress Wholesale for WooCommerce Plugin Privilege Escalation (CVE-2026-12144)

The Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation due to insufficient validation and capability checks in `save_requests_meta()` function, allowing authenticated attackers with author-level access or higher to escalate their privileges to administrator by supplying 'administrator' as the `user_role_set` value in a crafted request.

Wholesale for WooCommerce plugin wordpress plugin privilege-escalation web-vulnerability
1t 1c
critical advisory

IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)

A remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.

WebSphere Application Server 9.0 +8 vulnerability authentication-bypass websphere broken-access-control privilege-escalation deserialization RCE server-side-request-forgery +6
5t 7c 5i
critical advisory

WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)

The WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.

WP Password Policy wordpress privilege-escalation web-vulnerability php
1r 1t 1c
low advisory

Null Pointer Dereference Vulnerability in TinyWeb

A null pointer dereference vulnerability, CVE-2026-67184, in TinyWeb through version 0.0.8 allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string, leading to a denial of service.

TinyWeb web-vulnerability denial-of-service cve
1t 1c
medium advisory

Poweradmin Vulnerable to Host Header Injection in Authentication Redirects

Poweradmin versions earlier than 4.2.4 and from 4.3.0 up to, but not including, 4.3.3 are vulnerable to CVE-2026-54588, a critical Host Header Injection flaw in OIDC, SAML, and logout authentication flows that allows an unauthenticated attacker to manipulate the HTTP_HOST header, poisoning callback URLs to redirect authorization codes to an attacker-controlled server, leading to full account takeover and potential full DNS zone control.

Poweradmin +1 web-vulnerability host-header-injection oidc saml account-takeover dns-hijacking
3t 1c 1i
high advisory

Rouille HTTP Server Framework Vulnerable to Request Smuggling (CVE-2026-67181)

Rouille HTTP server framework versions 0.3.3 through 3.6.2 are vulnerable to an HTTP request smuggling attack, CVE-2026-67181, allowing remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation, leading to potential bypassing of security controls or unauthorized access.

Rouille 0.3.3 through 3.6.2 web-vulnerability http-request-smuggling server-side
1r 1t 1c
high advisory

TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)

An unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.

TrueBooker – Appointment Booking and Scheduler System plugin +1 wordpress sqli plugin web-vulnerability cve
1r 2t 1c
high advisory

CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin

An SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.

WP Fast Total Search – The Power of Indexed Search wordpress plugin sql-injection web-vulnerability data-exfiltration
1r 2t 1c
high advisory

Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin

A path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots < 2.15.19 wordpress web-vulnerability path-traversal rce file-deletion
1r 2t 1c
medium advisory

The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)

Unauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.

The Demi – One Click Demo Import, WP Backup & Site Migration plugin <= 0.0.7 wordpress plugin-vulnerability arbitrary-deletion web-vulnerability
2t 1c
low advisory

Denial-of-Service Vulnerability in facil.io HTTP/1.1 Chunked Transfer Encoding Parser (CVE-2026-66731)

An unauthenticated remote denial-of-service vulnerability exists in facil.io versions 0.7.5 through 0.7.6, allowing attackers to crash the server by sending a POST request with a 'Transfer-Encoding: chunked' header containing a negative chunk size value, which corrupts internal state and leads to a fault.

facil.io 0.7.5 +1 denial-of-service web-vulnerability facil.io
1t 1c
critical advisory

Critical Eval Injection Vulnerability in vBulletin Allows Remote Code Execution (CVE-2026-61511)

An eval injection vulnerability, identified as CVE-2026-61511, exists in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, specifically within the vB5_Template_Runtime::runMaths() method, allowing unauthenticated remote attackers to achieve arbitrary PHP code execution by manipulating the pagenav[pagenumber] parameter through the unauthenticated ajax/render template route with phpfuck-style encoding.

PoC vBulletin 5.x through 5.7.5 +4 web-vulnerability remote-code-execution eval-injection php unauthenticated
1r 2t 3c 4i
high advisory

WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE

The WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.

WPForms Pro plugin for WordPress <= 1.10.1.1 +1 wordpress rce arbitrary-file-upload web-vulnerability
1r 2t 1i updated
high advisory

Multiple High-Severity Vulnerabilities in OmniFaces Library

Multiple vulnerabilities in OmniFaces versions prior to 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2 allow attackers to exploit forged combined-resource IDs leading to server-side request forgery (SSRF)-like behavior or information disclosure, achieve client-side arbitrary code execution via cross-site scripting (XSS) in `o:hashParam`, bypass session authentication for push channels resulting in unauthorized message interception, and cause denial-of-service (DoS) via unbounded caches.

omnifaces +4 web-vulnerability ssrf xss dos java information-disclosure session-hijacking
6t 1c
critical advisory

Budibase Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

An unauthenticated attacker can steal REST datasource credentials, including Bearer/Basic tokens and static headers, from Budibase applications due to a critical cross-origin authentication leak (GHSA-mqhr-6j6h-74p5) where the application attaches stored credentials to outgoing requests without validating the destination host, allowing exfiltration to an attacker-controlled server.

Budibase credential-theft authentication-bypass web-vulnerability api-abuse cloud network
3t 4i
high advisory

Budibase MongoDB Datasource Vulnerability Allows Server Filesystem Existence/Read Oracle

A vulnerability in Budibase's MongoDB datasource configuration allows authenticated attackers to specify arbitrary absolute server-side file paths for `tlsCertificateKeyFile` and `tlsCAFile`, enabling the `/api/datasources/verify` endpoint to act as an arbitrary-path existence/read oracle on the underlying multi-tenant server, distinguishing between existing and non-existing files and potentially exfiltrating certificate content.

npm/@budibase/server <= 3.38.1 +1 budibase vulnerability file-read information-disclosure cloud mongodb api web-vulnerability +1
2r 6t 2i
critical advisory

SQL Injection Vulnerability in Budibase MySQL Integration

A critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.

Budibase Server +1 sql-injection web-application vulnerability nosql-injection data-exfiltration data-destruction application-vulnerability csrft +4
1r 7t
high advisory

Cloudreve OAuth Admin.Read Scope Bypass for OneDrive Storage Policy Credential Update (CVE-2026-55502)

An authorization bypass vulnerability (CVE-2026-55502) in Cloudreve 4.16.1 allows an attacker with an `Admin.Read` OAuth token to modify the OneDrive storage policy credentials via a POST request to `/api/v4/admin/policy/oauth/signin`, despite lacking `Admin.Write` scope, which can break the storage backend and redirect future OAuth setups.

Cloudreve +1 authorization-bypass oauth web-vulnerability credential-manipulation
1r 1t
high advisory

Open WebUI: Cross-User Code-Interpreter and Tool Execution via Unvalidated Socket.IO Session ID

An authenticated low-privilege user can exploit CVE-2026-59216 in Open WebUI versions prior to 0.10.0 to execute arbitrary Python code or tools within another user's authenticated session by supplying an unvalidated `session_id`, which, if targeting an administrator, leads to remote code execution on the server as the root process.

Open WebUI web-vulnerability rce session-hijacking open-webui python vulnerability web-application identity-spoofing +1
1r 3t 1c
high advisory

Fastify/static Vulnerable to Route Guard Bypass via Path Traversal

The @fastify/static package is vulnerable to a route guard bypass via path traversal using non-leading '..' or '%2E%2E' path segments, allowing attackers to circumvent route-based middleware and access protected files that are served by the static plugin.

@fastify/static fastify nodejs web-vulnerability path-traversal webserver
1r 3t 1c
medium advisory

React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)

An unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.

react-router web-vulnerability denial-of-service npm
1t
high threat

VikBooking Hotel Booking Engine & PMS Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-15401)

The VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to and including 1.8.13 is vulnerable to Stored Cross-Site Scripting (XSS) via the 'vbfX' parameter, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an infected page.

VikBooking Hotel Booking Engine & PMS plugin for WordPress wordpress xss web-vulnerability stored-xss cms
1r 2t 1c
high advisory

Wpify Woo Plugin Privilege Escalation Vulnerability (CVE-2026-12736)

A privilege escalation vulnerability (CVE-2026-12736) in the Wpify Woo plugin for WordPress, affecting versions up to and including 5.4.16, allows authenticated attackers with 'Shop Manager' capabilities or higher to gain Administrator privileges by exploiting a REST route that overwrites arbitrary WordPress options.

Wpify Woo plugin +1 privilege-escalation wordpress web-vulnerability
1r 2t 1c
high advisory

Microweber CMS Path Traversal Vulnerability (CVE-2026-65694)

An unauthenticated path traversal vulnerability (CVE-2026-65694) in the static file controller of Microweber CMS, affecting versions through 2.0.20, allows remote attackers to read arbitrary files by supplying directory traversal sequences in the 'path' query parameter via a single unauthenticated HTTP GET request, potentially disclosing sensitive information like environment configuration files containing credentials or system files.

PoC Microweber CMS +1 web-vulnerability path-traversal cms webserver
1r 2t 1c 2i updated
high advisory

Cal.com Stored Cross-Site Scripting Vulnerability (CVE-2024-58355)

A stored cross-site scripting (XSS) vulnerability, CVE-2024-58355, affects Cal.com (calcom/cal.diy) versions through 4.7.15, allowing an attacker to inject arbitrary HTML/JavaScript into a booking-question label that executes in a victim's browser when they view a crafted booking URL, potentially leading to session hijacking, data theft, or defacement.

Cal.com xss web-vulnerability client-side-execution
1t 1c
critical advisory

CVE-2024-58353: Cal.com Cross-Site Scripting Vulnerability

CVE-2024-58353 describes a cross-site scripting (XSS) vulnerability in Cal.com (repository calcom/cal.diy) versions up to and including 4.7.15, where an attacker can inject malicious HTML/JavaScript into booking question labels that is then executed via React's dangerouslySetInnerHTML when a victim visits a publicly accessible single booking view, allowing for arbitrary client-side code execution, particularly impacting self-hosted instances with open registration.

Cal.com xss web-vulnerability react dangerouslySetInnerHTML
1t 1c
critical advisory

WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)

A critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.

PoC SAML Single Sign On – SSO Login plugin +2 authentication-bypass wordpress web-vulnerability cve-2026-15981
2t 1c 2i updated
critical advisory

h2oGPT Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2026-65700)

h2oGPT through version 0.2.1 contains a critical path traversal vulnerability (CVE-2026-65700) in its OpenAI-compatible files API, allowing unauthenticated remote attackers to achieve arbitrary file read, write, and delete, and ultimately remote code execution, by injecting traversal sequences into the bearer token.

h2oGPT 0.2.1 path-traversal rce api-vulnerability web-vulnerability critical-vulnerability
1r 3t 1c
high threat

CVE-2026-65919 Unauthenticated Arbitrary File Read in Meshery

Meshery versions prior to 1.0.57 are vulnerable to an unauthenticated arbitrary file read due to a path traversal flaw in the /api/system/fileView and /api/system/fileDownload API endpoints, allowing attackers to read arbitrary files from the host filesystem without authentication by supplying path traversal sequences.

exploited Meshery path-traversal arbitrary-file-read web-vulnerability
1r 1t 1c
high advisory

CyberPanel Missing Authorization Vulnerability Allows Cross-Tenant Backup Manipulation

A missing authorization vulnerability, identified as CVE-2026-65916, in CyberPanel through version 1.9.1 allows authenticated users to manipulate and destroy other tenants' backups by sending crafted POST requests to the `cancelBackupCreation` handler.

CyberPanel web-vulnerability authorization-bypass data-destruction cve
1r 2t 1c
critical advisory

Auth.js Email Normalizer Vulnerability Allows Homoglyph Bypass Leading to Account Takeover

A critical vulnerability in Auth.js libraries (next-auth and @auth/core) affects the email/magic-link sign-in flow, allowing an attacker to craft an email address with a homoglyph character that bypasses validation before Unicode normalization, leading to magic links being misrouted to attacker-controlled mailboxes and enabling account takeover without victim interaction.

next-auth +3 account-takeover authentication-bypass web-vulnerability magic-link unicode-normalization
2t
high advisory

CVE-2026-65898: DOMPurify Vulnerability Leads to Stored Cross-Site Scripting

A vulnerability in DOMPurify before version 3.4.11 allows attackers to achieve stored Cross-Site Scripting (XSS) by manipulating the `ALLOWED_ATTR` allowlist through an `uponSanitizeAttribute` hook, leading to client-side code execution.

DOMPurify xss javascript web-vulnerability client-side
2t 1c 2i
critical advisory

Bold Reports Standalone Report Designer Path Traversal Vulnerability (CVE-2026-65687)

CVE-2026-65687 describes a path traversal vulnerability in Bold Reports Standalone Report Designer prior to version 14.1.12, allowing an unauthenticated attacker to read arbitrary files from the server filesystem by exploiting a missing filepath validation flaw in the SVG processing feature, potentially leading to full unauthorized access via disclosure of sensitive server files like authentication credentials.

Bold Reports Standalone Report Designer +1 path-traversal arbitrary-file-read web-vulnerability critical-vulnerability
1r 2t 2c
high advisory

CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection

The Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.

Lumise Product Designer for WooCommerce wordpress woocommerce sql-injection web-vulnerability cve
1r 2t 1c
high advisory

SUMO Reward Points WordPress Plugin Vulnerable to Unauthenticated Stored XSS via REST API (CVE-2026-7534)

The SUMO Reward Points plugin for WordPress, versions up to and including 32.7.0, is vulnerable to CVE-2026-7534, an Unauthenticated Stored Cross-Site Scripting flaw that allows attackers to inject arbitrary web scripts into the reward points log via the `/wp-json/wc-srp/v1/earning` REST API endpoint, executing when an administrator accesses specific admin pages.

SUMO Reward Points plugin < 32.7.0 +1 wordpress xss web-vulnerability plugin stored-xss
1r 2t 1c
high advisory

Next.js App Router Middleware/Proxy Bypass Vulnerability (CVE-2026-64642)

A high-severity vulnerability, CVE-2026-64642, in Next.js App Router applications built with Turbopack and configured with a single locale entry allows attackers to bypass middleware and proxy-based authentication mechanisms through specially crafted HTTP requests, leading to unauthorized access to protected resources.

Next.js web-vulnerability middleware-bypass turbopack CVE-2026-64642
2t
high advisory

Next.js Server-Side Request Forgery and Open Redirect Vulnerability (CVE-2026-64645)

A vulnerability (CVE-2026-64645) in Next.js allows Server-Side Request Forgery (SSRF) and Open Redirect when `rewrites()` or `redirects()` rules in `next.config.js` use attacker-controlled input to construct external destination hostnames, enabling attackers to manipulate dynamic segments from the path or `has` captures to point the rewrite to an arbitrary hostname, potentially leading to internal network access, information disclosure, or redirection of users to malicious sites, affecting Next.js versions from 12.0.0 up to, but not including, 15.5.21, and versions from 16.0.0 up to, but not including, 16.2.11.

Next.js 12.x +6 ssrf open-redirect next.js web-vulnerability cve
2r 3t
high advisory

Eclipse Jetty Digest Authentication Bypass via ISO-8859-1 Encoding Flaw (CVE-2026-10050)

A vulnerability, CVE-2026-10050, in Eclipse Jetty's HTTP client `DigestAuthentication.apply()` method allows an authentication bypass by an attacker who can exploit the lossy ISO-8859-1 character encoding to forge Digest authentication response hashes for users with non-Latin-1 passwords.

Jetty jetty-security +8 web-vulnerability authentication-bypass java jetty iso-8859-1 character-encoding cve
1t
high advisory

LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback

An authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.

LiteLLM authentication-bypass api-security web-vulnerability
1t 1c
critical advisory

Grav Login Plugin Privilege Escalation (CVE-2026-65603)

A critical privilege escalation vulnerability, CVE-2026-65603, exists in the Grav Login plugin (grav-plugin-login) versions up to and including 3.8.11, allowing an authenticated low-privilege user to exploit a flaw in the `processUserProfile()` handler to bypass privilege stripping and escalate to super-admin, enabling admin panel access, remote code execution, and Twig evaluation.

Grav Login plugin privilege-escalation web-vulnerability grav cms
2t 1c
critical advisory

CVE-2026-65057 Server-Side Request Forgery in Keep Healthcheck Endpoint

An unauthenticated server-side request forgery (SSRF) vulnerability in Keep (commit 91c75e0) allows attackers to exploit an unprotected healthcheck endpoint by supplying crafted JSON payloads with malicious host values, forcing the backend to issue arbitrary HTTP requests to internal services or cloud metadata endpoints for internal network reconnaissance and theft of cloud credentials.

Keep SSRF vulnerability cloud web-vulnerability credential-theft
1r 2t 1c
high advisory

Gitea Server-Side Request Forgery Vulnerabilities

Two Server-Side Request Forgery (SSRF) vulnerabilities in Gitea version 1.26.2 and earlier allow authenticated users to bypass IP filtering for webhooks and repository migrations by targeting CGNAT and IPv6 transition prefixes, and unauthenticated users to trigger arbitrary GET requests against internal hosts via the OpenID sign-in form, potentially leading to internal network discovery and data exposure.

Gitea <= 1.26.2 ssrf gitea web-vulnerability internal-reconnaissance
1r 3t 1i
high advisory

SVGO removeScripts Plugin Bypass Leads to Cross-Site Scripting

A vulnerability in the SVGO library's `removeScripts` plugin, affecting versions prior to 2.8.3, 3.3.4, and 4.0.2, allowed namespaced script elements and case-insensitive JavaScript URIs to bypass sanitization, potentially leading to Cross-Site Scripting (XSS) in web applications serving untrusted SVGs.

SVGO +2 xss svg sanitization-bypass web-vulnerability
2t
high advisory

Gitea Repository Migration SSRF and Internal Git Repository Exfiltration

A critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.

Gitea +1 server-side-request-forgery ssrf vulnerability code-exfiltration data-exfiltration information-disclosure api-vulnerability web-vulnerability +5
2r 9t 1c
high advisory

Unauthenticated Input Validation Bypass in Ninja Forms WordPress Plugin (CVE-2026-65052)

An improper input validation vulnerability, identified as CVE-2026-65052, in Ninja Forms WordPress plugin versions 3.14.8 and prior allows unauthenticated attackers to tamper with form submission payloads to the ajax submit endpoint, injecting arbitrary numeric values into form calculations and payment totals, thereby bypassing admin-configured pricing logic and potentially reducing payment amounts to zero.

Ninja Forms WordPress plugin wordpress plugin improper-input-validation web-vulnerability financial-impact
1t 1c
critical advisory

WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)

An unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.

Easy Form Builder by WhiteStudio plugin for WordPress <= 4.0.11 wordpress plugin privilege-escalation web-vulnerability
1r 2t 1c
high advisory

CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability

A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.

DNS-320 1.0.2 web-vulnerability remote-code-execution file-upload d-link unrestricted-file-upload nas vulnerability unrestricted-upload +2
4r 4t 2i updated
high advisory

CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability

A high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.

MetaCRM cve rce unrestricted-upload web-vulnerability metasystem
1r 2t 1c
high advisory

Astro Authorization Bypass via Iterative Decode Limit and Canonicalization Mismatch

An authorization bypass vulnerability exists in Astro versions >= 6.4.7 and < 6.4.8, caused by a mismatch in URL path canonicalization, allowing an unauthenticated attacker to bypass middleware protections and access protected routes if the application relies on pathname-based authorization and uses rewrite behavior that performs route matching after middleware execution.

Astro authorization-bypass web-vulnerability nodejs
1r 2t 1c
critical advisory

LightRAG CORS Misconfiguration Allows Credentialed Cross-Origin Requests (CVE-2026-61736)

The LightRAG application, specifically the 'lightrag-hku' package, contains a critical vulnerability (CVE-2026-61736) due to its default Cross-Origin Resource Sharing (CORS) configuration, enabling any malicious website to perform authenticated API calls on behalf of a logged-in LightRAG user, leading to unauthorized data exfiltration or destructive actions.

lightrag-hku cors-misconfiguration web-vulnerability data-exfiltration cve
2t 1c
critical advisory

CVE-2026-63766: Unauthenticated OS Command Injection in GPT-SoVITS webui.py

An unauthenticated OS command injection vulnerability (CVE-2026-63766) in GPT-SoVITS through version 20250606v2pro's webui.py allows attackers to execute arbitrary operating system commands via shell metacharacters in Gradio textbox inputs, leading to remote code execution.

PoC GPT-SoVITS through 20250606v2pro +1 command-injection rce web-vulnerability ai/ml-model cve
1r 2t 1c 2i updated
high advisory

Adminer Cookie Injection Vulnerability via X-Forwarded-Prefix Header (CVE-2026-63771)

Adminer versions prior to 5.4.3 are vulnerable to a cookie injection flaw, which allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header, enabling cross-origin authenticated requests and bypassing cookie security controls.

Adminer < 5.4.3 web-vulnerability cookie-injection cve CWE-113
1r 1t 1c
high advisory

Server-Side Request Forgery in Huginn (CVE-2026-63769)

A server-side request forgery vulnerability, CVE-2026-63769, in Huginn through version 2022.08.18 allows authenticated users to make arbitrary HTTP requests via crafted URLs, leading to internal network probing, port enumeration, and potential credential theft from cloud metadata endpoints.

Huginn server-side-request-forgery web-vulnerability cve reconnaissance credential-access
1r 2t 1c
high advisory

Roo Code Command Injection Vulnerability (CVE-2026-63108)

A command injection vulnerability in Roo Code versions through 3.54.0 allows attackers to bypass allowlist/denylist enforcement in the auto-approve execute feature. By nesting command substitutions inside parameter expansion defaults, the command parser in parse-command.ts fails to detect the dangerous payloads, leading to their auto-approval and subsequent arbitrary command execution via the shell through execa.

Roo Code command-injection rce web-vulnerability cve
1r 1t 1c
low advisory

Tornado Quadratic DoS via Repeated HTTP Header Coalescing (CVE-2025-67725)

A quadratic Denial of Service (DoS) vulnerability exists in Tornado's `HTTPHeaders.add` method due to inefficient string concatenation for repeated header names, which, when processing a maliciously crafted HTTP request with numerous repeated headers, can block the server's single event loop for an extended period, leading to a high severity DoS if `max_header_size` is increased from its default 64KB.

Tornado denial-of-service web-vulnerability python
1t 1c
high advisory

Tenda AC10 Buffer Overflow Vulnerability (CVE-2026-16248)

A stack-based buffer overflow vulnerability (CVE-2026-16248) has been identified in Tenda AC10 firmware version 16.03.10.09_multi_TDE01, residing in the fromAdvSetLanip function of the /goform/AdvSetLanip file within the httpd/netctrl component, which can be remotely exploited by manipulating the GetValue/SetValue argument, with a public exploit now available.

AC10 16.03.10.09_multi_TDE01 buffer-overflow rce firmware router web-vulnerability cve
2t 1c 6i
low advisory

Web Server Local File Inclusion Activity

This brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.

Nginx +4 local-file-inclusion web-vulnerability information-disclosure remote-code-execution discovery
1r 4t 1i
high advisory

Shibboleth Service Provider SQL Injection Vulnerability

A remote, unauthenticated attacker can exploit a SQL Injection vulnerability within the Shibboleth Service Provider software, allowing them to perform unauthorized database queries and potentially extract or manipulate sensitive data.

Shibboleth Service Provider sql-injection web-vulnerability authentication shibboleth
1t
high advisory

QueryWeaver Authentication Bypass via Signup Request (CVE-2026-10130)

CVE-2026-10130 describes an authentication bypass vulnerability in QueryWeaver, enabling unauthenticated attackers to obtain valid session tokens for existing user accounts by submitting a crafted signup request with a known victim's email address, leveraging a Cypher MERGE operation that unconditionally links a new token before checking for existing accounts.

QueryWeaver authentication-bypass cve web-vulnerability
3t 1c
low advisory

CVE-2024-58368: SurrealDB Denial-of-Service via Malformed HTTP Headers

Unauthenticated attackers can exploit CVE-2024-58368 in SurrealDB versions prior to 1.1.0 by sending crafted HTTP REST API requests with malformed ID, DB, or NS headers, leading to an uncaught exception and server crash, resulting in denial of service.

SurrealDB denial-of-service web-vulnerability database http-api cve
1t 1c
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
high advisory

Authenticated Full-Read SSRF in CloudTAK /api/esri* Routes

An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in CloudTAK's `/api/esri*` routes, allowing any authenticated user to compel the server to make arbitrary outbound HTTP requests to internal network resources, enabling attackers to access sensitive cloud instance metadata, enumerate internal services, and exfiltrate data by reflecting the response bodies.

CloudTAK <= 13.7.0 ssrf web-vulnerability credential-access network-discovery cloud-security
1r 3t 2i
critical advisory

IBM Langflow OSS Remote Code Execution via Deserialization

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.

Langflow OSS 1.0.0 +13 remote-code-execution deserialization python langflow web-vulnerability rce authentication-bypass critical-vulnerability +7
1r 5t 7c 1i
critical advisory

IBM Engineering AI Hub Cross-site Scripting Vulnerability (CVE-2026-15091)

A critical cross-site scripting (XSS) vulnerability, identified as CVE-2026-15091 with a CVSS v3.1 score of 9.3, affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, allowing a remote attacker to execute arbitrary scripts due to improper input neutralization during web page generation.

Engineering AI Hub +2 cve xss web-vulnerability
2t 1c
high advisory

Flask-Reuploaded Extension Denylist Bypass via Case-Folding Asymmetry

An incomplete fix for CVE-2026-27641 in Flask-Reuploaded versions up to and including 1.5.0 allows attackers to bypass extension denylists through case-folding asymmetry, enabling the upload of malicious files with dangerous extensions (e.g., shell.PHP) that can lead to remote code execution on case-insensitive execution environments.

Flask-Reuploaded <= 1.5.0 web-vulnerability file-upload rce python flask incomplete-fix
3t 1c
high advisory

meta-ads-mcp Authentication Bypass via X-Pipeboard-Token Header

An authentication bypass vulnerability in `meta-ads-mcp` version 1.0.113 allows unauthenticated network callers to gain unauthorized access by sending an arbitrary value in the `X-Pipeboard-Token` HTTP header, leading to the reuse of the server operator's `META_ACCESS_TOKEN` for full read and write access to Meta Ads data.

meta-ads-mcp authentication-bypass web-vulnerability meta python cwe-287
3t
critical advisory

IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)

Unauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.

PoC Langflow OSS +3 remote-code-execution api-exploitation unauthenticated-access code-injection web-vulnerability ai-llm
1r 3t 3c 2i updated
high advisory

FreePBX Modules Vulnerable to Unauthenticated RCE and SQL Injection

Multiple critical vulnerabilities have been identified in FreePBX modules, including unauthenticated remote code execution (RCE) in the UCP module, unauthenticated SQL injection in the missedcall module leading to administrator takeover, authenticated command injection in the TTS module, and authenticated RCE in the music module. These flaws affect specific versions of these modules across FreePBX 16 and 17, allowing attackers to execute arbitrary commands, bypass authentication, and gain administrative control.

FreePBX Security-Reporting ucp +7 freepbx rce sql-injection command-injection web-vulnerability asterisk
2r 5t
high threat

Vulnerability in poco-ai poco-claw Leads to Server-Side Request Forgery (CVE-2026-16016)

A high-severity server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16016, exists in poco-ai's poco-claw software up to version 0.5.4, allowing remote attackers to manipulate the `callback_url` argument in the `run_task` function to force the server to make arbitrary requests, with a public exploit available posing an immediate risk.

exploited poco-claw <= 0.5.4 server-side-request-forgery ssrf web-vulnerability python remote-code-execution cve
1r 2t 1c
high advisory

Kali Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via digitalSignature Field

The Kali Forms - Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'digitalSignature' field in versions up to and including 2.4.18, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an affected page.

Kali Forms - Contact Form & Drag-and-Drop Builder wordpress plugin xss web-vulnerability stored-xss
1r 6t 1c
high advisory

Grav API Plugin Vulnerable to CORS Misconfiguration Allowing Data Exposure and Unauthorized Operations

The Grav API plugin before version 1.0.0-rc.16 contains a CORS misconfiguration that sets `Access-Control-Allow-Origin: *` by default, enabling an attacker to perform authenticated cross-origin requests from a malicious website after obtaining a valid API token, leading to sensitive data exfiltration and unauthorized write operations.

Grav API plugin web-vulnerability cors misconfiguration data-exfiltration rce-potential
1r 3t 1c
high advisory

Grav .htaccess Case-Insensitivity Bypass for Sensitive File Access

An unauthenticated attacker can exploit a flaw in Grav prior to version 2.0.4 where the default .htaccess file's rules for blocking access to sensitive file types are case-sensitive, allowing bypass on case-insensitive filesystems (Windows, macOS, or Docker volume mounts) by requesting sensitive configuration files (e.g., .yaml, .php, .json) using uppercase or mixed-case extensions, leading to unauthorized reading of files that may contain API keys and credentials.

Grav < 2.0.4 web-vulnerability information-disclosure grav
1r 3t 1c
critical advisory

Pheditor Hardcoded Admin Password Leads to Remote Code Execution (CVE-2026-55579)

Pheditor contains a critical vulnerability (CVE-2026-55579) where a hardcoded default password 'admin' with no forced change mechanism upon first login allows an unauthenticated attacker to gain full administrative access, enabling arbitrary file read/write and remote code execution through the application's terminal feature, leading to complete server compromise.

Pheditor +1 hardcoded-credentials rce web-application cve web-vulnerability command-injection php
1r 5t
high advisory

Pheditor Authenticated Command Whitelist Bypass via Shell Command Substitution

Pheditor 2.0.4 contains an authenticated command injection vulnerability, CVE-2026-54540, allowing a user with `terminal` permissions to bypass the `TERMINAL_COMMANDS` whitelist by leveraging shell command substitution to execute arbitrary shell commands as the web server user.

Pheditor 2.0.4 web-vulnerability command-injection php
1r 1t
high advisory

AVideo OS Command Injection Vulnerability (CVE-2026-63304)

AVideo versions up to and including 29.0 are vulnerable to an OS command injection (CVE-2026-63304) in the `listFFmpegProcesses()` function within `plugin/API/standAlone/functions.php`, allowing attackers to craft an encrypted `codeToExec` payload to bypass single-quote escaping and execute arbitrary operating system commands as the web-server user, leading to remote code execution.

AVideo os-command-injection rce web-vulnerability cve
1r 1t 1c 2i
high threat

Vulnerability in Ruby on Rails Allows Remote Indirect Code Injection (XSS)

A cross-site scripting (XSS) vulnerability has been discovered in Ruby on Rails versions prior to 1.7.1, enabling a remote attacker to perform an indirect remote code injection, allowing malicious scripts to be executed in the client's browser.

exploited Ruby on Rails < 1.7.1 xss web-vulnerability ruby-on-rails cross-site-scripting
1t 1i
high advisory

WordPress Digits Plugin Privilege Escalation via Missing Authorization

The Digits: WordPress Mobile Number Signup and Login plugin is vulnerable to privilege escalation, allowing authenticated attackers with Subscriber-level access to elevate privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, impacting WordPress sites configured with the built-in DIGITS User Role field.

Digits: WordPress Mobile Number Signup and Login plugin <= 9.1.0.5 wordpress privilege-escalation web-vulnerability cve
1r 1t 1c
high advisory

RPB Chessboard WordPress Plugin Vulnerable to Stored Cross-Site Scripting

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its comment content functionality, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user views the affected page, bypassing WordPress's default kses sanitization.

RPB Chessboard wordpress xss web-vulnerability
1t 1c
high advisory

SQL Injection Vulnerability in WordPress WooCommerce Advanced Product Search Plugin (CVE-2026-12753)

A SQL Injection vulnerability, CVE-2026-12753, has been identified in the Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress, affecting all versions up to and including 1.4.4. The flaw, caused by insufficient input sanitization of the 's' and 'match' parameters and inadequate SQL query preparation, allows unauthenticated attackers to append arbitrary SQL queries. This enables them to extract sensitive information directly from the database.

Advance Product Search- Voice & Ajax Search for WooCommerce plugin wordpress woocommerce sql-injection web-vulnerability
1r 2t 1c
high advisory

SQL Injection Vulnerability in H3C SecPath F1000-C8300 (CVE-2026-15907)

A SQL injection vulnerability, CVE-2026-15907, exists in H3C SecPath F1000-C8300 appliances up to version 20260522, allowing remote attackers to manipulate the 'subject' argument in the '/webui/?g=log_fw_nbc_mail_jsondata' endpoint to execute arbitrary SQL commands, potentially leading to unauthorized data access or system compromise, with a publicly available exploit.

SecPath F1000-C8300 sql-injection web-vulnerability h3c cve
1r 1t 1c 5i
high advisory

TensorZero Gateway Arbitrary File Read and SSRF Vulnerability

A high-severity vulnerability (CVE-2026-54457) in the TensorZero Gateway's `/internal/object_storage` endpoint allows attackers to achieve arbitrary file reading from the gateway filesystem and Server-Side Request Forgery (SSRF) by manipulating the `storage_path` parameter, potentially leading to credential exposure and internal network reconnaissance.

pip/tensorzero arbitrary-file-read ssrf web-vulnerability credential-access discovery cloud pip-package
1r 3t
high advisory

Gravity Forms Directory Traversal Vulnerability (CVE-2026-12997)

Unauthenticated attackers can exploit a Directory Traversal vulnerability (CVE-2026-12997) in the Gravity Forms plugin for WordPress, affecting all versions up to and including 2.10.4, to read arbitrary files on the server and receive their contents as an email attachment, potentially exfiltrating sensitive information.

Gravity Forms plugin wordpress plugin web-vulnerability collection network
1r 2t 1c
critical advisory

MantisBT Reflected XSS Vulnerabilities in admin/install.php (CVE-2026-52847)

MantisBT versions 2.28.3 and earlier are vulnerable to six reflected XSS injection points in the `/admin/install.php` script, which attackers can exploit without authentication to perform credential phishing, open redirects, and UI manipulation due to an incomplete Content Security Policy.

composer/mantisbt/mantisbt xss web-vulnerability credential-theft phishing open-redirect
1r 4t
high advisory

Kanboard Vulnerability CVE-2026-58660 Allows Cross-Project Task Manipulation

A high-severity vulnerability, CVE-2026-58660, in Kanboard versions up to 1.2.52 allows any authenticated user to enumerate, move, corrupt, or hide tasks belonging to any project on the same instance, including private projects, due to improper validation in the BoardAjaxController save() method.

Kanboard web-vulnerability privilege-escalation data-manipulation
3t 1c
high advisory

Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)

A Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.

Splunk Enterprise < 9.4.13 +14 splunk vulnerability csrf remote-code-execution credential-access data-exfiltration web-vulnerability
4t 3c updated
high advisory

MantisBT Remote Code Execution via Class Hoisting (CVE-2026-49273)

A high-severity remote code execution vulnerability, CVE-2026-49273, affects MantisBT versions 2.28.3 and earlier, allowing an authenticated administrator to achieve arbitrary code execution as the web server user by leveraging PHP's class hoisting during the processing of non-string configuration values in `adm_config_set.php`.

MantisBT remote-code-execution web-application php class-hoisting xss web-vulnerability
1r 1t
critical advisory

MantisBT SOAP API Authentication Bypass and Privilege Escalation (CVE-2026-47156)

A critical authentication bypass vulnerability, CVE-2026-47156, exists in the SOAP API's mci_check_login() function of MantisBT versions 2.28.3 and earlier, allowing an unauthenticated attacker to impersonate any user, including an administrator, by knowing a valid cookie_string and the target username, without needing the target's password, which can lead to full administrator access, extensive data exfiltration, and destructive operations when default self-registration is enabled.

MantisBT authentication-bypass privilege-escalation web-vulnerability cve
2t
critical advisory

MantisBT SQL Injection via history_order Configuration Value

MantisBT versions 2.28.3 and earlier are vulnerable to a SQL injection within the `history_order` configuration value in `core/history_api.php`, allowing an authenticated administrator to inject malicious SQL via the web UI or REST API, which then executes whenever any user views a bug with history entries, leading to sensitive data extraction and potential Remote Code Execution (RCE) via webshell if the MySQL FILE privilege is enabled.

MantisBT <= 2.28.3 sql-injection web-application vulnerability rce mantisbt xss web-vulnerability credential-phishing
2r 8t
high advisory

Grav Form Plugin Arbitrary File Write Vulnerability (CVE-2026-61873)

Grav before version 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, allowing attackers to bypass path traversal validation via Twig template processing and write PHP webshells for remote code execution.

Grav arbitrary-file-write rce web-vulnerability cms path-traversal
1r 3t 1c
high advisory

Grav API Plugin File Upload Extension Bypass Leading to RCE

A vulnerability (CVE-2026-61457) in the Grav API plugin before version 1.0.3 allows an authenticated attacker with `api.media.write` permissions to bypass file upload extension validation using double extensions, which can lead to remote code execution on the web server.

Grav API plugin web-vulnerability remote-code-execution extension-bypass grav
1r 3t 1c
high advisory

PraisonAI MCP HTTP-Stream Authentication Bypass (CVE-2026-61427)

PraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability, CVE-2026-61427, in the MCP HTTP-stream transport, allowing unauthenticated clients to establish sessions, enumerate tools, and invoke tools, potentially leading to remote code execution if the server is bound to a network-accessible address.

PraisonAI < 4.6.78 authentication-bypass remote-code-execution web-vulnerability ai-ml network
1r 3t 1c
high advisory

Grav Flex Objects Plugin Stored Template Injection Leading to RCE

A stored server-side template injection vulnerability, identified as CVE-2026-58655, exists in the Grav Flex Objects plugin before version 1.4.0, allowing an attacker to achieve arbitrary Twig execution and remote command execution by injecting malicious code into user-controlled title frontmatter that bypasses sanitization.

Grav Flex Objects plugin < 1.4.0 template-injection rce web-vulnerability cms grav php
1r 1t 1c
high advisory

Open WebUI Stored Cross-Site Scripting Vulnerability (CVE-2026-56398)

Open WebUI before version 0.9.5 contains a high-severity stored cross-site scripting (XSS) vulnerability, CVE-2026-56398, in its OAuth authentication flow that allows an authenticated attacker to bypass profile image validation by uploading malicious SVG files, leading to script execution, authentication token theft, and ultimately account takeover for other authenticated users.

Open WebUI xss web-vulnerability account-takeover credential-access
2t 1c
critical advisory

CVE-2026-61451: Unauthenticated Account Takeover in Grav API Plugin via Password Reset Vulnerability

An unauthenticated attacker can exploit CVE-2026-61451 in Grav API plugin versions prior to 1.0.4, leveraging improper URL validation in the password reset functionality to specify an arbitrary host in the reset link, thereby disclosing valid reset tokens to an attacker-controlled server and enabling full account takeover.

Grav API plugin web-vulnerability account-takeover password-reset grav api
1r 3t 1c
high advisory

Zhinianboke Xianyu-Auto-Reply Missing Authorization Vulnerability (CVE-2026-15752)

A missing authorization vulnerability (CVE-2026-15752) exists in the /api/v1/users/ endpoint of zhinianboke xianyu-auto-reply, affecting versions up to commit dcb445ad97816ad65299a7580ee0c8c8f929da84, allowing a remote attacker to bypass authentication or authorization checks. An exploit for this vulnerability has been made public, and organizations using this product should apply the patch named 19fc3282a1bb78a05c34945c088525d20e081cbd to mitigate the risk.

xianyu-auto-reply vulnerability authorization-bypass cve web-vulnerability network
1t 1c
high advisory

CAI Content Credentials Server-Side Request Forgery Leads to Arbitrary Code Execution

CAI Content Credentials is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-48290, which an attacker can exploit to achieve arbitrary code execution and potentially gain elevated access by injecting malicious scripts into a web page, requiring user interaction to succeed.

Content Credentials server-side-request-forgery ssrf arbitrary-code-execution web-vulnerability cve
2t 1c
high advisory

Unauthenticated API Key Use in NetLicensing-MCP HTTP Mode

An unauthenticated vulnerability exists in netlicensing-mcp (version 0.1.5 and earlier) when operating in HTTP transport mode, where the ApiKeyMiddleware fails to enforce authentication for requests lacking a client API key, causing the application to fall back to the server's NETLICENSING_API_KEY environment variable for upstream calls, allowing an unauthenticated network attacker to invoke any MCP tool under the server operator's identity and account quota.

netlicensing-mcp web-vulnerability missing-authentication api-security supply-chain http
5t
critical advisory

Command Injection in Sustainable Irrigation Platform cli_control Plugin

A critical command injection vulnerability (CVE-2026-58479) exists in the optional cli_control plugin of Sustainable Irrigation Platform (SIP) versions up to 5.2.16, allowing unauthenticated or CSRF attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating an associated irrigation station.

Sustainable Irrigation Platform +1 command-injection web-vulnerability rce ot ics cve-2026-58479
3t 3c
medium advisory

Apache ActiveMQ Cross-Site Scripting Vulnerability

A remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Apache ActiveMQ to execute malicious scripts within a victim's browser.

ActiveMQ xss web-vulnerability apache
1t
high advisory

Remote SQL Injection Vulnerability in code-projects Online Job Portal (CVE-2026-15676)

A high-severity SQL injection vulnerability, CVE-2026-15676, exists in code-projects Online Job Portal up to version 1.0, allowing remote unauthenticated attackers to manipulate the database via the /Admin/DeleteUser.php file with a publicly available exploit.

Online Job Portal <= 1.0 sql-injection web-vulnerability cve
1r 2t 1c
high advisory

CVE-2026-44752: SAP NetWeaver Application Server Java Cross-Site Scripting Vulnerability

An unauthenticated attacker can exploit a cross-site scripting (XSS) vulnerability (CVE-2026-44752) in SAP NetWeaver Application Server Java by injecting malicious JavaScript through crafted URLs, leading to client-side script execution, access to sensitive session information, and modification of non-sensitive data, resulting in high confidentiality impact and low integrity impact.

SAP NetWeaver Application Server Java xss sap java web-vulnerability
3t 1c
high advisory

CVE-2026-61462 - mcp-gitlab Path Traversal Vulnerability Leading to Unauthorized API Access

A path traversal vulnerability, CVE-2026-61462, in the job_id parameter of build/index.js within mcp-gitlab allows attackers to redirect GitLab API requests to arbitrary endpoints by escaping the intended path prefix, leveraging the operator's personal access token for unauthorized access.

mcp-gitlab path-traversal gitlab web-vulnerability cve
1r 2t 1c
critical advisory

Rejetto HFS Vulnerability Allows Remote Code Execution via Session Forgery (CVE-2026-61500)

A remote attacker can exploit a critical vulnerability, CVE-2026-61500, in Rejetto HFS versions 3.0.0 through 3.2.0 by recovering the session-cookie signing key due to poor randomness, forging an administrator session, and achieving remote code execution.

HFS web-vulnerability rce session-hijacking
4t 1c
high advisory

NukeViet Server-Side Request Forgery via X-Forwarded-Host (CVE-2026-55372)

An unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in NukeViet by spoofing the X-Forwarded-Host and X-Forwarded-Proto HTTP headers, allowing the server to make a cURL request to an attacker-controlled host without validation for internal host/port discovery and cache poisoning. The vulnerability affects NukeViet versions prior to 4.6.00.

nukeviet < 4.6.00 ssrf web-vulnerability nukeviet
2t
high advisory

NukeViet Multiple Anti-XSS Filter Bypasses Leading to Stored XSS

Two filter-bypass techniques in NukeViet\Core\Request allow a low-privileged user with news-posting permission to store and execute arbitrary JavaScript in the browsers of any visitor to an affected page, leading to session cookie theft, credential harvesting, defacement, and further privilege escalation via CVE-2026-54064.

NukeViet xss web-vulnerability cms cross-site-scripting filter-bypass
2t
high advisory

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

An authenticated administrator in NukeViet is vulnerable to a path traversal flaw (CVE-2026-54065) in the Edit Comment admin function, allowing an attacker to inject a crafted `attach` parameter which, upon comment deletion, leads to arbitrary file deletion within the application root, causing a full application outage and exposing the install wizard.

NukeViet path-traversal arbitrary-file-deletion web-vulnerability cms
1r 2t
high advisory

NukeViet CMS Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting (XSS) vulnerability, CVE-2026-49259, exists in NukeViet CMS versions 4.x through 4.5.08, including the 'composer/nukeviet/nukeviet' package prior to version 4.5.09, which allows a low-privileged authenticated user to inject JavaScript into their profile's display name fields that executes in the browser of any visitor, including administrators, who clicks the 'Reply' link on a comment posted by the attacker, leading to arbitrary JavaScript execution, administrative session hijacking, credential phishing, and data exfiltration.

NukeViet CMS < 4.5.09 +1 xss web-vulnerability cms nukeviet stored-xss
1r 2t
high advisory

Decidim Vulnerability Allows Unauthorized Access to Identity Documents via Reusable Signed URLs

A high-severity vulnerability (CVE-2026-45378) in Decidim's identity document verification workflow allows unauthorized access to sensitive identity documents. Signed `/rails/active_storage/disk/` URLs, which are generated for administrator review, can be harvested and replayed by unauthenticated users for up to seven days, enabling attackers to bypass authentication and download highly sensitive personal information if these URLs are leaked through various channels.

Decidim +2 web-vulnerability access-control data-leakage rails active-storage
1r 1t
high advisory

CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0

A remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.

Online Book Store System 1.0 web-vulnerability sql-injection authentication-bypass remote-code-execution
1t 1c
critical threat

Drupal AlternativeCommerce (Basket) Module Vulnerability Allows Code Execution

A critical vulnerability in the Drupal 'AlternativeCommerce' (Basket) module allows a remote, unauthenticated attacker to execute arbitrary program code. This can lead to full compromise of the affected web application.

exploited AlternativeCommerce drupal rce web-vulnerability
2t
high advisory

Metasoft MetaCRM SQL Injection Vulnerability (CVE-2026-15514)

A critical SQL injection vulnerability (CVE-2026-15514) in Metasoft MetaCRM up to version 6.4.0 Beta06 allows remote attackers to exploit the RPCService.query function via the phprpc_args argument in /customizemt/xkq/rpc.jsp, leading to unauthorized database access and manipulation, with a public exploit available.

MetaCRM up to 6.4.0 Beta06 sql-injection web-vulnerability crm remote-code-execution
1r 1t 1c
high advisory

LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)

LuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.

LuCI xss web-vulnerability network-device router dhcpv6
1t 1c
high advisory

CVE-2026-61875: Stored Cross-Site Scripting in OpenWrt luci-app-upnp

CVE-2026-61875 details a stored cross-site scripting vulnerability in OpenWrt's luci-app-upnp that allows unauthenticated LAN clients to inject malicious JavaScript into UPnP IGD AddPortMapping SOAP requests, leading to client-side code execution in an administrator's browser when viewing specific web interface pages.

luci-app-upnp cross-site-scripting xss openwrt router web-vulnerability client-side-execution
2t 1c
high advisory

CVE-2026-15489: SQL Injection in RafyMrX TOKO-ONLINE-ROTI login.php

A critical SQL injection vulnerability (CVE-2026-15489) exists in RafyMrX TOKO-ONLINE-ROTI, allowing remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument in the 'proses/login.php' file, with a public exploit available.

TOKO-ONLINE-ROTI web-vulnerability sql-injection initial-access public-exploit web-exploitation cve remote-code-execution
2r 4t 1c
high advisory

SQL Injection Vulnerability in Aster Telecom Azcall (CVE-2026-15482)

A critical SQL injection vulnerability, tracked as CVE-2026-15482, exists in Aster Telecom Azcall 10/11 within the HTTP Handler component, where manipulating the 'nome/perfil/status' argument when accessing '/azcall/adm/gestao_loja/sis.php?t=consultar' can lead to remote SQL injection, with a publicly available exploit allowing unauthenticated attackers to potentially access or modify sensitive data.

Azcall 10/11 sql-injection web-vulnerability cve exploit-available
1r 1t 1c
high advisory

WP CTA Plugin Vulnerable to Unauthenticated Time-Based Blind SQL Injection (CVE-2026-4661)

The WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in versions up to and including 2.2.2. This vulnerability is due to insufficient escaping of user-supplied column names and lack of preparation in database queries. Unauthenticated attackers can exploit this by injecting arbitrary SQL queries to extract sensitive information, including administrator password hashes, from the database.

WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin <= 2.2.2 wordpress plugin sql-injection time-based-blind unauthenticated web-vulnerability
1r 2t 1c
critical advisory

The Swiss Toolkit For WP Plugin Vulnerable to Arbitrary File Upload Leading to RCE (CVE-2026-2354)

A critical arbitrary file upload vulnerability (CVE-2026-2354) exists in The Swiss Toolkit For WP plugin for WordPress, affecting all versions up to and including 1.4.6. The flaw, located in the `upload_extension_files()` function, allows authenticated attackers with Author-level access or higher to bypass file type validation due to an improper `strpos()` check, enabling the upload of arbitrary files, including PHP scripts, which can lead to remote code execution on the server if the "Enhanced Multi-Format Image Support" feature is active with at least one configured extension.

The Swiss Toolkit For WP plugin +1 wordpress plugin file-upload rce web-vulnerability
1r 3t 1c
high advisory

WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection

The Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.

Booking Package plugin <= 1.7.20 wordpress sqli web-vulnerability cms
1t 1c
high advisory

SiYuan Stored XSS via Malicious Bazaar Package README

A stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-54070, affects SiYuan versions up to 3.6.5, allowing a malicious third-party package author to embed JavaScript in package READMEs via an incomplete HTML sanitizer's blocklist, which executes in an Administrator's authenticated browser session upon viewing and interacting with the crafted README in the Bazaar marketplace, leading to API token theft and potential full workspace control.

siyuan-note/siyuan +2 xss web-vulnerability code-execution credential-theft si-yuan
5t 1c
critical advisory

SiYuan Unauthenticated Admin API Access via Chrome Extension Allowlist

A critical vulnerability (CVE-2026-54069) in SiYuan Note kernel's HTTP server allows any Chrome/Chromium browser extension to gain unauthenticated RoleAdministrator access, enabling data exfiltration, stored XSS injection, and configuration tampering for SiYuan desktop users, including via compromised legitimate extensions.

SiYuan Note +1 web-vulnerability privilege-escalation data-exfiltration xss supply-chain desktop-application chrome-extension siyuan
1r 6t 1c 1i
high advisory

FileBrowser Authentication Bypass via Forged Proxy Authentication Header

An unauthenticated attacker can impersonate any user, including administrators, or automatically create new user accounts in FileBrowser by forging the `X-Remote-User` HTTP header when the server is configured for proxy authentication and is directly reachable, leading to full administrative control and unauthorized access to data.

FileBrowser authentication-bypass web-vulnerability privilege-escalation file-browser account-creation
1r 3t
high advisory

SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding

An incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.

siyuan kernel path-traversal vulnerability web-vulnerability arbitrary-file-read
1r 3t 2c 1i
high advisory

Dify MyScale Backend SQL Injection Vulnerability (CVE-2026-61461)

A high-severity SQL injection vulnerability, CVE-2026-61461, exists in the MyScale vector store backend of Dify versions prior to 1.16.0-rc1, allowing attackers with low privileges to execute arbitrary SQL commands via unsanitized search parameters, leading to unauthorized data manipulation in the underlying ClickHouse database.

Dify sql-injection web-vulnerability clickhouse
1r 4t 1c
critical threat

CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE

A critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.

exploited Forms vulnerability web-vulnerability rce file-upload cisa-kev
1r 2t 1c
high advisory

Crawl4AI Server-Side Request Forgery Vulnerability (CVE-2026-56261)

Crawl4AI versions before 0.8.7 contain a server-side request forgery (SSRF) vulnerability, CVE-2026-56261, in its Docker API server's webhook endpoints, allowing an attacker to coerce the server into making requests to internal services and potentially expose cloud metadata.

Crawl4AI ssrf web-vulnerability docker cloud-security
2t 1c
high advisory

Lucee CFML Server Reflected XSS Vulnerability (CVE-2026-29519)

Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines are vulnerable to a reflected cross-site scripting (XSS) flaw in URL path parsing, allowing unauthenticated remote attackers to embed arbitrary HTML or JavaScript payloads within the request path which, when visited by a victim, enables the execution of arbitrary JavaScript in the victim's browser for purposes such as session hijacking or unauthorized actions against the Lucee administrative interface.

Lucee CFML Server +3 xss web-vulnerability cve network lucee
1r 2t 1c
high advisory

CVE-2026-15330: zhayujie CowAgent Server-Side Request Forgery

A critical server-side request forgery (SSRF) vulnerability, CVE-2026-15330, exists in zhayujie CowAgent up to version 2.1.1, allowing remote attackers to manipulate the 'image' argument in the Vision Tool component's `_build_image_content` or `_download_to_data_url` functions to access internal resources or conduct port scanning.

CowAgent web-vulnerability ssrf remote-code-execution network
1r 1t 1c
high advisory

CVE-2026-15290: Ultimate Member Plugin Blind SQL Injection

The Ultimate Member plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to and including 2.10.1, due to insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 wordpress plugin sql-injection web-vulnerability
1r 2t 2c
high advisory

CVE-2026-13430: WordPress Post Export Import with Media Plugin Arbitrary File Upload Leading to RCE

A high-severity arbitrary file upload vulnerability, CVE-2026-13430, exists in all versions up to 1.13.1 of the Post Export Import with Media plugin for WordPress, allowing authenticated administrators to upload executable web shells via a trailing-dot filename bypass, leading to remote code execution.

Post Export Import with Media plugin web-vulnerability wordpress arbitrary-file-upload rce
1r 2t 1c
critical advisory

CVE-2026-58122: Hermes WebUI Authentication Bypass via Spoofed X-Forwarded-For Header

CVE-2026-58122 describes an authentication bypass vulnerability in Hermes WebUI before version 0.51.307, allowing unauthenticated remote attackers to bypass local-origin IP restrictions on onboarding endpoints by spoofing the X-Forwarded-For header with a loopback address, leading to server-side request forgery (SSRF), API key overwrites, and persistent access token acquisition.

Hermes WebUI < 0.51.307 authentication-bypass ssrf web-vulnerability credential-theft persistence cloud network
1r 4t 1c
high advisory

YesWiki Unauthenticated ActivityPub Signature-Verification Bypass (CVE-2026-52767)

A critical vulnerability, CVE-2026-52767, in YesWiki's `HttpSignatureService::verifySignature()` allows unauthenticated attackers to bypass ActivityPub signature verification due to a loose boolean negation (`!openssl_verify(...)`) accepting `int(-1)` from PHP's `openssl_verify()` under specific conditions, enabling arbitrary Create, Update, and Delete operations on ActivityPub-enabled forms leading to defacement and content manipulation.

composer/yeswiki/yeswiki web-vulnerability php activitypub signature-bypass cve unauthenticated-access
1r 3t
high advisory

YesWiki Unauthenticated SSRF via ActivityPub Signature.keyId (CVE-2026-52769)

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52769, exists in YesWiki's `POST /api/forms/{formId}/actor/inbox` route when ActivityPub is enabled, allowing attackers to force arbitrary outbound HTTP GET requests to internal or external hosts and potentially exfiltrate sensitive information via timing and error messages.

YesWiki ssrf web-vulnerability php unauthenticated cve
1r 3t 1i
high advisory

CVE-2026-9253: WordPress E&P Forms Plugin Stored Cross-Site Scripting

An unauthenticated attacker can inject arbitrary web scripts into WordPress sites running the 'WP Cost Estimation & Payment Forms Builder' plugin version 10.5.97 and earlier by exploiting CVE-2026-9253, a Stored Cross-Site Scripting vulnerability via the 'customerInfos' parameter, leading to script execution in users' browsers and potential session hijacking or data theft.

WP Cost Estimation & Payment Forms Builder wordpress xss web-vulnerability plugin
2t 1c
high advisory

EventPrime WordPress Plugin Stored XSS (CVE-2026-13441)

A critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-13441, exists in all versions up to 4.3.4.2 of the EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress, allowing authenticated attackers with custom-level access (or unauthenticated attackers if 'Guest Submissions' is enabled) to inject malicious web scripts via the new_event_type_background_color parameter that execute whenever a user accesses an affected page, potentially leading to session hijacking, defacement, or further compromise.

EventPrime – Events Calendar, Bookings and Tickets plugin web-vulnerability wordpress xss plugin
1r 2t 1c
critical advisory

CVE-2026-5955: Critical SQL Injection in Inrove BiEticaret

A critical SQL injection vulnerability (CVE-2026-5955) in Inrove Software and Internet Services BiEticaret, affecting versions before v3.3.57, allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to data exfiltration and full system compromise.

BiEticaret < v3.3.57 sql-injection web-vulnerability critical-vulnerability data-exfiltration webserver
1r 1t 1c
high advisory

CVE-2026-38969: Ruby WEBrick Request Smuggling Vulnerability

A high-severity vulnerability, CVE-2026-38969, exists in Ruby WEBrick versions up to v1.9.2 due to improper re-parsing of the 'trailer Content-Length' header, enabling HTTP request smuggling that attackers can exploit to bypass security controls and gain unauthorized access or execute arbitrary requests.

WEBrick through v1.9.2 web-vulnerability request-smuggling server-side cve ruby
2t 1c
medium advisory

Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification

Multiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.

Joomla cms vulnerability xss web-vulnerability data-integrity
1t
high advisory

Gradio Open Redirect and Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-59806)

Gradio versions before 6.20.0 contain an open redirect and server-side request forgery (SSRF) vulnerability, CVE-2026-59806, allowing attackers to redirect users or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the `/gradio_api/file=` endpoint, potentially leading to the retrieval of sensitive credentials, such as EC2 IAM role credentials.

Gradio < 6.20.0 web-vulnerability ssrf open-redirect credential-access cloud gradio
1r 2t 1c
critical advisory

Unauthenticated SQL Injection in IBM API Connect (CVE-2026-9074)

IBM API Connect versions 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 are vulnerable to an unauthenticated SQL injection (CVE-2026-9074) in the password reset functionality, potentially leading to unauthorized data access or authentication bypass.

API Connect +13 sql-injection web-vulnerability critical-vulnerability api-management
1r 3t 1c
high advisory

CVE-2026-59703: repomix Local File Inclusion Vulnerability

repomix contains a local file inclusion vulnerability (CVE-2026-59703) in its git clone endpoint, allowing unauthenticated attackers to read arbitrary local git repositories and server filesystem contents by bypassing validation with crafted file:// URLs.

repomix < 1.14.1 local-file-inclusion web-vulnerability cve repomix
1r 2t 1c
high advisory

CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover

A critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.

Grav API plugin grav api-plugin jwt cors remote-code-execution web-vulnerability
1r 3t 1c
high advisory

Multiple Vulnerabilities Discovered in Joomla! CMS

Multiple vulnerabilities, including several Cross-Site Scripting (XSS) flaws and incorrect access control issues, have been discovered in Joomla! versions 6.x prior to 6.1.2 and 5.x prior to 5.4.7, which could allow an attacker to bypass security policies, compromise data confidentiality and integrity, and perform remote indirect code injection.

Joomla! +1 web-vulnerability xss access-control cms joomla
4t 5c 24i
high advisory

CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability

A stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.

VikBooking Hotel Booking Engine & PMS plugin < 1.8.9 wordpress plugin xss web-vulnerability cms
1r 5t 1c
high advisory

CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE

Authenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.

WHMCS Bridge <= 6.9 wordpress arbitrary-file-upload remote-code-execution web-vulnerability plugin-vulnerability
3t 1c
critical threat

Critical OS Command Injection in 9Router (CVE-2026-59800)

A critical OS command injection vulnerability (CVE-2026-59800) affects 9Router versions prior to 0.4.44, allowing unauthenticated remote attackers to execute arbitrary OS commands as root via a crafted POST request to the /api/tunnel/tailscale-install endpoint, leading to full system compromise with active exploitation observed.

exploited 9Router < 0.4.44 os-command-injection rce web-vulnerability network-appliance linux
1r 2t 1c
high advisory

XWiki Platform Old Core Path Traversal via /skin/ Endpoint (CVE-2026-34151)

An attacker can exploit CVE-2026-34151, a path traversal vulnerability in XWiki Platform Old Core through the `/skin/` action endpoint when hosted on Jetty 12+. This allows unauthenticated users to craft URLs to access and download arbitrary files on the server, such as `/etc/passwd` or sensitive XWiki configuration files (e.g., `xwiki.cfg`), potentially leading to information disclosure and further system compromise.

XWiki Platform Old Core +2 path-traversal web-vulnerability xwiki jetty cve information-disclosure platform:network
1r 3t 2i
high advisory

EGroupware Authenticated RCE via Malicious eTemplate Upload (CVE-2026-40187)

An authenticated EGroupware administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) containing unescaped backtick characters that lead to shell command execution within a PHP `eval()` call during template processing (CVE-2026-40187), impacting non-Docker or non-hardened EGroupware deployments.

EGroupware +1 rce web-vulnerability php linux
1r 2t 3i
critical advisory

EGroupware Critical RCE Vulnerability (CVE-2026-27823)

A critical remote code execution vulnerability (CVE-2026-27823) in EGroupware allows an authenticated attacker, or an unauthenticated attacker if self-registration is enabled, to execute arbitrary commands on the server by combining an authorization bypass, arbitrary file write via path traversal, and arbitrary file read, leading to full system compromise.

composer/egroupware/egroupware +1 RCE web-vulnerability egroupware php critical exploit
2r 4t
high advisory

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

An attacker with only a GitHub account can plant a malicious JavaScript payload in a GitHub issue title, leading to a DOM Cross-Site Scripting (XSS) vulnerability (CVE-2026-55790) that executes in a Craft CMS administrator's control panel session when they use the CraftSupport widget and retrieve the poisoned issue, allowing for arbitrary JavaScript execution and potential unauthorized actions.

Craft CMS 5.x +1 xss web-vulnerability craft-cms application-layer
1t 1c 1i
critical advisory

Critical Unauthenticated API Vulnerabilities in 9Router Leading to Data Leak and RCE Risk

Multiple critical unauthenticated API vulnerabilities in 9Router versions up to 0.4.41 allow an attacker to perform full CRUD operations on provider connections, leak plaintext API keys, and access sensitive conversation history, posing risks of data exfiltration and denial of service.

9Router <= 0.4.41 web-vulnerability api-security data-exfiltration credential-access denial-of-service unauthenticated-access
3r 5t
high advisory

CVE-2026-59712: Leantime JSON-RPC API Authorization Bypass Leads to Credential Disclosure

An authenticated user can exploit CVE-2026-59712, an authorization bypass vulnerability in Leantime's JSON-RPC API `Users::getUser` method, to retrieve sensitive user credential information including password hashes, TOTP secrets, and session tokens for any user, leading to account enumeration, offline password cracking, 2FA bypass, and session hijacking.

Leantime authorization-bypass credential-disclosure api-exploitation web-vulnerability cve
3t 1c 3i
high advisory

Coder User-Admin Role Can Reset Owner Account Password (CVE-2026-55077)

A critical vulnerability, CVE-2026-55077, in the Coder platform allowed a user with the `user-admin` role to reset the password of an `owner` account without needing the current password via the `PUT /api/v2/users/{user}/password` endpoint, leading to privilege escalation and full deployment control.

Coder +3 privilege-escalation web-vulnerability api-vulnerability
1t
critical advisory

CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server

An unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.

ArcGIS Server +17 directory-traversal web-vulnerability esri cve
2t 1i updated
critical advisory

Formie Hidden Field SSTI Vulnerability (CVE-2026-52889)

Formie Hidden fields in versions prior to 3.1.27 are vulnerable to Server-Side Template Injection (SSTI), allowing an unauthenticated attacker to inject Twig syntax into request-derived default values, potentially leading to remote code execution, sensitive information disclosure, or application state modification.

Formie server-side-template-injection web-vulnerability craft-cms rce cve-2026-52889 network
1r 2t
critical advisory

CVE-2026-14808 — Prog Management System Sensitive Information Exposure

A critical vulnerability, CVE-2026-14808, in the Prog Management System developed by PROG MIS allows unauthenticated remote attackers to view a specific web page and obtain sensitive database account credentials, including the username and password, with high impact on confidentiality, integrity, and availability.

Prog Management System sensitive-data-exposure web-vulnerability critical-vulnerability cwe-497 database-credentials
2t 1c 2i
high advisory

CVE-2026-14778: Improper Authorization in SourceCodester Onlne Examination & Learning Management System

A high-severity improper authorization vulnerability (CVE-2026-14778) exists in SourceCodester Onlne Examination & Learning Management System version 1.0, allowing remote attackers to bypass authorization checks by manipulating the `student_id`, `schedule_id`, or `action` arguments in `/ajax_enroll.php`, potentially leading to unauthorized access or actions.

Onlne Examination & Learning Management System 1.0 web-vulnerability improper-authorization cve
1c
high advisory

CVE-2026-14769 — SQL Injection in code-projects Real State Services 1.0

A critical security vulnerability, CVE-2026-14769, allows for remote SQL Injection in code-projects Real State Services 1.0 via the 'Bankname' argument in the '/pay.php' file, with a publicly disclosed exploit enabling information disclosure and potential data manipulation.

Real State Services 1.0 sql-injection web-vulnerability cve data-exfiltration
1r 3t 1c 6i
high advisory

CVE-2026-14768: Remote SQL Injection in code-projects Real State Services 1.0

A remote SQL injection vulnerability (CVE-2026-14768) has been identified in code-projects Real State Services 1.0, allowing attackers to exploit the 'loc' argument in '/builderHome.php' for arbitrary SQL command execution, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection php cve
1r 1t 1c
high threat

CVE-2026-14764: SQL Injection in code-projects Hotel and Tourism Reservation

An unauthenticated attacker can remotely exploit CVE-2026-14764, an SQL injection vulnerability in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_event.php` component via the `fdetails` argument, to manipulate database queries and compromise sensitive data, with public exploit disclosure increasing the risk of active exploitation.

exploited Hotel and Tourism Reservation 1.0 web-vulnerability sql-injection cve data-compromise webserver
1r 3t 1c
high advisory

CVE-2026-14755: Remote SQL Injection in code-projects Hotel and Tourism Reservation

A critical remote unauthenticated SQL injection vulnerability (CVE-2026-14755) in code-projects Hotel and Tourism Reservation version 1.0, specifically within the '/admin/reservations.php' file's 'delete' argument, allows attackers to manipulate backend database queries, leading to data exposure and manipulation with a publicly disclosed exploit.

Hotel and Tourism Reservation 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration
1r 2t 1c 2i
high advisory

CVE-2026-14749: mjperpinosa stumasy Code Injection Vulnerability

A code injection vulnerability (CVE-2026-14749) was identified in mjperpinosa stumasy, affecting versions up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, which allows remote attackers to execute arbitrary code by manipulating the 'mathematical_sentence' argument in the 'eval' function of 'application/pages/imba_calculator/calculate.php', with a public exploit available and no vendor response.

stumasy web-vulnerability code-injection rce php
1r 2t 1c
high threat

CVE-2026-14746: SQL Injection in code-projects Real State Services

A high-severity SQL injection vulnerability (CVE-2026-14746) exists in code-projects Real State Services 1.0, specifically in the `/addprojectrent.php` file, where the `amen` argument can be manipulated to execute arbitrary SQL commands, enabling remote attackers to achieve unauthorized data access or modification, with public exploit disclosure increasing the risk of active exploitation.

exploited Real State Services 1.0 sql-injection web-vulnerability cve webserver public-exploit
1r 1t 1c
high advisory

CVE-2026-14745: SQL Injection in code-projects Real State Services

A critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection cve real-estate vulnerability
1r 3t 1c
high advisory

CVE-2026-14713 — SQL Injection in SourceCodester Pizzafy E-Commerce System

A critical SQL injection vulnerability (CVE-2026-14713) exists in SourceCodester Pizzafy E-Commerce System version 1.0, allowing unauthenticated remote attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the `/admin/ajax.php?action=confirm_order` endpoint, potentially leading to data exfiltration or modification, with a public exploit available.

Pizzafy E-Commerce System 1.0 sql-injection web-vulnerability cve sourcecodester e-commerce
1r 1t 1c
high advisory

CVE-2026-14695: SourceCodester Multi-Vendor Online Grocery Management System SQL Injection

A high-severity SQL injection vulnerability, CVE-2026-14695, exists in SourceCodester Multi-Vendor Online Grocery Management System 1.0, allowing remote attackers to manipulate the 'Name' argument within the `save_client` function of `classes/Users.php` to execute arbitrary SQL commands, with a public exploit available.

Multi-Vendor Online Grocery Management System 1.0 sql-injection web-vulnerability cve sourcecodester data-theft
1t 1c
high advisory

CVE-2026-14688: Remote SQL Injection in itsourcecode Online Hotel Management System

A high-severity SQL injection vulnerability, CVE-2026-14688, exists in itsourcecode Online Hotel Management System 1.0 within the `/admin/login.php` file via the `email` argument, allowing remote unauthenticated attackers to bypass authentication and potentially exfiltrate data, with a publicly available exploit.

Online Hotel Management System 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration webserver
1r 1t 1c 3i
high advisory

CVE-2026-14654: Remote SQL Injection in SourceCodester Simple and Nice Shopping Cart Script

A remote, unauthenticated SQL injection vulnerability (CVE-2026-14654) in SourceCodester Simple and Nice Shopping Cart Script 1.0 allows attackers to manipulate the `user_id` argument via `/admin/girlsproductdeletequery.php`, leading to database compromise, data exfiltration, or unauthorized access, with an exploit publicly available.

Simple and Nice Shopping Cart Script 1.0 sql-injection web-vulnerability cve sourcecodester shopping-cart
1r 1t 1c 7i
high advisory

CVE-2026-14652: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script

A critical SQL injection vulnerability (CVE-2026-14652) exists in the Admin Login component of SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing an unauthenticated attacker to remotely exploit it by manipulating the 'Username' argument in the /admin/login.php file, potentially leading to unauthorized access, information disclosure, or data manipulation, with a public exploit available.

Simple and Nice Shopping Cart Script 1.0 sql-injection web-vulnerability cve initial-access
1r 1t 1c
high advisory

CVE-2026-14637: Critical Deserialization Vulnerability in kirilkirkov Ecommerce-CodeIgniter-Bootstrap

A high-severity deserialization vulnerability, CVE-2026-14637, exists in the `getCartItems` function of `application/libraries/ShoppingCart.php` in kirilkirkov Ecommerce-CodeIgniter-Bootstrap versions up to commit `13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7`, allowing remote attackers to achieve arbitrary code execution by manipulating the `shopping_cart` argument, with public exploit disclosure raising immediate risk.

Ecommerce-CodeIgniter-Bootstrap deserialization remote-code-execution web-vulnerability php codeigniter
2t 1c
high advisory

CVE-2026-14622 — Jairiidriss restaurant-website-php-mysql Authentication Bypass

A high-severity authentication bypass vulnerability (CVE-2026-14622) exists in the jairiidriss restaurant-website-php-mysql web application's AJAX Endpoint, specifically affecting the /admin/ajax_files component, allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionalities, with public exploit code increasing immediate risk.

restaurant-website-php-mysql <= 521428b5b612449df0cf4a5d15ee40cba67f3d35 web-vulnerability authentication-bypass php webserver cve
1r 1t 1c
high advisory

Incomplete Fix for CVE-2026-25754 in @adonisjs/bodyparser Leads to CVE-2026-48795

An incomplete fix for CVE-2026-25754 in the `@adonisjs/bodyparser` package, tracked as CVE-2026-48795, allows remote unauthenticated attackers to bypass security measures via nested prototype pollution payloads in `multipart/form-data` requests, potentially leading to authorization bypasses or remote code execution.

@adonisjs/bodyparser +1 prototype-pollution web-vulnerability adonisjs rce
3t 1c
high advisory

GeoNetwork Reflected XSS through Client-Side Template Injection (CVE-2026-39379)

A reflected Cross-Site Scripting (XSS) vulnerability, CVE-2026-39379, exists in GeoNetwork due to client-side template injection within error pages, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript to execute in their browser in the context of their authenticated session.

GeoNetwork +3 xss web-vulnerability client-side-injection angularjs ghsa webserver
1r 4t
high advisory

GeoNetwork ACL Bypass in Elasticsearch Search (CVE-2026-46487)

A high-severity authorization bypass vulnerability, CVE-2026-46487, in GeoNetwork's Elasticsearch-backed search API allows unauthenticated attackers to retrieve restricted metadata records by bypassing access control and visibility filters when the request body omits the 'query' field, leading to sensitive information disclosure.

GeoNetwork +2 authorization-bypass information-disclosure web-vulnerability elasticsearch ghsa
3t
high advisory

MediaWiki Maps Stored XSS via display_map `overlays` Parameter (CVE-2026-52854)

A high-severity stored cross-site scripting (XSS) vulnerability, CVE-2026-52854, exists in the MediaWiki Maps extension (versions prior to 12.1.3), allowing any authenticated user with edit permissions to inject malicious JavaScript into the `overlays` parameter of the `display_map` parser function, leading to arbitrary client-side code execution in a victim's browser.

mediawiki/maps xss mediawiki web-vulnerability web-application
1r 2t
high advisory

Unauthenticated SQL Execution Vulnerability in Recce OSS Server (CVE-2026-49360)

Recce OSS server deployments are vulnerable to unauthenticated SQL execution via the query run API when configured with a DuckDB-backed project, allowing attackers to use DuckDB filesystem primitives to read and write arbitrary files accessible to the server process, potentially leading to data disclosure, tampering, or stored XSS.

recce web-vulnerability sql-injection file-read-write rce data-exfiltration
1r 3t
critical advisory

OpenAM Pre-Authentication Reflected XSS via OAuth2/OIDC state parameter (CVE-2026-44203)

A critical pre-authentication reflected Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-44203, in OpenIdentityPlatform OpenAM's `openam-oauth2` component allows an unauthenticated attacker to inject malicious scripts into a victim's browser context by manipulating the `state` parameter in OAuth2/OIDC `form_post` responses, leading to session hijacking or credential theft.

openam-oauth2 xss web-vulnerability openam oidc oauth2
1r 2t
critical advisory

Budibase Arbitrary File Read Vulnerability via PWA-zip Symlink Upload (CVE-2026-54352)

A critical vulnerability, CVE-2026-54352, in Budibase server allows an authenticated workspace builder to perform arbitrary file reads on the host system by uploading a crafted PWA zip file containing a symbolic link, leading to credential compromise and privilege escalation, potentially enabling a full global administrator takeover.

Budibase server < 3.39.9 +1 arbitrary-file-read web-vulnerability privilege-escalation credential-access symlink budibase cloud saas
4t 1c 3i
critical advisory

i18next-http-middleware Prototype Pollution via missingKeyHandler (CVE-2026-48714)

A critical prototype pollution vulnerability (CVE-2026-48714) exists in `i18next-http-middleware` versions up to 3.9.6, where the `missingKeyHandler` fails to adequately sanitize dotted key segments, allowing attackers to manipulate `Object.prototype` when exposed to untrusted input and used with vulnerable `i18next-fs-backend` versions up to 2.6.5, potentially leading to configuration poisoning, security bypasses, crashes, or remote code execution.

i18next-http-middleware +1 web-vulnerability prototype-pollution npm nodejs
1r 2t 1c
critical advisory

CVE-2024-58351: Flowise Remote Code Execution via Configuration Injection

Flowise versions before 2.1.4 are critically vulnerable to configuration injection (CVE-2024-58351) via the `overrideConfig` option in both its frontend web integration and backend Prediction API, which, due to a bypassable `vm2` sandbox, allows attackers to achieve remote code execution, sandbox escape, denial of service, server-side request forgery, prompt injection, and server variable/data exfiltration.

Flowise web-vulnerability rce sandbox-escape node.js configuration-injection
2r 7t
high advisory

Faraday: Uncontrolled Recursion in NestedParamsEncoder Allows Stack Exhaustion DoS

An unauthenticated attacker can trigger a denial-of-service condition in applications using the Faraday Ruby library by sending deeply nested query parameters (CVE-2026-54297), leading to `SystemStackError` and application crashes due to uncontrolled recursion.

Faraday denial-of-service web-vulnerability ruby ghsa cve
2r 1t
high advisory

JupyterLab Git Extension Stored XSS to RCE (CVE-2026-54527)

A stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-54527, in the `jupyterlab-git` JupyterLab extension (versions >= 0.30.0b3, < 0.54.0a1), specifically in `PlainTextDiff.ts`, allows an adversary with Git commit access to execute arbitrary JavaScript in a victim's browser and achieve Remote Code Execution (RCE) on the JupyterLab server by crafting a malicious filename in a Git commit that, when viewed as a rename diff, triggers the XSS payload to steal `_xsrf` cookies, open a terminal, and execute arbitrary shell commands to exfiltrate data.

jupyterlab-git +2 xss rce jupyterlab git web-vulnerability software-supply-chain ghsa
2r 6t
high advisory

JupyterLab-Git excluded_paths Case-Sensitivity Bypass (CVE-2026-54528)

An authenticated user can bypass the admin-configured `excluded_paths` security control in `jupyterlab-git` versions up to 0.53.0 by exploiting a case-sensitivity flaw on case-insensitive filesystems (e.g., macOS APFS, Windows NTFS), allowing unauthorized read access to git history and file content in explicitly excluded directories.

jupyterlab-git <= 0.53.0 web-vulnerability path-traversal data-exfiltration jupyterlab python
2r 4t
high advisory

Joomla com_booking Information Disclosure (CVE-2023-54357)

An unauthenticated information disclosure vulnerability (CVE-2023-54357) in the Joomla com_booking component version 2.4.9 allows attackers to enumerate user accounts, including names, usernames, and email addresses, by exploiting the getUserData function via specific GET requests.

Joomla! com_booking component 2.4.9 joomla web-vulnerability information-disclosure cve
1r 2t
high advisory

AlchemyCMS: Unauthenticated Nested Page API Leaks Restricted & Unpublished Content

An unauthenticated API endpoint, `GET /api/pages/nested`, in Alchemy CMS versions up to 8.2.5 (including all 8.x versions prior to a fix and all 7.x versions up to 7.4.14), fails to enforce authorization and scoping checks, allowing any anonymous user to retrieve the complete page tree, encompassing restricted and unpublished pages, and, with `?elements=true`, the full content of these sensitive pages, completely bypassing intended access controls and leading to unauthorized information disclosure.

Alchemy CMS +3 web-vulnerability information-disclosure cms rails ruby
2r
high advisory

Joomla! Calendar Planner 1.0.1 SQL Injection (CVE-2017-20267)

An unauthenticated attacker can exploit CVE-2017-20267, an SQL injection vulnerability in Joomla! Component Calendar Planner 1.0.1, by sending malicious GET requests to the 'events' view via the 'category_id' parameter, allowing for sensitive database information extraction.

Calendar Planner 1.0.1 sqli web-vulnerability joomla cve
1r 1t
high advisory

Joomla! Component Flip Wall SQL Injection (CVE-2017-20265)

An SQL injection vulnerability, CVE-2017-20265, in Joomla! Component Flip Wall 8.0 allows unauthenticated attackers to execute arbitrary SQL queries via malicious GET requests to the `wallid` parameter, enabling the extraction of sensitive database information.

Flip Wall 8.0 sql-injection web-vulnerability joomla cve data-exfiltration
2r 3t
high advisory

Joomla! FocalPoint Pro/Free SQL Injection (CVE-2017-20263)

An unauthenticated SQL injection vulnerability (CVE-2017-20263) in Joomla! Component FocalPoint Pro/Free version 1.2.3 allows attackers to execute arbitrary SQL queries via a crafted 'id' parameter in GET requests, leading to sensitive database information disclosure.

FocalPoint Pro/Free sqli web-vulnerability joomla data-exfiltration
1r 3t 1c
high threat

CVE-2017-20262 — Joomla! Component Ajax Quiz SQL Injection

An unauthenticated SQL injection vulnerability, CVE-2017-20262, in Joomla! Component Ajax Quiz version 1.8 allows attackers to execute arbitrary SQL queries by injecting malicious code through the `cid` parameter in GET requests to `index.php` with `option=com_ajaxquiz` and `view=ajaxquiz`, leading to extraction of sensitive database information.

exploited Ajax Quiz 1.8 sql-injection web-vulnerability joomla cve
1r 3t
high advisory

Joomla OSDownloads SQL Injection (CVE-2017-20259)

An unauthenticated SQL injection vulnerability (CVE-2017-20259) in Joomla OSDownloads version 1.7.4 allows attackers to execute arbitrary SQL queries via a crafted GET request to index.php, extracting sensitive database information like credentials and configuration data.

OSDownloads 1.7.4 sql-injection web-vulnerability joomla cve
2r 3t 1c
high advisory

Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection (CVE-2017-20258)

Unauthenticated attackers can exploit an SQL injection vulnerability (CVE-2017-20258) in Joomla! Component RPC Responsive Portfolio 1.6.1 by injecting malicious code through the 'id' parameter in GET requests, allowing the execution of arbitrary SQL queries and extraction of sensitive database information.

RPC Responsive Portfolio 1.6.1 sql-injection web-vulnerability joomla cve data-exfiltration
1r 2t 1c
high advisory

Joomla! Component JB Visa 1.0 SQL Injection (CVE-2017-20255)

An unauthenticated SQL injection vulnerability (CVE-2017-20255) in Joomla! Component JB Visa 1.0 allows attackers to execute arbitrary SQL queries by injecting malicious code via the 'visatype' parameter in GET requests to 'index.php?option=com_bookpro&view=popup', leading to the extraction of sensitive database information including credentials.

JB Visa 1.0 sql-injection joomla web-vulnerability cve
2r 2t
high advisory

Joomla! User Bench Component SQL Injection (CVE-2017-20254)

An unauthenticated attacker can exploit CVE-2017-20254, an SQL injection vulnerability in the Joomla! Component User Bench 1.0, by sending crafted HTTP GET requests to extract sensitive database information including credentials and configuration data.

User Bench 1.0 sqli joomla web-vulnerability cve
1r 3t
high advisory

CVE-2017-20252: Joomla NextGen Editor SQL Injection

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability (CVE-2017-20252) that allows unauthenticated attackers to execute arbitrary SQL commands through the `plname` parameter in crafted GET requests to `index.php?option=com_nge&view=config`, leading to the extraction of sensitive database information.

NextGen Editor 2.1.0 sqli web-vulnerability joomla cve data-exfiltration
2r 4t
high advisory

Tilt: Cross-site WebSocket Hijacking Vulnerability (CVE-2026-55883)

An attacker can exploit CVE-2026-55883, a Cross-site WebSocket Hijacking vulnerability in Tilt versions 0.24.0 through 0.37.3, by acquiring an unauthenticated CSRF token or bypassing Origin header checks, to establish a WebSocket connection to a network-exposed Tilt HUD and exfiltrate sensitive developer session state, Tiltfile contents, and resource statuses.

Tilt websocket hijacking CVE developer-tool web-vulnerability
3r 3t
critical advisory

gemini-mcp-tool Vulnerable to OS Command Injection and File Exfiltration (CVE-2026-0755)

A critical vulnerability, CVE-2026-0755, in npm's gemini-mcp-tool package allows for OS command injection on Windows systems due to improper handling of unquoted cmd.exe metacharacters, and arbitrary local file exfiltration via the @file parser when processing untrusted prompt input, leading to potential remote code execution and sensitive data compromise.

gemini-mcp-tool command-injection file-exfiltration npm cli-tool web-vulnerability
2r 3t
critical advisory

Crawl4AI Unauthenticated RCE via Chromium Launch-Argument Injection

An attacker can achieve unauthenticated remote code execution (RCE) in Crawl4AI Docker deployments by injecting malicious Chromium launch arguments, such as `--utility-cmd-prefix` and `--no-zygote`, into the `browser_config.extra_args` field of the API request, allowing for arbitrary command execution as the container's runtime user.

crawl4ai RCE web-vulnerability Chromium container Docker Linux
3r 2t
high advisory

Kirby: Self cross-site scripting (self-XSS) in the writer field (CVE-2026-49276)

Kirby CMS versions prior to 4.9.4 and between 5.0.0-alpha.1 and 5.4.3 are vulnerable to a self-cross-site scripting (self-XSS) flaw, CVE-2026-49276, in the writer field, allowing an attacker to inject malicious JavaScript as the target of a link or email link which, if clicked by an authenticated user before saving, will execute in their browser context, potentially making API requests with their permissions, while Panel plugins using the `<k-writer>` component may be vulnerable to stored XSS if they don't sanitize HTML.

composer/getkirby/cms <= 4.9.3 +1 xss self-xss web-vulnerability kirby cms
2r 3t
critical advisory

Jupyter Server Stored XSS via Missing CSP Sandbox (CVE-2026-44727)

A critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-44727, exists in `jupyter_server` versions up to 2.19.0 due to a missing `sandbox` directive in Content-Security-Policy (CSP) headers, allowing authenticated attackers to craft malicious notebooks that exfiltrate victim tokens and achieve kernel Remote Code Execution (RCE) when viewed.

jupyter_server xss web-vulnerability jupyter server-side rce
2r 4t
critical advisory

Critical Kirby CMS Vulnerability Allows Remote Admin Account Creation via Reverse Proxy Headers (CVE-2026-54003)

A critical external initialization vulnerability (CVE-2026-54003) in Kirby CMS allows unauthenticated attackers to create an initial admin account on sites running behind a reverse proxy, specifically when the proxy utilizes `Forwarded: for=...`, `X-Client-IP`, or `X-Real-IP` headers, bypassing Kirby's `isLocal` check and enabling remote Panel installation with full administrative access.

Kirby CMS +1 web-vulnerability cms initial-access privilege-escalation kirby
2r 2t
high advisory

PraisonAI Authentication Bypass via PRAISONAI_CALL_AUTH=disabled

A high-severity authentication bypass vulnerability in PraisonAI versions prior to 4.6.61 allows unauthenticated attackers to invoke any registered agent by setting the `PRAISONAI_CALL_AUTH=disabled` environment variable, potentially leading to arbitrary code execution or system compromise.

praisonai web-vulnerability authentication-bypass api-exploitation misconfiguration container
2r 7t
high advisory

CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability

An injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.

PoC NGINX Plus +10 config-injection nginx kubernetes cloud-native web-vulnerability cve
2r 1t 5c 2i updated
high advisory

CVE-2026-49952: Discuz! X5.0 Authentication Bypass Leading to Database Access

CVE-2026-49952 is an authentication bypass vulnerability in Discuz! X5.0 versions 20260320 through 20260501, allowing unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key, leading to potential data exfiltration and user impersonation.

PoC Discuz! X5.0 +1 authentication-bypass web-vulnerability cve discuz data-exfiltration
2r 6t 1c 1i updated
high advisory

Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)

A high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.

PoC Vite +4 information-disclosure bypass web-vulnerability windows development-server
2r 1t 1c 3i updated
high threat

Multiple Vulnerabilities in Typo3 Leading to RCE, Privilege Escalation, and Data Compromise

Multiple vulnerabilities discovered in Typo3 allow an attacker to achieve remote arbitrary code execution, privilege escalation, data confidentiality compromise, data integrity compromise, security policy bypass, remote indirect code injection (XSS), and SQL injection (SQLi).

exploited Typo3 < 10.4.57 +4 web-vulnerability rce privilege-escalation data-exfiltration typo3 cert-fr
3r 6t 5c 20i
high advisory

Path Traversal Vulnerability in WilliamCloudQi matlab-mcp-server

A path traversal vulnerability exists in WilliamCloudQi matlab-mcp-server up to version ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca, allowing a remote attacker to manipulate the scriptPath argument in the generate_matlab_code/execute_matlab_code function to access arbitrary files.

matlab-mcp-server path-traversal web-vulnerability
2r 1t 1c