Skip to content
Threat Feed

Tag

Webapps

37 briefs RSS
critical advisory

FreePBX Endpoint Manager Unauthenticated Remote Code Execution

An unauthenticated SQL injection vulnerability (CVE-2025-57819) in the FreePBX Endpoint Manager module allows attackers to achieve remote code execution by injecting malicious cron jobs.

FreePBX webapps cve rce sql-injection exploit
1r 3t 1c
high advisory

Remote Code Execution in Marimo 0.20.4

A Remote Code Execution vulnerability in Marimo version 0.20.4 allows attackers to achieve arbitrary command execution via a publicly available exploit.

Marimo webapps rce vulnerability
2t
high advisory

Remote Code Execution in Ghost CMS 6.19.0

Ghost CMS version 6.19.0 is susceptible to unauthenticated remote code execution via a publicly disclosed exploit.

Ghost rce webapps ghost-cms
1t
medium advisory

Stored XSS Vulnerability in PodcastGenerator 3.2.9

PodcastGenerator version 3.2.9 contains a stored Cross-Site Scripting (XSS) vulnerability allowing unauthenticated attackers to inject malicious scripts into the application.

PodcastGenerator webapps xss vulnerability
1t
high advisory

Blind SQL Injection in EasyAppointments

EasyAppointments versions 1.5.1 and earlier contain a blind SQL injection vulnerability in search endpoints that allows authenticated attackers to extract sensitive database content via malicious 'order_by' parameters.

EasyAppointments webapps sqli cve-2025-50455
1r 1t 1c
high advisory

Stored XSS Vulnerability in Bludit CMS

Bludit CMS version 3.22.0 contains a stored XSS vulnerability in its SVG upload process, allowing attackers to execute arbitrary JavaScript via malicious XML processing instructions.

Bludit CMS +1 webapps xss injection
2r 4t updated
high threat

Blind SQL Injection Vulnerability in Payload CMS

Payload CMS versions prior to 3.73.0 are vulnerable to Blind SQL Injection via maliciously crafted JSON filter inputs processed by the Drizzle database adapter.

exploited Payload CMS webapps sqli vulnerability
1r 1t 1c
high threat

SQL Injection in CubeCart 6.7.4

An authenticated SQL injection vulnerability in CubeCart 6.7.4 allows administrative users to execute arbitrary SQL commands due to improper sanitization of the download_expire parameter.

exploited CubeCart +1 webapps sqli cube-cart xss injection cve-2026-54644
2r 3t
high threat

C-MOR Video Surveillance Directory Traversal Vulnerability

C-MOR Video Surveillance versions up to 6.0104 are vulnerable to an unauthenticated directory traversal attack in the show-movies.pml component, allowing remote attackers to read arbitrary files.

exploited C-MOR Video Surveillance webapps directory-traversal cve-2026-51134 surveillance web-application-vulnerability xss
2r 2t
high advisory

Unauthenticated OS Command Injection in Linksys E1200

Linksys E1200 routers running firmware v2.0.04 and earlier are vulnerable to unauthenticated remote command execution via the tmUnblock.cgi endpoint.

E1200 webapps cve-2025-60689 command-injection
1r 2t 1c
high advisory

Nodemailer MailComposer Security Bypass Vulnerability

Nodemailer version 9.0.0 and earlier fails to enforce security flags when using the raw message option, allowing attackers to bypass file and URL access restrictions for arbitrary file read or SSRF.

Nodemailer webapps ssrf file-read security-bypass
3t
high advisory

Duplicati JWT Signing Key Exposure via Guard Bypass

An unpatched vulnerability in Duplicati 2.2.0.3 allows authenticated attackers to bypass security guards and extract JWT signing keys to forge administrative tokens.

Duplicati webapps privilege-escalation jwt
1r 1t
high threat

CSRF Vulnerability in webpack-dev-server

A CSRF vulnerability (CVE-2026-14620) in webpack-dev-server 5.2.5 allows unauthenticated cross-origin requests to trigger the launchEditor() function, potentially enabling remote command execution via arbitrary local file paths.

exploited webpack-dev-server webapps csrf cve-2026-14620
1r 1t 2c
high advisory

Unauthenticated Arbitrary File Upload in WooCommerce 1.5.0

WooCommerce 1.5.0 contains an unauthenticated arbitrary file upload vulnerability allowing remote attackers to upload malicious files, potentially resulting in remote code execution.

WooCommerce webapps file-upload remote-code-execution
1t
high advisory

Directory Traversal and LFI in Ray 2.56.0

Ray 2.56.0 contains a directory traversal and local file inclusion vulnerability in the /api/v0/logs endpoint allowing unauthenticated attackers to read arbitrary files.

Ray webapps directory-traversal lfi
1r 2t
high advisory

Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit

A public exploit (EDB-52629) has been released for Krayin CRM v2.2.x, demonstrating an authenticated remote code execution vulnerability that allows an authenticated attacker to execute arbitrary code on the underlying system, significantly increasing the risk for unpatched deployments of the web application.

Krayin CRM v2.2.x webapps rce exploit-db krayin-crm crm
1t
high advisory

Joomla Page Builder CK Arbitrary File Upload (EDB-52626)

A public exploit has been released for an arbitrary file upload vulnerability in Joomla Page Builder CK version 3.5.10, which allows an unauthenticated attacker to upload malicious files to the server, potentially leading to remote code execution and full system compromise.

Joomla Page Builder CK 3.5.10 webapps arbitrary-file-upload joomla remote-code-execution
3t
high advisory

Public Exploit for MCPJam Inspector Remote Code Execution (EDB-52625)

A public exploit (EDB-52625) has been published for the web application MCPJam Inspector, demonstrating a Remote Code Execution vulnerability, significantly elevating the risk for unpatched systems and allowing attackers to execute arbitrary code.

MCPJam Inspector webapps rce exploit-db vulnerability
2t
critical advisory

Flowise 3.1.3 Arbitrary Code Execution Exploit Published

A critical arbitrary code execution vulnerability in Flowise version 3.1.3 and earlier has been publicly disclosed on Exploit-DB, enabling unauthenticated attackers to execute arbitrary commands on unpatched web application instances, leading to full system compromise.

Flowise webapps arbitrary-code-execution exploit-db
2t
high advisory

WordPress Bricks Builder Theme - Unauthenticated RCE (CVE-2024-25600)

An unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2024-25600) exists in the WordPress Bricks Builder Theme up to version 1.9.6, allowing attackers to exploit the 'render_element' endpoint by first extracting a nonce from the page source, then injecting PHP code to execute arbitrary operating system commands on the underlying web server, with a public exploit now available.

PoC Bricks Builder Theme < 1.9.7 +1 wordpress rce webapps exploit-db cve
1r 2t 1c 4i updated
high advisory

JoomShaper SP LMS PHP Object Injection Leads to RCE (CVE-2026-48909)

A critical PHP object injection vulnerability (CVE-2026-48909) in JoomShaper SP LMS versions <= 4.1.3 allows unauthenticated attackers to achieve remote code execution (RCE) via a crafted 'lmsOrders' cookie, leading to webshell deployment on vulnerable Joomla installations (< 5.2.2).

JoomShaper SP LMS <= 4.1.3 +1 webapps php object-injection rce webshell
1r 3t 1c
high advisory

KeepInMind 0.8.4.2 - Stored XSS Public Exploit

A public exploit has been published for a Stored XSS vulnerability in KeepInMind version 0.8.4.2, significantly increasing the risk for unpatched installations.

KeepInMind 0.8.4.2 webapps xss vulnerability exploit-db
1t
high advisory

WordPress WPZOOM Portfolio Plugin XSS Vulnerability (CVE-2026-49069)

A critical reflected cross-site scripting (XSS) vulnerability, CVE-2026-49069, affects the WPZOOM Portfolio plugin (version 1.4.21 and earlier) for WordPress, enabling unauthenticated attackers to inject malicious JavaScript into web pages via the `wpzoom_load_more_items` AJAX action, leading to client-side script execution in victims' browsers.

WordPress Plugin WPZOOM Portfolio <= 1.4.21 +1 xss wordpress webapps cve
1r 2t 1c 2i
critical advisory

Langflow 1.3.0 Remote Code Execution Vulnerability

Langflow 1.3.0 contains a remote code execution vulnerability (CVE-2026-0770) due to untrusted input in the exec_globals parameter at the validate endpoint, allowing remote attackers to execute arbitrary code as root without authentication, as demonstrated by a public exploit.

langflow 1.3.0 +3 remote-code-execution webapps langflow
1r 1t 5i updated
high advisory

MixPHP Framework 2.2.17 Unsafe Deserialization Remote Code Execution

MixPHP Framework 2.2.17 is vulnerable to remote code execution due to unsafe deserialization, with a public exploit available, increasing the risk for unpatched systems.

MixPHP Framework 2.2.17 webapps rce deserialization
2r 1t
high advisory

EspoCRM 9.3.3 SSRF Vulnerability (CVE-2026-33534)

A public exploit is available for EspoCRM 9.3.3, exploiting a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-33534) allowing authenticated attackers to potentially access internal resources.

EspoCRM 9.3.3 ssrf webapps cve-2026-33534
2r 1t 1c
high advisory

Casdoor 3.54.1 Arbitrary File Write via Path Traversal

Casdoor version 3.54.1 is vulnerable to a path traversal attack, allowing arbitrary file writes on the system, with a public exploit available.

Casdoor 3.54.1 path-traversal file-write webapps
2r 1t
high advisory

OpenCATS 0.9.7.4 SQL Injection Vulnerability

A SQL Injection vulnerability exists in OpenCATS 0.9.7.4, with a published exploit that allows for database version and user extraction on unpatched systems.

OpenCATS 0.9.7.4 sqli webapps opencats
2r 1t
critical advisory

WordPress Temporary Login Plugin Authentication Bypass Vulnerability

A public exploit is available for WordPress Temporary Login Plugin version 1.0.0, which demonstrates an authentication bypass vulnerability that can lead to account takeover, increasing the risk for unpatched systems.

Temporary Login Plugin 1.0.0 wordpress authentication-bypass account-takeover webapps
2r 1t
medium threat

SolarEdge CSRF and Out-of-Band Injection Vulnerability

A CSRF-OOB-Injection vulnerability exists in SolarEdge Monitoring Platform's `/solaredge-web/p/initClient` endpoint due to improper validation of session parameters, allowing attackers to manipulate headers to initiate requests to attacker-controlled domains, potentially leading to session compromise and unauthorized system control.

SolarEdge Monitoring Platform - Framework /solaredge-web/ solaredge csrf oob-injection webapps
2r 1t 1i
medium advisory

BookStack 25.12.1 Denial-of-Service Vulnerability

A denial-of-service vulnerability exists in BookStack version 25.12.1, and a public exploit (EDB-52571) is available, increasing the risk to unpatched systems.

BookStack denial-of-service webapps exploit
2r 1t
high threat

Cockpit 359 Remote Code Execution Vulnerability

Cockpit version 359 is vulnerable to remote code execution, and a public exploit is available on Exploit-DB, increasing the risk for unpatched systems.

Cockpit 359 rce webapps exploit
2r 1t
high advisory

ePati Antikor NGFW 2.0.1301 Authentication Bypass Vulnerability

A public exploit has been published for ePati Antikor NGFW 2.0.1301, exploiting an authentication bypass vulnerability, increasing the risk to unpatched systems.

Antikor NGFW 2.0.1301 authentication bypass webapps
1r 1t
critical advisory

Apache HertzBeat 1.8.0 Remote Code Execution Vulnerability

Apache HertzBeat 1.8.0 is vulnerable to remote code execution due to a newly published exploit, posing a significant risk to unpatched systems.

HertzBeat 1.8.0 rce apache-hertzbeat exploit webapps
2r 1t
high advisory

Bludit CMS 3.18.4 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Bludit CMS 3.18.4, for which a public exploit has been published, increasing the risk to unpatched systems.

Bludit CMS 3.18.4 webapps rce bludit
2r 1t
critical threat

LuaJIT 2.1.1774638290 Arbitrary Code Execution Vulnerability

A public exploit has been published for LuaJIT version 2.1.1774638290, enabling arbitrary code execution on vulnerable web applications.

LuaJIT 2.1.1774638290 webapps code-execution luajit
2r 1t
high advisory

Ghost CMS 6.19.0 SQL Injection Vulnerability

A SQL injection vulnerability exists in Ghost CMS 6.19.0, and a public exploit (EDB-52555) is available, increasing the risk to unpatched systems.

Ghost CMS 6.19.0 sqli webapps ghostcms
2r 1t