Atomicorp WAF Research Notes

Research Update - 2026-08-23

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-Series312658 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-34163Dongsheng Logistics Software Unauthenticated Arbitrary File Upload351000
CVE-2026-19188Haiwell IoT Cloud HMI Gateway OS Command Injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-33712TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer script340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-57827Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12351000
CVE-2026-72899Metabase SQL injection via public card or dashboard340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-8984Unauthenticated RCE340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8985Unauthenticated Command Injection340014 , 340023 , 344360 , 344361 , 344362 , 344363 , 344364 , 344366 , 344370
CVE-2026-31818Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-42454Termix: OS Command Injection in Docker Container Management Endpoints340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-43986Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-51027FileThingie v.2.5.7 Information Disclosure Vulnerability340007 , 344360 , 390709
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and cr337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-66898Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE390719
CVE-2026-69083SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69085SiYuan before v3.7.3 SQL Injection via searchDocs340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72740Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscan340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72865Dokploy: OS Command Injection via compose composePath340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72872Dokploy: OS Command Injection via Bitbucket owner/repository in git clone340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73263Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path340014 , 340023 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73294Semaphore U: OS Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-8481Remote Code Execution via Code Validation Endpoint340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2015-10138Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload351000
CVE-2022-31340simple inventory system SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-57631tduck Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-65336Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-65340kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67403Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67404Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69930CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69931CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69933CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69934CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69935SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69936CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69937CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69938CodeAstro Membership Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69941SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69942kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69943SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69946SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69947SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69948SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10880Unauthenticated SQL Injection in Osnexus Quantastor340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-15732WGDashboard Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-30118scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-31040stata-mcp Code Injection Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34243wenxian: Command Injection in GitHub Actions Workflow via issue_comment.body340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in Installer340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-35471Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs340007 , 344360 , 347009 , 390709
CVE-2026-35847the CheckUils.php file Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-36669ck_upload_handler.php in Feng Office 3.11.13.11 Arbitrary File Upload Vulnerability351000
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-38428kestra SQL Injection Vulnerability340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-38431erpnext Code Injection Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm override340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-46670YesWiki: Unauthenticated SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-48528Metacat has an unauthenticated SQL injection vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48687fastnetmon Command Injection Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-49827WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)351000
CVE-2026-51775Fastadmin v.1.6.1.20250430 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-52348cool-admin-java 8.0.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-52472Wgcloud 3.6.4 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-67678RainyGao-Hithub DocSys v.2.02.80 Arbitrary Code Execution Vulnerability351000
CVE-2026-67688ICS-Park Smart Park Management System v2.0 Arbitrary Code Execution Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-67689FineAdmin V1.0 Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-67919Halo 2.25.4 Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-67926JeecgBoot v.3.9.2 Arbitrary Code Execution Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-69240Sequelize: SQL Injection (Oracle DB)340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72592dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-12564Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credenti337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-12605glassfish Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 393655
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-53513Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8986Command Injection via Malicious OCPP Server340014 , 340023 , 340193 , 344360 , 344361 , 344362 , 344363 , 344364 , 344366 , 344370
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-11419Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write340007 , 344360 , 390709
CVE-2026-11423Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation344360 , 390709
CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code execution340014 , 340016 , 340017 , 340023 , 340029 , 340157 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-39342ChurchCRM has a SQL injection searchwhat parameter via QueryView.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-637329router before 0.4.60 Remote Code Execution via default password340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-66395SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol333140 , 340095 , 341266
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgent340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversal340007 , 344360 , 347009 , 390709
CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Upload340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotations340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadata340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-73043SiYuan before v3.7.4 Remote Code Execution via Template Calculation333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73044SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73050SiYuan before v3.7.4 Stored XSS via select option color333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73052SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73053SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteer340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2016-20052Snews CMS 1.7 Unrestricted File Upload via snews_files351000
CVE-2016-20096Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20251WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904
CVE-2018-25412Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php351000
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.php340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2019-25727WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download340007 , 344360 , 347009 , 390709
CVE-2021-47940WordPress Download From Files 1.48 Arbitrary File Upload351000
CVE-2022-4995Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp351000
CVE-2024-58348WordPress Background Image Cropper 1.2 Remote Code Execution340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2024-58355Cal.com through 4.7.15 Cross-Site Scripting via booking questions333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-31114Fooocus webui vulnerable to Remote Code Execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-23734XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash340007 , 344360 , 347009 , 390709
CVE-2026-34361HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-40329SQL Injection vulnerability via sortBy in beanFeed340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-40330Masa CMS SQL injection via sortDirection parameter in beanFeed340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-42849authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45118MyBB: Contact page reflected XSS333140 , 333141 , 340003 , 340087 , 340095 , 340099 , 340147 , 340148 , 340158 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45668Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)340007 , 344360 , 347009 , 390709
CVE-2026-47669DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE340007 , 344360 , 390709
CVE-2026-47754unauthenticated path traversal in Metacat 2.x340007 , 344360 , 347009 , 390709
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-57858Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-60121Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-61511vBulletin 6.x - Remote Code Execution340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 360151 , 393655
CVE-2026-63106ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.py340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsync340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirect337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655
CVE-2026-65700h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-65701SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route340007 , 344360 , 390709
CVE-2026-65761Joomla Easy Store - SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-66394SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass300013 , 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-66418OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Request340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-67426Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-69110OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music340007 , 344360 , 347009 , 390709
CVE-2026-70553MaxSite CMS Unauthenticated RCE via Install Endpoint340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-70558Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token351000
CVE-2026-71944D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71945D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71949D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71950D-Link DWR-M961 Command Injection via /boafrm/formSmsManage340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71951D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71952D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71953D-Link DWR-M961 Command Injection via /boafrm/formNtp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71954D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWsc340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71956D-Link DWR-M961 Command Injection via app.cgi340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilter340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilter340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-74798SiYuan kernel Path Traversal via database_clean MCP tool340007 , 344360 , 390709
CVE-2026-74902SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-9586Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcesses340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.php340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-65057Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65317Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-65318Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0340007 , 344360 , 347009 , 390709
CVE-2025-50455the CodeIgniter Query Builder Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-15360Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-16532Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-17552Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022
CVE-2026-34745Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public340007 , 344360 , 390709
CVE-2026-44313LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-47731NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by u340007 , 344360 , 390709
CVE-2026-52610reportico-web <= 8.1.0 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-73069Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary PostgreSQL Execution340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34448SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop cl333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34612Kestra: Remote Code Execution via SQL Injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-35198HeyForm vulnerable to stored XSS via form field titles333140 , 333141 , 340095 , 342259 , 350147 , 350148
CVE-2026-42556Postiz stored XSS in public preview page333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-69251Flowise RCE via TypeORM DataSource340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-72851Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agent340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agent340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-43984Tautulli has stored XSS in logFile via guest-controlled log_js_errors input333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9408Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9475Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2016-20062Simply Poll 1.4.1 Plugin for WordPress SQL Injection340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2017-20243WordPress Car Park Booking Plugin SQL Injection via space_id340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20247WordPress Plugin PICA Photo Gallery 1.0 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20249WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2018-25340Smartshop 1 SQL Injection via category.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25341Smartshop 1 SQL Injection via product.php id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25342Smartshop 1 SQL Injection via search.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25348Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25351Joomla! Component EkRishta 2.10 SQL Injection via username340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25362Twitter-Clone 1 SQL Injection via follow.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25364Twitter-Clone 1 SQL Injection via search.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25371mooSocial Store Plugin 2.6 SQL Injection via product parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25372MedDream PACS Server Premium 6.7.1.1 SQL Injection via email340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2018-25385E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25386HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25394Kados R10 GreenBee SQL Injection via update_release.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25395Kados R10 GreenBee SQL Injection via update_feature.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25411MGB OpenSource Guestbook 0.7.0.2 SQL Injection via email.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25413AiOPMSD Final 1.0.0 SQL Injection via search.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25414AiOPMSD Final 1.0.0 SQL Injection via actor.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25416AiOPMSD Final 1.0.0 SQL Injection via country.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25417AiOPMSD Final 1.0.0 SQL Injection via quality.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25418AiOPMSD Final 1.0.0 SQL Injection via year.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25419AiOPMSD Final 1.0.0 SQL Injection via genre.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25420AiOPMSD Final 1.0.0 SQL Injection via watch.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25422MOGG web simulator Script All Version SQL Injection via play.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25424Gate Pass Management System 2.1 SQL Injection via login-exec.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25425Yot CMS 3.3.1 SQL Injection via aid and cid Parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25428Paroiciel 11.20 SQL Injection via tRecIdListe Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25433Joomla JE Photo Gallery 1.1 SQL Injection via categoryid340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25434WP AutoSuggest 0.24 SQL Injection via autosuggest.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25662ResourceSpace 8.6 SQL Injection via watched_searches.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25668News Website Script 2.0.5 SQL Injection via index.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25669qdPM 9.1 SQL Injection via search_by_extrafields Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25675eDirectory All Versions SQL Injection Authentication Bypass340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25678C4G BLIS 3.4 SQL Injection via users_select.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25680Advance Gift Shop Pro Script 2.0.3 SQL Injection via search340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25684OpenDocMan 1.3.4 SQL Injection via where Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25694Kados R10 GreenBee SQL Injection via user2reset340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25728Care2x 2.7 Hospital Information System SQL Injection via ck_config340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25730Listing Hub CMS 1.0 SQL Injection via pages.php id340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25732PHP EI-Tube Script 3 SQL Injection via search parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-47928Opencart TMD Vendor System 3.x Blind SQL Injection via product route340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-47930Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2024-39024In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-45868LogicalDOC Enterprise up to and for v9.1.1 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-12968Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-17623Langflow is affected OS Command Injection in Model Context Protocol features344360 , 347009 , 390709
CVE-2026-17625Langflow is affected by OS Command Injection in Model Context Protocol features344360 , 347009 , 390709
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-31069BillaBear (all versions prior to Jan 2026) SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34524SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within user340007 , 344360 , 390709
CVE-2026-35031Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates action340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-35395WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-35470OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-36723bookcars v8.3 Arbitrary Code Execution Vulnerability340007 , 344360 , 390109 , 390709
CVE-2026-41075RT: SQL injection via entry_aggregator parameter in JSON search340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-41473CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-42455LinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same origin)333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-42605AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Upload340007 , 344360 , 347009 , 390709
CVE-2026-43624F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()340007 , 344360 , 390709
CVE-2026-44741Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parame340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45578WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-48017DbGate: Remote Code Execution via functionName injection in loadReader endpoint340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-501864gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export344360 , 347009 , 390709
CVE-2026-55084SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-55676Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component351000
CVE-2026-58195Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into ex340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-60009theia Arbitrary Code Execution Vulnerability351000
CVE-2026-62857Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65702Vanna 2.0.2 Path Traversal via FileSystemConversationStore340007 , 344360 , 390709
CVE-2026-70369Koha - SQL Injection in reports/acquisitions_stats.pl340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-70370Koha - SQL Injection in reports/catalogue_stats.pl340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-70373Koha - SQL Injection in reports/issues_stats.pl340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72557Cockpit CMS Cockpit CMS - Unrestricted File Upload351000
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8071Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass331702 , 333140 , 333141 , 344370 , 346755
CVE-2016-20097Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20248WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download340007 , 344360 , 347009 , 390709
CVE-2017-20250WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download340007 , 344360 , 347009 , 390709
CVE-2018-25374Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal340007 , 344360 , 347009 , 390709
CVE-2018-25409SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.php351000
CVE-2019-25671VA MAX 8.3.4 Remote Code Execution via changeip.php340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2019-25673UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload351000
CVE-2019-25765ASP-CMS SQL Injection via commentList.asp id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-47938ImpressCMS 1.4.2 Remote Code Execution via Autotasks340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2021-47939Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File Upload340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.php340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2022-50997Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 , 393781
CVE-2024-58374Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-30007HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10108xiaomusic 0.5.7 Path Traversal via GET /music endpoint340007 , 344360 , 347009 , 390709
CVE-2026-12496Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-15217Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-17524zip-lib Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-25559OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint340007 , 344360 , 347009 , 390709
CVE-2026-25855OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload340007 , 344360 , 347009 , 390709
CVE-2026-25856OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface340007 , 344360 , 347009 , 390709
CVE-2026-27634Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-28445Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview333140 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-31844Authenticated SQL Injection in Koha displayby parameter of suggestion.pl340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-34367InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field337109 , 337110 , 340147 , 340162 , 340163 , 340165 , 344360 , 344370 , 347009 , 390722 , 398021 , 398022
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-35184EcclesiaCRM has a Critical SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-35214Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write340007 , 344360 , 390709
CVE-2026-41147NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class333140
CVE-2026-41453Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-43982Algernon: Path traversal file write via savein()340007 , 344360 , 390709
CVE-2026-44667Faction: Stored XSS in Remediation Verification Attachment Filename Preview Rendering333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-44669Faction: Stored XSS in Assessment Attachment Filename Preview Rendering333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-44729Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers)333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-44739Pimcore: SQL Injection in Custom Reports Column Configuration340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44886Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-45115MyBB: Buddy/ignore list username XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45116MyBB: Profile field type confusion XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-45270CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-46518OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-46746sinec ins OS Command Injection Vulnerability340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate340007 , 344360 , 390709
CVE-2026-47659Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}340007 , 344360 , 347009 , 390709
CVE-2026-47661Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read340007 , 344360 , 347009 , 390709
CVE-2026-47743Shopper: Multiple data integrity and disclosure issues in admin Livewire components333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-48026lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48527HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-49143BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50636LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54347Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-65759Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1340007 , 344360 , 347009 , 390709
CVE-2026-65919Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload340007 , 344360 , 347009 , 390709
CVE-2026-67200Perspective 5.0.0 Path Traversal via cwd_static_file_handler340007 , 344360 , 347009 , 390709
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermark340007 , 344360 , 347009 , 390709
CVE-2026-69095OpenWrt luci-app-bmx7 Path Traversal via bmx7-info340007 , 344360 , 347009 , 390709
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 350147 , 390904 , 393655
CVE-2026-69100LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/file340007 , 344360 , 390709
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twig340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72870Dokploy: Command Injection via Docker Credentials in buildRemoteDocker340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72874Dokploy: Command Injection via Unescaped Git URL in Clone Commands340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73680Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75111Evidently UI Path Traversal via Dataset Materialization Filename344360 , 347009 , 390709
CVE-2026-75482SWE-agent Trajectory Inspector Path Traversal File Disclosure340007 , 344360 , 347009 , 390709
CVE-2026-75914CodeWhale before 0.8.64 Path Traversal via image_analyze symlink340007 , 344360 , 390709
CVE-2026-9506Path Traversal Vulnerability in Bagisto344360 , 347009 , 390709
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-66024XWiki Blog Application home page vulnerable to Stored XSS via Post Title333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-11349Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-11974Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download340748 , 344360 , 347006 , 390709
CVE-2026-12721Kirki < 6.0.13 - Unauthenticated SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-3430Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-34463MantisBT has Stored HTML Injection/XSS via Clone Issue Form333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34577Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-35032Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-39931OpenEMR Authenticated SQL Injection via backup.php Import Feature340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupware340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-42425OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative Scripting340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-45298Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-46491SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi340007 , 344360 , 347009 , 390709
CVE-2026-49864wetty vulnerable to DOM XSS via file-download filename333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 344365 , 346755 , 350147 , 350148
CVE-2026-54650openhole-server vulnerable to path traversal via URL-decoded request path347009
CVE-2026-566779Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-59239Stored XSS in Prospero Flow CRM email body allows administrator account takeover333140 , 333141 , 340095
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-63429HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context351000
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup Path340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup Path340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-66397phpMyFAQ before 4.1.6 Path Traversal via category image deletion344360 , 390109
CVE-2026-67328@better-auth/sso before 1.6.21 Account Takeover via SSO333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameter340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.php340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73670CMS Admin SQL Injection via db_data.php table_name Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 380026 , 380122 , 390572
CVE-2026-73850Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-7412Eclipse BaSyx SSRF Vulnerability344360 , 347009 , 390709
CVE-2026-75833Grav API Plugin Open Redirect via Backslash Bypass344365
CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious image344360 , 390709
CVE-2026-21618Cross-site scripting (XSS) in OAuth Device Authorization screen333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34931hoppscotch: Improper loopback redirect_uri validation in device-login flow344365
CVE-2026-34932hoppscotch: Stored XSS via mock server responses on backend origin333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-44238FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44706Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44881Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update340007 , 344360 , 347009 , 390709
CVE-2026-46372SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-51583usememos through v0.30.0 Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-57894Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-63361LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-65707Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-65986CVAT has stored XSS via annotation guide assets333140 , 333141 , 340095 , 341256 , 342259 , 350147 , 350148
CVE-2026-67424Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-67428Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-69250Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-73079Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstrea340007 , 344360 , 347009 , 390709
CVE-2026-49489OpenCATS - SQL Injection in DataGrid sortDirection Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5385GLPI 11.0.0 - Stored XSS in knowledge base333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-57862Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocols337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-64657Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72855Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-73629Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-75855ArcadeDB before 26.8.1 Path Traversal via create/drop database340007 , 344360 , 390709
CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component337109 , 337110 , 344360 , 398021 , 398022
CVE-2025-59711biztalk360 Path Traversal Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34576Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34966Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-633139Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65056mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-69086SiYuan before v3.7.3 Path Traversal via unvalidated avID340007 , 344360 , 390709
CVE-2026-75842ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV340007 , 340029 , 344360 , 344370 , 390109 , 390709
CVE-2025-69755Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-14920AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2026-16268Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34725dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket340007 , 344360 , 347009 , 390709
CVE-2026-40075OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet340007 , 344360 , 347009 , 390709
CVE-2026-43910Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-45711Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs340007 , 344360 , 390709
CVE-2026-48126Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir340007 , 344360 , 347009 , 390709
CVE-2026-54691datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-56670ComfyUI: Stored XSS via SVG file upload on the /view endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-73658Trigger.dev: Cross-tenant object store read and write via URL path traversal347009
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.php340007 , 344360 , 347009 , 390709
CVE-2026-15258Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite340007 , 344360 , 347009 , 390709
CVE-2026-33437Stirling PDF: Stored XSS in Info Summary333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-34365InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34366InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-34522SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directory340007 , 344360 , 390709
CVE-2026-39341SQL injection in ChurchCRM.0340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39344Reflected XSS the login page through the 'username' parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45344LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-46484Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user340007 , 344360 , 347009 , 390709
CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-48060Litestar: HTML Injection Through CSRF Token333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48081OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer333140 , 333141 , 340095 , 342259
CVE-2026-48695fastnetmon Command Injection Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50143Actor MCP path authority injection leaks Apify token337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-50758DayuanJiang next-ai-draw-io 0.4.13 Arbitrary Code Execution Vulnerability333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73659Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API340007 , 344360 , 347009 , 390709
CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex340007 , 344360 , 347009 , 390709
CVE-2026-67179Genkit improper host header validation340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-67309Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass340007 , 344360 , 347009 , 390709
CVE-2025-27621UpTrain has a Constant Default API Key340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34163Server-Side Request Forgery via MCP Tools Endpoint in FastGPT337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-34936PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-39361OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_url337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-39965TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-40519Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-42345FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, a337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-44285FastGPT: SSRF Protection Bypass via externalFile in Dataset Preview API337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-45806Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-47179Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane340007 , 344360 , 347009 , 390709
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files340007 , 344360 , 347009 , 390709
CVE-2026-58314Two SSRF findings in Gitea 1.26.2337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-61835Directus: SSRF Protection Bypass via 0.0.0.0 in File Import337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63764LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-67346Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-71303Lemur: Incomplete fix for CVE-2026-55166 – ACME authority update endpoint allows non-admin to replace acme_url with i337109 , 337110 , 340163 , 344360 , 398021 , 398022
CVE-2026-71365Awx: webhook status callback ssrf leaks the git pat337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2026-73498MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_at340007 , 344360 , 347009 , 390709
CVE-2026-8183Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement340007 , 344360 , 347009 , 390709
CVE-2026-16969DFIR-IRIS Stored XSS in Assets333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-18360DFIR-IRIS Stored XSS in Custom Attributes333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-18361DFIR-IRIS Stored XSS in Datastore Upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-39369WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs340007 , 344360 , 390709
CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard Module340007 , 344360 , 347009 , 390709
CVE-2026-45082Karakeep has a SSRF Protection Bypass via Redirect Handling337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-63094SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft344365
CVE-2026-65695Office-Word-MCP-Server 1.1.11 Path Traversal via document tools344360 , 390709
CVE-2025-45145Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-10716Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12592SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header333141 , 334168 , 340003 , 340099 , 340158 , 341099 , 342259
CVE-2026-12987Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-16573Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload346755
CVE-2026-32820dataCycle Public Markdown Path Traversal Via /docs/*path340007 , 344360 , 347009 , 390709
CVE-2026-34239Chamilo Authenticated Remote Code Execution340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-39359Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name340007 , 344360 , 390709
CVE-2026-39844NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization344360 , 390709
CVE-2026-39847Emmett has a path traversal in internal assets handler340007 , 344360 , 347009 , 390709
CVE-2026-44657MantisBT: Stored XSS in File Download333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-46581mojarra Path Traversal Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-50776Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-51077Dede CMS v.5.7.118 SQL Injection Vulnerability340145 , 380122
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-52476aiflowy <= 2.1.2 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-54293NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read347009
CVE-2026-5487DriveLock Directory Traversal Information Disclosure Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-5491DriveLock Directory Traversal Information Disclosure Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-56671ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read344360 , 347009 , 390709
CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-71209audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Trave340007 , 344360 , 347009 , 390709
CVE-2026-49857auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback337109 , 337110 , 344360 , 398004 , 398021 , 398022
CVE-2026-70666Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-7460mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755 , 350147 , 350148
CVE-2025-67405Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67406Advocate office management system Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67407Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-67408Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69944kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69945kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-69949kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-6735XSS within PHP-FPM status endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-8203Concrete CMS 9.5.0 and below has Stored XSS on the height parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-31339simple inventory system SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-13157Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload351000
CVE-2026-13158Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload351000 , 382238 , 390501
CVE-2026-13392ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-15244HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search340748 , 344360 , 347006 , 390709
CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise340007 , 344360 , 347009 , 390709
CVE-2026-27834Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-27885Piwigo: SQL Injection in Activity.getList340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-34607Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE344360 , 347009
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Execution340007 , 344360 , 347009 , 390709
CVE-2026-39343ChurchCRM has a SQL Injection in Event Type Editor (Admin)340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39387BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter340007 , 344360 , 347009 , 390709
CVE-2026-4267Query Monitor <= 3.20.3 - Reflected Cross-Site Scripting via Request URI333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266
CVE-2026-6229Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-71284Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-7537MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Par351000
CVE-2018-25346WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2018-25352WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2018-25392MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25393Navigate CMS 2.8.5 Path Traversal via navigate_download.php340007 , 344360 , 347009 , 390709
CVE-2018-25410SIM-PKH 2.4.1 SQL Injection via media.php id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25421Open STA Manager 2.3 Arbitrary File Download via Path Traversal340007 , 344360 , 347009 , 390709
CVE-2018-25429Paroiciel 11.20 SQL Injection via zProIdPro Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25430Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2018-25431No-Cms 1.0 SQL Injection via order_by Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25664SuiteCRM 7.10.7 SQL Injection via record Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12970LearnPress < 4.4.1 - Reflected XSS via c_search333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-13725Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax346755
CVE-2026-14234WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-14239Tourmaster < 5.4.8 - Stored XSS via CSRF333141 , 340087 , 340095 , 340099 , 340148 , 341099 , 341266 , 346755
CVE-2026-14870Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id340087 , 340099 , 341099 , 341266
CVE-2026-16007Authenticated SQL Injection in AppFlowy340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-18737Shlink Blind SQL Injection via tags/stats orderBy Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-22664prompts.chat SSRF via Fal.ai Media Status Polling337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-33714Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34598YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-39370WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltr337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-42339New API: SSRF Filter Bypass via 0.0.0.0337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-45725compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal347009
CVE-2026-46555WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration340007 , 344360 , 347009 , 390709
CVE-2026-48231Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48232Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48233Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48234Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48236Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48237Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48238Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48239Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48240Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63080Aptabase SQL Injection via ClickHouse query backend340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-64826rConfig < 8.2.13 Path Traversal File Read via FileDownloadController344360 , 347009 , 390709
CVE-2026-6858Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72607Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72609Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-74247Quay: ssrf via build archive_url in quay build api337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopy340007 , 344360
CVE-2026-75844ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-9833Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-10107MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-40506OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php340007 , 344360 , 347009 , 390709
CVE-2026-55746Cotonti stored XSS via PFS folder title333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-58411ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-69704Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-73033Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php340007 , 344360 , 347009 , 390709
CVE-2026-74038Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment340007 , 344360
CVE-2022-50954WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2022-50956WordPress Plugin amministrazione-aperta 3.7.3 Local File Read340007 , 344360 , 347009 , 390709
CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-39383Gotenberg unauthenticated blind SSRF via unfiltered webhook URL337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2026-39838ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-39936Stored XSS in Score due to usage of non-reserved data attributes333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-40598MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-41917OpenKM 6.3.12 Local File Inclusion via Admin Scripting344360 , 347009
CVE-2026-44651SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-44652SillyTavern: SSRF vulnerability in the CORS proxy middleware337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-45731WWBN AVideo: Authenticated Arbitrary File Read in view/update.php340007 , 344360 , 390709
CVE-2026-45774compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal340007 , 344360 , 347009 , 390709
CVE-2026-46337WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.php340007 , 344360 , 347009 , 390709
CVE-2026-54885Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-5739PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-59238Stored XSS in Pentestify via unsanitized finding images and report client logo333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-69092Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-73058stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-59709biztalk360 Path Traversal Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-13605Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-14817Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-14827Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter333140 , 333141 , 340095 , 342259
CVE-2026-14833Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-14872Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-15047s2Member < 260805 - Contributor+ Stored XSS via Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-15153WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16069Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-16559YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-33741EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35593Trilium Notes has Local File Inclusion via upload modified file API endpoint340007 , 344360 , 390709
CVE-2026-39311Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments333140 , 333141 , 340095 , 340099 , 341099 , 342259 , 344363
CVE-2026-67352luci-app-https-dns-proxy Stored XSS via resolver_url333140 , 333141 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-71475Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path340007 , 344360 , 347009 , 390709
CVE-2026-34216CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-11442Allegra exportReport Directory Traversal Information Disclosure Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-12898All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write330791 , 340152 , 340748 , 344360 , 347006 , 390709 , 390716
CVE-2026-14554Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-15974sglang Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16065Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-16548Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint351000
CVE-2026-26379koha Server-Side Request Forgery Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34740AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34787Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter344360 , 347009
CVE-2026-34788Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-35718fd8136 firmware Path Traversal Vulnerability344360 , 347009
CVE-2026-36227Easy Chat Server 3.1 Arbitrary Code Execution Vulnerability340007 , 344360 , 390709
CVE-2026-39229Bolt CMS through 3.7.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39368WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0340007 , 344360 , 390709
CVE-2026-46556FlaskBB: SSRF in get_image_info() via unrestricted avatar URL337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-48093Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed333140
CVE-2026-52371xxl-job v3.4.0 Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-52607reportico-web <= 8.1.0 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-58442Repository migration SSRF via multi-answer DNS allow-list bypass337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal340007 , 344360 , 390709
CVE-2026-72608Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-72739Dokploy: Command Injection via Compose Shell Execution340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73573zimbra collaboration suite Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-73574zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-7646Langflow is affected by security vulnerabilities in Model Context Protocol features344360 , 347009 , 390709
CVE-2026-7658Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement340007 , 344360 , 390709
CVE-2025-15064Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets346755
CVE-2026-0737Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-0738Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 346755
CVE-2026-36214osTicket Cross-Site Scripting Vulnerability333140 , 342259
CVE-2026-3885WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_bo333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45573Decidim: Push subscriptions can be abused for server-side requests337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-45797HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-50592Znuny Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34371LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversal340007 , 344360 , 390709
CVE-2026-39365Vite has a Path Traversal in Optimized Deps .map Handling340007 , 344360 , 347009 , 390709
CVE-2026-42335MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-42344FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-42538IRIS has an Insecure File Upload351000
CVE-2026-44284FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassable340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-49120Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-56722Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI344360 , 390709
CVE-2026-63107LimeSurvey SSRF via REST API Survey Template Host Header337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63643MagicMirror: ssrf calendar .js337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-63731HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-63769Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder340007 , 344360 , 347009 , 390709
CVE-2026-65593n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-67620Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-70667Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fi337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-73530Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2018-6882zimbra collaboration suite Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-65341Ecommerce Fruits Bazar 1.0 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 342259
CVE-2026-11588EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-11881Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-12982Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-13330Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-13400Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-14190Sina Extension for Elementor < 3.10.2 - Reflected XSS346755
CVE-2026-14207LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-14841King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget346755
CVE-2026-14845NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-14921Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 346755
CVE-2026-17532Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-26028CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-26483Mettle SendPortal 3.0.1 and earlier Cross-Site Scripting Vulnerability333140
CVE-2026-30251zenshare suite Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-30252zencrm Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030
CVE-2026-33213Redash: Open redirect vulnerability in post-login redirect handling344365
CVE-2026-34206Captcha Protect: Reflected XSS in challenge page via unsanitized destination rendered with text/template333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34229Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34396AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout340165 , 344365
CVE-2026-34739AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34847hoppscotch: Open redirect via /enter?redirect=344365
CVE-2026-35404Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter344365
CVE-2026-36324SourceCodester Doctor Appointment System 1.0 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-36725FastapiAdmin v2.2.0 Cross-Site Scripting Vulnerability333140
CVE-2026-37750School Management System by mahmoudai1 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-38432erpnext Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-38444osTicket v1.18.3 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266
CVE-2026-38446Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-38947FluentCMS 1.2.3 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-40295Devise: Open Redirect via Unvalidated request.referrer in Timeoutable Session Timeout Handler344365
CVE-2026-41580Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-42253Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266
CVE-2026-51565Modules/Docs/DocsController.php in Milk admin <=0.9.8 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-52232FS Inc S3150-8T2F Switch 2.2.0D Build 118101 Cross-Site Scripting Vulnerability333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-52475aiflowy <= 2.1.2 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-5776Email Encoder < 2.4.7 - Unauthenticated Stored XSS333140 , 333141 , 340147 , 340148
CVE-2026-61526AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-70620Odysseus SSRF via Embedding Endpoint Configuration337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-73084Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2023-6717Keycloak: xss via assertion consumer service url in saml post-binding flow333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-18403LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-41363OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter340007 , 344360 , 347009 , 390709
CVE-2026-65698Void 1.3.4 Path Traversal via AI Agent File-Reading Tools340007 , 344360 , 347009 , 390709
CVE-2026-66004BlenderMCP Path Traversal via download_polyhaven_asset API340007 , 344360 , 347009 , 390709
CVE-2026-8245Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-13693Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal340748 , 344360 , 347006 , 390709
CVE-2026-10526EmbedPress < 4.6.1 - Unauthenticated Blind SSRF337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16949Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-34360HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-45709Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filte337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63428HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's dec333140 , 333141 , 340095 , 342259 , 350147 , 350148
CVE-2026-73243kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-40605Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API340007 , 344360 , 347009 , 390709
CVE-2026-6428Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10178code-projects Online Music Site AdminEditAlbum.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10186code-projects Online Hospital Management System patient.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-10249itsourcecode Online Blood Bank Management System viewrequest.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10250itsourcecode Online Blood Bank Management System campsdetails.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10251itsourcecode Online House Rental System ajax.php login sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-10252itsourcecode Online House Rental System manage_tenant.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10253itsourcecode Online House Rental System manage_payment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10260CodeAstro Online Job Portal delete-jobs.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10261CodeAstro Online Job Portal application_status.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10262code-projects Real State Services Login loginuser.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10263SourceCodester Computer Repair Shop Management System manage_product.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10280horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10287SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10620code-projects Student Admission System index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusion340007 , 344360 , 347009 , 390709
CVE-2026-10704SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-11435Jinher OA nextselectplan.aspx sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11456Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11474Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload351000 , 393655
CVE-2026-11482SourceCodester Class and Exam Timetabling System archive5.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11483SourceCodester Class and Exam Timetabling System archive4.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11484SourceCodester Class and Exam Timetabling System archive3.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11485SourceCodester Class and Exam Timetabling System archive2.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11486SourceCodester Class and Exam Timetabling System archive1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11488code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11489code-projects Online Music Site AdminDeleteAlbum.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11490code-projects Online Music Site Search.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11501SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11582CodeAstro Student Attendance Management System index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16125zevorn rt-claw http_request net.c claw_net_post server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-16127zevorn rt-claw http_request tool_net.c claw_net_post server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-16128zevorn rt-claw http_request swarm.c receiver_thread server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-16152SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16154SourceCodester Class and Exam Timetabling System edit_room1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16227SourceCodester Class and Exam Timetabling System edit_subject.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16228SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16252Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection340007 , 344360 , 347009 , 390709
CVE-2026-16484SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16765CodeAstro Online Classroom loginlinkadmin.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16910Quay: ssrf in red hat quay notification webhooks (slack/generic)337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-18641Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginC340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-18646danpros HTMLy Author Name htmly.php path traversal340007 , 344360 , 347009
CVE-2026-18788Trippo ResponsiveFilemanager dialog.php unrestricted upload351000
CVE-2026-18973heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19000JeecgBoot Anonymous Chat Attachment send server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19021SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19196SourceCodester Photo Share Website ajax.php login sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-19211SourceCodester Photo Share Website ajax.php signup sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-19343code-projects Task Management System AdminLogin.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19344code-projects Task Management System comment_count_user.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19374adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-19384SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-19710SourceCodester Simple Student Information System view_department.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19753Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19758dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal340007 , 344360 , 390709
CVE-2026-19762DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal340007 , 344360 , 390709
CVE-2026-19827alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal340007 , 344360 , 347009 , 390709
CVE-2026-19899SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19919code-projects Online Shopping System Login login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19926Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-45376Decidim: Admin user search allows SQL injection through similarity-based sorting340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5346huimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5368projectworlds Car Rental Project Parameter login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5551itsourcecode Free Hotel Reservation System Parameter login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5554code-projects Concert Ticket Reservation System Parameter process_search.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5555code-projects Concert Ticket Reservation System Parameter login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5564code-projects Simple Laundry System Parameter searchguest.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5565code-projects Simple Laundry System Parameter delmemberinfo.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5573Technostrobe HI-LED-WR120-G2 fs unrestricted upload351000
CVE-2026-5575SourceCodester/jkev Record Management System Login index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5577Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5631assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5634projectworlds Car Rental Project Parameter book_car.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5672code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5677Totolink A7100RU cstecgi.cgi CsteSystem os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5678Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5688Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5689Totolink A7100RU cstecgi.cgi setNtpCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5690Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5691Totolink A7100RU cstecgi.cgi setFirewallType os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5692Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5736PowerJob detailPlus Endpoint InstanceController.java sql injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5741suvarchal docker-mcp-server HTTP index.ts pull_image os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5802idachev mcp-javadc HTTP os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5805code-projects Easy Blog Site contact_us.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5813PHPGurukul Online Course Registration check_availability.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5814PHPGurukul Online Course Registration check_availability.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5824code-projects Simple Laundry System userchecklogin.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5827code-projects Simple IT Discussion Forum question-function.php sql injection340147 , 340148 , 340156 , 341256 , 342259 , 346755
CVE-2026-5829code-projects Simple IT Discussion Forum content.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122
CVE-2026-5832atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-68922MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads340007 , 344360 , 347009 , 390709
CVE-2026-7178ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-7194SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-7205duartium papers-mcp-server main.py search_papers path traversal340007 , 344360 , 390709
CVE-2026-7206dubydu sqlite-mcp entry.py extract_to_json sql injection340007 , 344360 , 390709
CVE-2026-7212edvardlindelof notes-mcp notes_mcp.py path traversal340007 , 344360 , 390709
CVE-2026-7214eghuzefa engineer-your-data server.py file_inf path traversal340007 , 344360 , 390709
CVE-2026-7216donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal344360 , 390709
CVE-2026-7217Deepractice PromptX Document File index.ts read_pdf absolute path traversal340007 , 344360 , 390709
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-7221TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-7223BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery334168 , 390719
CVE-2026-7314eiceblue spire-doc-mcp-server base.py get_doc_path path traversal340007 , 344360 , 390709
CVE-2026-7315eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal340007 , 344360 , 390709
CVE-2026-7319elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal340007 , 344360
CVE-2026-75014SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75079SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75080SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75089PHPGurukul Complaint Management System check_availability.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-75778code-projects Task Management System Login Form index.php select_with_multiple_condition sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-75986code-projects Online Job Portal System Password Recovery ForPass.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76048SourceCodester Simple Online Food Ordering System ajax.php login sql injection340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-76049SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-9355SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9356SourceCodester Hospitals Patient Records Management System manage_history.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9364projectworlds Online Art Gallery Shop adminHome.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9372ItzCrazyKns Vane Model Provider API route.ts server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-9383itsourcecode Electronic Judging System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9469yashpokharna2555 StudentManagementSystem success.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9470yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-9525itsourcecode Electronic Judging System edit_judge.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9526itsourcecode Electronic Judging System edit_team.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9528itsourcecode Electronic Judging System delete_judge.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9573itsourcecode Student Transcript Processing System index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9574itsourcecode Student Transcript Processing System trans.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9575itsourcecode Student Transcript Processing System index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9584code-projects Project Management System Login chk.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9606itsourcecode Courier Management System manage_user.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11569Quay: quay: stored xss via filedrop svg upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-14864JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode333140 , 340095 , 340147 , 342259 , 346755
CVE-2026-15234Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-15245BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-15262Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column333141 , 340087 , 340095 , 340099 , 341099 , 341266
CVE-2026-16063Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16537Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16558YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-17010Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta346755
CVE-2026-18266Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability344365
CVE-2026-18395Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-26378koha Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-30520loan management system SQL Injection Vulnerability340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-34212Docmost page content has stored XSS via unsanitized attachment URLs333140
CVE-2026-34590Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34848hoppscotch: Stored XSS in team member overflow tooltip via display name333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34974phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35403LORIS has potential cross-site scripting in survey_accounts module333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35455immich has Stored XSS via OCR Text in 360° Panorama Viewer333140 , 333141 , 340147 , 341256 , 346755
CVE-2026-36722bookcars v8.3 Arbitrary Code Execution Vulnerability351000
CVE-2026-39380Open Source Point of Sale has Stored XSS in Stock Location (Configuration)333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-39960MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values333140 , 341256
CVE-2026-39964TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45138CI4MS: Stored XSS in Blog Content via Broken html_purify Validation Rule333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-45580WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48483TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48762TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72570cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-72583fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-7798FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter337109 , 337110 , 340162 , 340163 , 340165 , 340464 , 340465 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-7869Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement340007 , 344360 , 390709
CVE-2026-9278Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2019-25731Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-14860Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-15932Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal340007 , 344360 , 347009 , 390709
CVE-2026-16336trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect340165 , 344365
CVE-2026-16531Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet340007 , 344360 , 390709
CVE-2026-16536Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-22662prompts.chat Blind SSRF via media-generate337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-25860OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler333140 , 333141
CVE-2026-34523SillyTavern: Path traversal allows file existence oracle340007 , 344360 , 347009 , 390709
CVE-2026-35208lichess.org has an Unsanitized Stream Title Injection on /streamer333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-36726bookcars v8.3 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-41472CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard333140 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-44583Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022
CVE-2026-47720FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48094ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-49138Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-5538QingdaoU OnlineJudge judge_server_heartbeat Endpoint JudgeServer.service_url server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5547Tenda AC10 httpd formAddMacfilterRule os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5606PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5808openstatusHQ openstatus Onboarding Endpoint client.tsx cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-59231Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-59232Stored Cross-site Scripting in Prospero Flow CRM lead name field333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-63730HyperDX < 2.31.0 SSRF via Webhook Test Endpoint337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-63768cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State340162 , 340163 , 340165 , 344365
CVE-2026-64626AVideo Encoder downloadURL SSRF via unpinned retry fallback337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-64870MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-69116FlyEnv < 4.18.0 Cross-Site Scripting via v-html333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73038NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-73082Activepieces: Server-side request forgery in MCP tool validation endpoint337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-73244kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing340007 , 344360 , 390709
CVE-2026-73422Astro: Reflected XSS via unescaped View Transition animation properties333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585
CVE-2026-73628Serendipity 2.3.5 Reflected XSS via search clean-URL route333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-73845CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer)337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-74858jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-9524xianrendzw EasyReport REST Endpoint execute sql injection340017 , 340145 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2018-25248MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2018-25349userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-25739GigToDo Freelance Marketplace Script 1.3 Persistent XSS333140 , 333141
CVE-2021-47931Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2021-47947Projectsend r1295 Stored Cross-Site Scripting via files-edit.php333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2021-47983WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code340095 , 346755
CVE-2022-50943Moodle LMS 4.0 Cross-Site Scripting via course search.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50948Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2022-50958WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2022-50959WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2022-50960WordPress International Sms Contact Form 7 Integration 1.2 XSS340087 , 340099 , 341099 , 341266
CVE-2022-50962uBidAuction 2.0.1 myOrders Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50963uBidAuction 2.0.1 myAuctions active Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50964uBidAuction 2.0.1 myAuctions loose Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50965uBidAuction 2.0.1 posts manage Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50966uBidAuction 2.0.1 news manage Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50968uBidAuction 2.0.1 auctions manage Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50969uBidAuction 2.0.1 mailingLog manage Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2022-50970WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter340087 , 340099 , 341099 , 341266 , 346755
CVE-2025-71404better-auth before 1.1.16 Reflected XSS via error parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-17597Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19434Stored Cross-site Scripting in Pentestify finding severity field333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19716Stored Cross-site Scripting in Pentestify user account deletion via unescaped username333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19761DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal340007 , 344360 , 347009 , 390709
CVE-2026-19763DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal340007 , 344360 , 347009 , 390709
CVE-2026-22675OCS Inventory NG Server Stored XSS via User-Agent333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-25557Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-32113Discourse: Open redirect via sso_destination_url cookie in enter344365
CVE-2026-32856Ellucian Banner Self-Service Reflected XSS via dateConverter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34161Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution333140
CVE-2026-34416OSCAL-GUI Reflected XSS via project parameter in oscal.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34417OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34798Endian Firewall /cgi-bin/routing.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34799Endian Firewall /manage/dnsmasq/hosts/ remark Stored Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34800Endian Firewall /cgi-bin/uplinkeditor.cgi NAME Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34801Endian Firewall /manage/dhcp/fixed_leases/ remark Stored Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34802Endian Firewall /cgi-bin/salearn.cgi remark user ham spam Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34803Endian Firewall /manage/qos/classes/ name Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-34804Endian Firewall /manage/qos/rules/ dscp Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34805Endian Firewall /cgi-bin/dnat.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34806Endian Firewall /cgi-bin/snat.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34807Endian Firewall /cgi-bin/incoming.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34808Endian Firewall /cgi-bin/outgoingfw.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34809Endian Firewall /cgi-bin/zonefw.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34810Endian Firewall /cgi-bin/vpnfw.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34811Endian Firewall /cgi-bin/xtaccess.cgi remark Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34812Endian Firewall /cgi-bin/proxypolicy.cgi mimetypes Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34813Endian Firewall /cgi-bin/proxyuser.cgi user Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34814Endian Firewall /cgi-bin/proxygroup.cgi group Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34815Endian Firewall /cgi-bin/smtpdomains.cgi DOMAIN Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34816Endian Firewall /manage/smtpscan/domainrouting/ domain Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34817Endian Firewall /cgi-bin/smtprouting.cgi ADDRESS BCC Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34818Endian Firewall /manage/dnsmasq/localdomains/ remark Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34819Endian Firewall /cgi-bin/openvpnclient.cgi REMARK Stored Cross-Site Scripting333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34820Endian Firewall /manage/ipsec/ remark Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34821Endian Firewall /manage/vpnauthentication/user/ remark Stored Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-34822Endian Firewall /manage/ca/certificate/ new_cert_name Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-34823Endian Firewall /manage/password/web/ remark Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35007Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35008Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35009Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35010Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35011Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35012Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35014Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35015Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35016Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']340162 , 340163 , 340165 , 344365
CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']340162 , 340163 , 340165 , 344365
CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']340162 , 340163 , 340165 , 344365
CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']340162 , 340163 , 340165 , 344365
CVE-2026-35474WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']344365
CVE-2026-35475WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']340165 , 344365
CVE-2026-4093Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels)333140 , 333141 , 340095
CVE-2026-42336MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-42350Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter344365
CVE-2026-42840ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-45551Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-47106Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes API333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48214Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48215Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48218Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id Parameters333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48219Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48220Open ISES Tickets < 3.44.2 Reflected XSS via ics205.php frm_add_str Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48221Open ISES Tickets < 3.44.2 Reflected XSS via ics205a.php frm_add_str Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48222Open ISES Tickets < 3.44.2 Reflected XSS via ics213.php frm_add_str Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48223Open ISES Tickets < 3.44.2 Reflected XSS via ics213rr.php frm_add_str Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48224Open ISES Tickets < 3.44.2 Reflected XSS via ics214.php frm_add_str Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48225Open ISES Tickets < 3.44.2 Reflected XSS via landb.php _type Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48226Open ISES Tickets < 3.44.2 Reflected XSS via os_watch.php ref and mode_orig Parameters333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48227Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Parameters333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48228Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id Parameters333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48229Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48530GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48531GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48532GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48534GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48535GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48536GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-48537GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48538GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-48539GFI Archiver < 15.13 Stored XSS via MailInsights.aspx333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-48552Nagios Core / XI DOM-based XSS via jsonquery.js333140 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48559Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-49131OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field333140 , 333141
CVE-2026-49132OPNsense < 26.1.9 Stored XSS via Certificate Description Field333140 , 333141
CVE-2026-53992Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-57857Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message Parameter333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755
CVE-2026-63302Local File Inclusion in Quick.CMS344360 , 347009
CVE-2026-64628Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-65697Fathom Lite 1.3.1 Stored XSS via /collect Endpoint333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-66296Reflected XSS in oaskit's default HTML error handler333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-66414Leantime Open Redirect in Login Controller via redirectUrl Parameter344365
CVE-2026-67333better-auth before 1.6.13 Stored XSS via javascript redirect_uri333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-72743SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-72832Grav before 2.0.12 Stored XSS via quoted-attribute bypass333140 , 333141
CVE-2026-73671Saurus CMS Unauthenticated Open Redirect via logout url parameter344365
CVE-2026-74908Grav plugin-api before 1.0.15 Script Injection via SVG351000
CVE-2026-75831Grav before 2.0.15 Stored XSS via audio/video source URL333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16955AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription340007 , 344360 , 390709
CVE-2025-15673Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read340007 , 344360 , 390709
CVE-2026-41412alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script344360
CVE-2026-51564the redirect parameter in Milk admin <=0.9.8 Open Redirect Vulnerability344365
CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path340007 , 344360 , 347009 , 390709
CVE-2026-71283Fledge IoT Gateway Backup Restore Tar Path Traversal344360 , 390709
CVE-2024-3822Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-15669Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-14203Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title340087 , 340099 , 341099 , 341266
CVE-2026-15233Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title340087 , 340099 , 341099 , 341266
CVE-2026-34246CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755
CVE-2026-39390CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-39392CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-43924FOSSBilling has an open redirect via administrator-configured redirect targets344365
CVE-2026-46516Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-67612OpenEMR 8.2.0 Stored XSS via import_template.php Template Management333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-67617Microweber CMS 2.0.20 Stored XSS via tag_names Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-70560Ultimate POS Stored XSS via First Name Field in Leave Notifications333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-9577Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-14236Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect344365
CVE-2026-3093Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-42329Iris has an Open Redirect issue344365
CVE-2026-16273Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 346755 , 350147 , 350148
CVE-2026-12724Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-26477dokuwiki Denial of Service Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-32250NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index.php?route=/queries/user/333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-35411Directus is an Open Redirect in Admin 2FA Setup Page344365
CVE-2026-36239PbootCMS v.3.2.11 Cross-site Scripting Vulnerability340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-43936e107: Server-Side Request Forgery (SSRF) in the remote file fetcher337109 , 337110 , 341737 , 341738 , 344360 , 398021 , 398022
CVE-2026-48012Shopware SSO referer trust leading to an arbitrary redirect target344365
CVE-2026-49856@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-72610Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-73657Trigger.dev: Cross-tenant payload poisoning via packet write + replay347009
CVE-2026-10052Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpoints337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-14238Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-48013Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-14189WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-17011Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-15381WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-15677GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories346755
CVE-2026-10827Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755 , 350147 , 350148
CVE-2026-13393ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-48051Papra: SSRF via HTTP redirect bypass in webhook delivery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-9060Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style346755
CVE-2026-9061Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-9062Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal340748 , 344360 , 347006 , 390709
CVE-2026-23603Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-55825Contao: Possible path traversal in job download URIs340007 , 344360 , 347009 , 390709
CVE-2026-49262Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-68927MobSF: SSRF port restriction bypass in assetlinks_check337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-42578Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation390719
CVE-2026-44286FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-55554Dompdf: Chroot Validation Bypass344360 , 390709
CVE-2026-73087Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2024-14046OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload351000
CVE-2025-15098YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10153westboy CicadasCMS AbstractCacheManager.java search cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10170code-projects Visitor Management System phone_0.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10173Orthanc Explorer 2 URL StudyList.vue cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10193OFCMS ComnController ComnController.java query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10202OFCMS JSON Query SystemDictController.java query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10203OFCMS JSON Query SystemParamController.java query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10204OFCMS JSON Query SysUserController.java query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10209code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10213AstrBotDevs AstrBot API Endpoint delete path traversal340007 , 344360
CVE-2026-10239JeecgBoot edit WordUtil.addImage server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-10240JeecgBoot test server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10241jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10256itsourcecode Content Management System save_comment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10258itsourcecode Content Management System add_sub_topic.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10265itsourcecode Content Management System edit_topic.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10274indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10276hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10278ishayoyo excel-mcp read_file/write_file index.ts path traversal340007 , 344360 , 390709
CVE-2026-10279hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10286CodeAstro Payroll System home_employee.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10289code-projects Hotel and Tourism Reservation System tour.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-10296itsourcecode Fees Management System ajax.php sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-10297itsourcecode Fees Management System manage_course.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10301itsourcecode Fees Management System index.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-10302itsourcecode Fees Management System manage_fee.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10558SourceCodester Pizzafy Ecommerce System index.php file inclusion344360 , 347009
CVE-2026-10559SourceCodester Pizzafy Ecommerce System index.php file inclusion340007 , 344360 , 347009 , 390709
CVE-2026-10568itsourcecode Fees Management System manage_payment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10662ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10690wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-10806mjperpinosa stumasy add_post.php unrestricted upload351000
CVE-2026-10807mjperpinosa stumasy change_profile_image.php unrestricted upload351000
CVE-2026-10808itsourcecode Fees Management System manage_student.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10809itsourcecode Fees Management System manage_user.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10810itsourcecode Fees Management System navbar.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-10811itsourcecode Fees Management System receipt.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10874projectworlds Online Art Gallery Shop Project adminHome.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10875projectworlds Online Art Gallery Shop Project adminHome.ph sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-11412Jinher OA GetFormSn.aspx sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11436Mage AI Sign-in Flow index.tsx useMutation cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11467jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal340007 , 344360 , 390709
CVE-2026-11475Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11476Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11477hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect340162 , 340163 , 340165 , 344365
CVE-2026-11495CodeAstro Ingredients Stock Management System add_stock.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11506CodeAstro Leave Management System search_staff_for_deletion.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11507CodeAstro Leave Management System delete_leave_type.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11508CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11510CodeAstro Leave Management System add_leave.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11512itsourcecode Hospital Management System billing.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11513itsourcecode Hospital Management System adminaccount.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11514itsourcecode Hospital Management System addpatient.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11518SourceCodester Inventory System User Management users.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 380106
CVE-2026-11529designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection340016 , 380122
CVE-2026-11558CodeAstro Payroll System home_salary.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11559CodeAstro Payroll System view_account.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11583CodeAstro Student Attendance Management System createClass.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11584CodeAstro Student Attendance Management System createClass.php edit sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-11585CodeAstro Student Attendance Management System createClassArms.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-12210universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16074AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-16124nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery334168 , 390719
CVE-2026-16131itsourcecode Hospital Management System prescriptionrecord.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16194zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-16219Croogo CMS Admin File Manager FileManager.php isEditable path traversal344360 , 347009
CVE-2026-16220code-projects Online Examination System account.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-162221Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-162231Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-16229itsourcecode Courier Management System index.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-16244itsourcecode Hospital Management System prescriptionorderreport.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16334itsourcecode Hospital Management System prescriptionorder.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16449zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16451zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload351000
CVE-2026-16485SourceCodester Class and Exam Timetabling System class.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16486SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-17458mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-18644danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal344360
CVE-2026-18645danpros HTMLy Admin Content Endpoint admin.php add_content path traversal344360
CVE-2026-18766chetans9 core-php-admin-panel customers.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-18774NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-18896lavkush-maurya Student-Registration-System changepass.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-18959yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal340007 , 344360 , 390709
CVE-2026-18968ttttonyhe OBlog tags.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-19020itsourcecode Hospital Management System servicetype.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19040MissionSquad mcp-api dcrClients.ts server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19067itsourcecode Hospital Management System treatment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19068itsourcecode Hospital Management System treatmentdetail.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19069itsourcecode Hospital Management System treatmentrecord.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19070itsourcecode Hospital Management System viewadmin.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19071itsourcecode Hospital Management System viewappointment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19210SourceCodester Photo Share Website ajax.php save_upload unrestricted upload351000
CVE-2026-19246HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19340anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19347itsourcecode Hospital Management System viewdoctor.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19364itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19375dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19378code-projects Task Management System CommentSave.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19752EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-19756Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal340007 , 344360 , 390709
CVE-2026-19767itsourcecode Hospital Management System viewdoctortimings.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19828648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal340007 , 344360 , 347009 , 390709
CVE-2026-19829648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal344360 , 347009 , 390709
CVE-2026-19894itsourcecode Hospital Management System viewmedicine.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19917code-projects Online Food Order System delete_food_items1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19920code-projects Online Shopping System action.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19921code-projects Online Shopping System homeaction.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19923code-projects Online Shopping System checkout_process.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19927OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19932DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19934itsourcecode Hospital Management System vieworder.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19958iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19972itsourcecode Hospital Management System viewpatient.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19973itsourcecode Hospital Management System viewpaymentreport.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19984jkawamoto mcp-florence2 init.py get_images server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19998code-projects Online Shopping System offersmail.php cross site scripting333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-20000itsourcecode Hospital Management System viewprescriptionrecord.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5206code-projects Simple Gym Management System Payment sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5351Trendnet TEW-657BRM setup.cgi add_wps_client os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5352Trendnet TEW-657BRM setup.cgi edit os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5353Trendnet TEW-657BRM setup.cgi ping_test os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5354Trendnet TEW-657BRM setup.cgi vpn_connect os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5355Trendnet TEW-657BRM setup.cgi vpn_drop os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5470mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request for337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5537halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5543PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5552PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5553itsourcecode Online Cellphone System Parameter available.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5558PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5560PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5578CodeAstro Online Classroom Parameter addassessment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5579CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5580CodeAstro Online Classroom Parameter addvideos.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5583PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5607imprvhub mcp-browser-agent URL Parameter handlers.ts CallToolRequestSchema server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5620itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5635PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5636PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5675itsourcecode Construction Management System Parameter borrowed_tool.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5681itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5719itsourcecode Construction Management System borrowedtool.php sql injection340145 , 340156 , 341145 , 380122 , 390572
CVE-2026-5803bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery337109 , 340162 , 347009 , 390722
CVE-2026-5823itsourcecode Construction Management System borrowed_tool_report.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5825code-projects Simple Laundry System delmemberinfo.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5826code-projects Simple IT Discussion Forum edit-category.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-59727Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-67350Serendipity < 2.6.1 Open Redirect via exit.php344365
CVE-2026-7196CodeAstro Online Classroom guestdetails sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-74842Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-75077SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-75078SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-75086itsourcecode Hospital Management System viewroom.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75087itsourcecode Hospital Management System viewdepartment.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75088itsourcecode Hospital Management System viewbilling.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75876xianrendzw EasyReport Move Operations ModuleController.java sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-7890Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-8188Wavlink NU516U1 adm.cgi change_wifi_password os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8189Wavlink NU516U1 adm.cgi wzdrepeater os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8190Wavlink NU516U1 adm.cgi wan os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-8192Wavlink NU516U1 adm.cgi wzdap os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8227Wavlink NU516U1 adm.cgi wzdapMesh os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8228Wavlink NU516U1 wireless.cgi advance os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8229Wavlink NU516U1 wireless.cgi WifiBasic os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8230Wavlink NU516U1 login.cgi sys_login1 os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8231CodeAstro Online Catering Ordering System deleteorder.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9302546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9342SourceCodester Hospitals Patient Records Management System view_history.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9343Edimax EW-7438RPn webs formWpsStart os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9347Edimax EW-7438RPn webs formWizSurvey os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9415code-projects Employee Management System eloginwel.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9416code-projects Employee Management System myprofile.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9417code-projects Employee Management System myprofileup.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9418code-projects Employee Management System changepassemp.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9419code-projects Employee Management System empproject.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9424Edimax EW-7438RPn Content-Type formWlanMP os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9448code-projects Employee Management System applyleave.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9450code-projects Employee Management System psubmit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9451code-projects Employee Management System applyleaveprocess.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9473c-rick jimeng-mcp api.ts generateVideo path traversal340007 , 344360 , 390709
CVE-2026-9511Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9512Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9514Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9515Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9518hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-9519stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9520blitz-js blitz Sign-in LoginForm.tsx cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-9527itsourcecode Electronic Judging System judges.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9531Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9532Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9533Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9534Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9542CodeAstro Leave Management System add_staff.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9566teableio teable Sign-up LoginPage.tsx cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-9607itsourcecode Courier Management System parcel_list.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10155Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10171code-projects Online Music Site AdminUpdateAlbum.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10228raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-10234Mettle sendportal Campaign webview cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10244SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10245SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10246SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-10247SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-105671Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting333140 , 333141
CVE-2026-10583nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery334168 , 390719
CVE-2026-12211Intelbras iNVU 7016 FT Web syslog path traversal340007 , 344360 , 347009 , 390709
CVE-2026-16088halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal340007 , 344360 , 347009 , 390709
CVE-2026-16155SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16156SourceCodester Class and Exam Timetabling System forexam.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16202SourceCodester Class and Exam Timetabling System CYS.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16203SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-18856Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-19209SourceCodester Photo Share Website index.php home cross site scripting333140 , 333141 , 340147 , 340148 , 342259 , 350147 , 350148
CVE-2026-19383saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload351000
CVE-2026-19787SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19839SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload351000
CVE-2026-19922code-projects Online Shopping System checkout.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19925SourceCodester Stock Management System Master.php delete_supplier sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19964Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5576SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload340156 , 341245 , 351000 , 390501
CVE-2026-5806code-projects Easy Blog Site update.php cross site scripting333140 , 333141 , 340095 , 342259
CVE-2026-5810SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-7222code-projects Coaching Management System Complaint Form complaint.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-8139Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-8259Tenda AC6 httpd telnet os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-9464YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-10112sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-105141Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting333140
CVE-2026-10529westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2026-11434FluentCMS Blocks Plugin blocks cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-11468SourceCodester Hospitals Patient Records Management System page room_types cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-16129princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-16205Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19110DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19207PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-19369KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-19373PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5621ChrisChinchilla Vale-MCP HTTP index.ts os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5834code-projects Online Shoe Store admin_running.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-5835code-projects Online Shoe Store admin_football.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-5836code-projects Online Shoe Store admin_product.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-9564SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11502JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect340162 , 340163 , 340165 , 344365
CVE-2026-19353DedeCMS Installation Wizard index.php _4_Setup file inclusion340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370