Atomicorp WAF Research Notes
Research Update - 2026-08-23
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2025-34037 | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | 312658 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-34163 | Dongsheng Logistics Software Unauthenticated Arbitrary File Upload | 351000 |
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway OS Command Injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-33712 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34234 | CtrlPanel: Unauthenticated RCE using installer script | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-44181 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-57827 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 | 351000 |
| CVE-2026-72899 | Metabase SQL injection via public card or dashboard | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-8984 | Unauthenticated RCE | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8985 | Unauthenticated Command Injection | 340014 , 340023 , 344360 , 344361 , 344362 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-31818 | Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-42454 | Termix: OS Command Injection in Docker Container Management Endpoints | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-43986 | Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-44450 | Lumiverse: RCE via MCP stdio argument injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-45629 | Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-45632 | Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-51027 | FileThingie v.2.5.7 Information Disclosure Vulnerability | 340007 , 344360 , 390709 |
| CVE-2026-55166 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and cr | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-63298 | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-66898 | Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE | 390719 |
| CVE-2026-69083 | SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-69085 | SiYuan before v3.7.3 SQL Injection via searchDocs | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-72738 | Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-72740 | Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscan | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72865 | Dokploy: OS Command Injection via compose composePath | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72868 | Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-72872 | Dokploy: OS Command Injection via Bitbucket owner/repository in git clone | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72882 | Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72902 | Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73263 | Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path | 340014 , 340023 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73294 | Semaphore U: OS Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-8481 | Remote Code Execution via Code Validation Endpoint | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2015-10138 | Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload | 351000 |
| CVE-2022-31340 | simple inventory system SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-57631 | tduck Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-65336 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-65340 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-67403 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-67404 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69930 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69931 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69933 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69934 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69935 | SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69936 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69937 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69938 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69941 | SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69942 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69943 | SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69946 | SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69947 | SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69948 | SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10880 | Unauthenticated SQL Injection in Osnexus Quantastor | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-12940 | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-15732 | WGDashboard Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-30118 | scalar/astro v0.1.13 was discovered to Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-31040 | stata-mcp Code Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-34243 | wenxian: Command Injection in GitHub Actions Workflow via issue_comment.body | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-35048 | Piwigo RCE via PHP Code Injection into Config File in Installer | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-35471 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-35847 | the CheckUils.php file Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-36669 | ck_upload_handler.php in Feng Office 3.11.13.11 Arbitrary File Upload Vulnerability | 351000 |
| CVE-2026-37281 | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-38428 | kestra SQL Injection Vulnerability | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-38431 | erpnext Code Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-46670 | YesWiki: Unauthenticated SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-47391 | PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-48528 | Metacat has an unauthenticated SQL injection vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48687 | fastnetmon Command Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-49819 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-49827 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) | 351000 |
| CVE-2026-51775 | Fastadmin v.1.6.1.20250430 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-52348 | cool-admin-java 8.0.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-52472 | Wgcloud 3.6.4 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-67678 | RainyGao-Hithub DocSys v.2.02.80 Arbitrary Code Execution Vulnerability | 351000 |
| CVE-2026-67688 | ICS-Park Smart Park Management System v2.0 Arbitrary Code Execution Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-67689 | FineAdmin V1.0 Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-67919 | Halo 2.25.4 Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-67926 | JeecgBoot v.3.9.2 Arbitrary Code Execution Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-69240 | Sequelize: SQL Injection (Oracle DB) | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-12564 | Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credenti | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-12605 | glassfish Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34449 | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 393655 |
| CVE-2026-35906 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-53513 | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-72878 | Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-70477 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8986 | Command Injection via Malicious OCPP Server | 340014 , 340023 , 340193 , 344360 , 344361 , 344362 , 344363 , 344364 , 344366 , 344370 |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write | 340007 , 344360 , 390709 |
| CVE-2026-11423 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation | 344360 , 390709 |
| CVE-2026-33324 | SQLBot prompt injection allows arbitrary SQL execution and remote code execution | 340014 , 340016 , 340017 , 340023 , 340029 , 340157 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-39342 | ChurchCRM has a SQL injection searchwhat parameter via QueryView.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-39932 | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-63732 | 9router before 0.4.60 Remote Code Execution via default password | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-66395 | SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol | 333140 , 340095 , 341266 |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-72850 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-72879 | Dokploy: Command Injection via Registry Credentials in Swarm Upload | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73041 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73042 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-73043 | SiYuan before v3.7.4 Remote Code Execution via Template Calculation | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73044 | SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73050 | SiYuan before v3.7.4 Stored XSS via select option color | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73052 | SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73053 | SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73483 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2016-20052 | Snews CMS 1.7 Unrestricted File Upload via snews_files | 351000 |
| CVE-2016-20096 | Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20251 | WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 |
| CVE-2018-25412 | Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php | 351000 |
| CVE-2019-25687 | Pegasus CMS 1.0 Remote Code Execution via extra_fields.php | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2019-25727 | WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download | 340007 , 344360 , 347009 , 390709 |
| CVE-2021-47940 | WordPress Download From Files 1.48 Arbitrary File Upload | 351000 |
| CVE-2022-4995 | Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp | 351000 |
| CVE-2024-58348 | WordPress Background Image Cropper 1.2 Remote Code Execution | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-58355 | Cal.com through 4.7.15 Cross-Site Scripting via booking questions | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-31114 | Fooocus webui vulnerable to Remote Code Execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-23734 | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-34361 | HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-40329 | SQL Injection vulnerability via sortBy in beanFeed | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-40330 | Masa CMS SQL injection via sortDirection parameter in beanFeed | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-41939 | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-42849 | authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45118 | MyBB: Contact page reflected XSS | 333140 , 333141 , 340003 , 340087 , 340095 , 340099 , 340147 , 340148 , 340158 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45668 | Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-47669 | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE | 340007 , 344360 , 390709 |
| CVE-2026-47754 | unauthenticated path traversal in Metacat 2.x | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-53975 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-57858 | Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-60121 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-61511 | vBulletin 6.x - Remote Code Execution | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 360151 , 393655 |
| CVE-2026-63106 | ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63766 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-64625 | AVideo before 29.0 OS Command Injection via execAsync | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-64824 | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirect | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-65008 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655 |
| CVE-2026-65700 | h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API | 340007 , 344360 , 347009 , 390709 , 390719 |
| CVE-2026-65701 | SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route | 340007 , 344360 , 390709 |
| CVE-2026-65761 | Joomla Easy Store - SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-66394 | SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass | 300013 , 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-66418 | OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-67308 | Wazuh GitHub Actions Shell Injection via Fork Pull Request | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-67426 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-69110 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-70553 | MaxSite CMS Unauthenticated RCE via Install Endpoint | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-70558 | Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token | 351000 |
| CVE-2026-71944 | D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71945 | D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71946 | D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71947 | D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71948 | D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71949 | D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71950 | D-Link DWR-M961 Command Injection via /boafrm/formSmsManage | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71951 | D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71952 | D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71953 | D-Link DWR-M961 Command Injection via /boafrm/formNtp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71954 | D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71955 | D-Link DWR-M961 Command Injection via /boafrm/formWsc | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71956 | D-Link DWR-M961 Command Injection via app.cgi | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71984 | MSI Radix AXE6600 v781521 Command Injection via urlfilter | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71992 | MSI Radix AXE6600 v781521 Command Injection via macfilter | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-74798 | SiYuan kernel Path Traversal via database_clean MCP tool | 340007 , 344360 , 390709 |
| CVE-2026-74902 | SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9586 | Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63304 | AVideo through 29.0 OS Command Injection via listFFmpegProcesses | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-63305 | AVideo through 29.0 OS Command Injection via ffmpeg.json.php | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-65057 | Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65317 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-65318 | Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-50455 | the CodeIgniter Query Builder Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-15360 | Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-16532 | Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-17552 | Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten | 337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-34745 | Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public | 340007 , 344360 , 390709 |
| CVE-2026-44313 | LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders Function | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-47731 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by u | 340007 , 344360 , 390709 |
| CVE-2026-52610 | reportico-web <= 8.1.0 Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-73069 | Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary PostgreSQL Execution | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34448 | SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop cl | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34612 | Kestra: Remote Code Execution via SQL Injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-35198 | HeyForm vulnerable to stored XSS via form field titles | 333140 , 333141 , 340095 , 342259 , 350147 , 350148 |
| CVE-2026-42556 | Postiz stored XSS in public preview page | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45630 | Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-72851 | Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-73485 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73486 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73487 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-43984 | Tautulli has stored XSS in logFile via guest-controlled log_js_errors input | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-7202 | Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7203 | Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7204 | Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9384 | Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-9386 | Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9387 | Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9388 | Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9404 | Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9405 | Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9406 | Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9407 | Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9408 | Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9432 | Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9433 | Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9434 | Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9435 | Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9436 | Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9454 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9455 | Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9456 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9457 | Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9458 | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9475 | Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection | 340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-9476 | Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9477 | Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9478 | Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2016-20062 | Simply Poll 1.4.1 Plugin for WordPress SQL Injection | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2017-20243 | WordPress Car Park Booking Plugin SQL Injection via space_id | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20247 | WordPress Plugin PICA Photo Gallery 1.0 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20249 | WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-6884 | Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2018-25340 | Smartshop 1 SQL Injection via category.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25341 | Smartshop 1 SQL Injection via product.php id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25342 | Smartshop 1 SQL Injection via search.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25348 | Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25351 | Joomla! Component EkRishta 2.10 SQL Injection via username | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25362 | Twitter-Clone 1 SQL Injection via follow.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25364 | Twitter-Clone 1 SQL Injection via search.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25371 | mooSocial Store Plugin 2.6 SQL Injection via product parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25372 | MedDream PACS Server Premium 6.7.1.1 SQL Injection via email | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2018-25385 | E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25386 | HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25394 | Kados R10 GreenBee SQL Injection via update_release.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25395 | Kados R10 GreenBee SQL Injection via update_feature.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25411 | MGB OpenSource Guestbook 0.7.0.2 SQL Injection via email.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25413 | AiOPMSD Final 1.0.0 SQL Injection via search.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25414 | AiOPMSD Final 1.0.0 SQL Injection via actor.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25416 | AiOPMSD Final 1.0.0 SQL Injection via country.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25417 | AiOPMSD Final 1.0.0 SQL Injection via quality.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25418 | AiOPMSD Final 1.0.0 SQL Injection via year.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25419 | AiOPMSD Final 1.0.0 SQL Injection via genre.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25420 | AiOPMSD Final 1.0.0 SQL Injection via watch.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25422 | MOGG web simulator Script All Version SQL Injection via play.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25424 | Gate Pass Management System 2.1 SQL Injection via login-exec.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25425 | Yot CMS 3.3.1 SQL Injection via aid and cid Parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25428 | Paroiciel 11.20 SQL Injection via tRecIdListe Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25433 | Joomla JE Photo Gallery 1.1 SQL Injection via categoryid | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25434 | WP AutoSuggest 0.24 SQL Injection via autosuggest.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25662 | ResourceSpace 8.6 SQL Injection via watched_searches.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25668 | News Website Script 2.0.5 SQL Injection via index.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25669 | qdPM 9.1 SQL Injection via search_by_extrafields Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25675 | eDirectory All Versions SQL Injection Authentication Bypass | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25678 | C4G BLIS 3.4 SQL Injection via users_select.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25680 | Advance Gift Shop Pro Script 2.0.3 SQL Injection via search | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25684 | OpenDocMan 1.3.4 SQL Injection via where Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25694 | Kados R10 GreenBee SQL Injection via user2reset | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25728 | Care2x 2.7 Hospital Information System SQL Injection via ck_config | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25730 | Listing Hub CMS 1.0 SQL Injection via pages.php id | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25732 | PHP EI-Tube Script 3 SQL Injection via search parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2021-47928 | Opencart TMD Vendor System 3.x Blind SQL Injection via product route | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2021-47930 | Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2024-39024 | In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-45868 | LogicalDOC Enterprise up to and for v9.1.1 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-59710 | biztalk360 Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-12968 | Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-17623 | Langflow is affected OS Command Injection in Model Context Protocol features | 344360 , 347009 , 390709 |
| CVE-2026-17625 | Langflow is affected by OS Command Injection in Model Context Protocol features | 344360 , 347009 , 390709 |
| CVE-2026-24893 | openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-31069 | BillaBear (all versions prior to Jan 2026) SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34524 | SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within user | 340007 , 344360 , 390709 |
| CVE-2026-35031 | Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-35395 | WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-35470 | OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-36723 | bookcars v8.3 Arbitrary Code Execution Vulnerability | 340007 , 344360 , 390109 , 390709 |
| CVE-2026-41075 | RT: SQL injection via entry_aggregator parameter in JSON search | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-41473 | CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-42455 | LinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same origin) | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-42605 | AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Upload | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-43624 | F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project() | 340007 , 344360 , 390709 |
| CVE-2026-44741 | Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parame | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-45578 | WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-45662 | Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion) | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-48017 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-50186 | 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export | 344360 , 347009 , 390709 |
| CVE-2026-55084 | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-55676 | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component | 351000 |
| CVE-2026-58195 | Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into ex | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-60009 | theia Arbitrary Code Execution Vulnerability | 351000 |
| CVE-2026-62857 | Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65702 | Vanna 2.0.2 Path Traversal via FileSystemConversationStore | 340007 , 344360 , 390709 |
| CVE-2026-70369 | Koha - SQL Injection in reports/acquisitions_stats.pl | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-70370 | Koha - SQL Injection in reports/catalogue_stats.pl | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-70373 | Koha - SQL Injection in reports/issues_stats.pl | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-72557 | Cockpit CMS Cockpit CMS - Unrestricted File Upload | 351000 |
| CVE-2026-72875 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio) | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8071 | Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass | 331702 , 333140 , 333141 , 344370 , 346755 |
| CVE-2016-20097 | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20248 | WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download | 340007 , 344360 , 347009 , 390709 |
| CVE-2017-20250 | WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download | 340007 , 344360 , 347009 , 390709 |
| CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2018-25409 | SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.php | 351000 |
| CVE-2019-25671 | VA MAX 8.3.4 Remote Code Execution via changeip.php | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2019-25673 | UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload | 351000 |
| CVE-2019-25765 | ASP-CMS SQL Injection via commentList.asp id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2021-47938 | ImpressCMS 1.4.2 Remote Code Execution via Autotasks | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2021-47939 | Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2022-50997 | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2023-54350 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 , 393781 |
| CVE-2024-58374 | Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-30007 | HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10108 | xiaomusic 0.5.7 Path Traversal via GET /music endpoint | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-12496 | Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-15217 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-17524 | zip-lib Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-25559 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-25855 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-25856 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-27634 | Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-28445 | Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview | 333140 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-31844 | Authenticated SQL Injection in Koha displayby parameter of suggestion.pl | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-34367 | InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field | 337109 , 337110 , 340147 , 340162 , 340163 , 340165 , 344360 , 344370 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34792 | Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34793 | Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34794 | Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34795 | Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34796 | Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34797 | Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-35184 | EcclesiaCRM has a Critical SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-35214 | Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write | 340007 , 344360 , 390709 |
| CVE-2026-41147 | NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class | 333140 |
| CVE-2026-41453 | Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-43982 | Algernon: Path traversal file write via savein() | 340007 , 344360 , 390709 |
| CVE-2026-44667 | Faction: Stored XSS in Remediation Verification Attachment Filename Preview Rendering | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-44669 | Faction: Stored XSS in Assessment Attachment Filename Preview Rendering | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-44729 | Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Content-Type/Content-Disposition Headers) | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-44739 | Pimcore: SQL Injection in Custom Reports Column Configuration | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-44886 | Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-45115 | MyBB: Buddy/ignore list username XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45116 | MyBB: Profile field type confusion XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-45270 | CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-46518 | OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-46746 | sinec ins OS Command Injection Vulnerability | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-47394 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate | 340007 , 344360 , 390709 |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-47661 | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-47743 | Shopper: Multiple data integrity and disclosure issues in admin Livewire components | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-48026 | lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48527 | HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-49143 | BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-50636 | LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54347 | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-65759 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-65919 | Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-67200 | Perspective 5.0.0 Path Traversal via cwd_static_file_handler | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655 |
| CVE-2026-69089 | Grav CMS before 2.0.11 Path Traversal via watermark | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-69096 | OpenWrt luci-app-dockerman Read ACL Remote Code Execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 350147 , 390904 , 393655 |
| CVE-2026-69100 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71966 | CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72713 | XAgent Path Traversal Arbitrary File Read via /workspace/file | 340007 , 344360 , 390709 |
| CVE-2026-72819 | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72827 | Grav CMS before 2.0.13 Remote Code Execution via Twig | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72870 | Dokploy: Command Injection via Docker Credentials in buildRemoteDocker | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72874 | Dokploy: Command Injection via Unescaped Git URL in Clone Commands | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73680 | Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75111 | Evidently UI Path Traversal via Dataset Materialization Filename | 344360 , 347009 , 390709 |
| CVE-2026-75482 | SWE-agent Trajectory Inspector Path Traversal File Disclosure | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-75914 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink | 340007 , 344360 , 390709 |
| CVE-2026-9506 | Path Traversal Vulnerability in Bagisto | 344360 , 347009 , 390709 |
| CVE-2024-20353 | adaptive security appliance software Denial of Service Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-66024 | XWiki Blog Application home page vulnerable to Stored XSS via Post Title | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-11349 | Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-11974 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download | 340748 , 344360 , 347006 , 390709 |
| CVE-2026-12721 | Kirki < 6.0.13 - Unauthenticated SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34160 | Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata ser | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-3430 | Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-34463 | MantisBT has Stored HTML Injection/XSS via Clone Issue Form | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34577 | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-35032 | Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-39931 | OpenEMR Authenticated SQL Injection via backup.php Import Feature | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-40187 | Authenticated RCE via Malicious eTemplate Upload in EGroupware | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-42425 | OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-45298 | Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-46491 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-49864 | wetty vulnerable to DOM XSS via file-download filename | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 344365 , 346755 , 350147 , 350148 |
| CVE-2026-54650 | openhole-server vulnerable to path traversal via URL-decoded request path | 347009 |
| CVE-2026-56677 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-59239 | Stored XSS in Prospero Flow CRM email body allows administrator account takeover | 333140 , 333141 , 340095 |
| CVE-2026-61523 | WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-63429 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context | 351000 |
| CVE-2026-63725 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-65693 | Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-65711 | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-66397 | phpMyFAQ before 4.1.6 Path Traversal via category image deletion | 344360 , 390109 |
| CVE-2026-67328 | @better-auth/sso before 1.6.21 Account Takeover via SSO | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-67599 | ClearOS 7.9 OS Command Injection via Log Viewer filter parameter | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 |
| CVE-2026-69088 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73664 | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73670 | CMS Admin SQL Injection via db_data.php table_name Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 380026 , 380122 , 390572 |
| CVE-2026-73850 | Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-7412 | Eclipse BaSyx SSRF Vulnerability | 344360 , 347009 , 390709 |
| CVE-2026-75833 | Grav API Plugin Open Redirect via Backslash Bypass | 344365 |
| CVE-2026-16033 | Arbitrary file read+write on host via templates/ symlink in malicious image | 344360 , 390709 |
| CVE-2026-21618 | Cross-site scripting (XSS) in OAuth Device Authorization screen | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-34931 | hoppscotch: Improper loopback redirect_uri validation in device-login flow | 344365 |
| CVE-2026-34932 | hoppscotch: Stored XSS via mock server responses on backend origin | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-44238 | FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-44706 | Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-44881 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-46372 | SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-51583 | usememos through v0.30.0 Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-57894 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfil | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-63361 | LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-65707 | Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-65986 | CVAT has stored XSS via annotation guide assets | 333140 , 333141 , 340095 , 341256 , 342259 , 350147 , 350148 |
| CVE-2026-67424 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-67428 | Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-69250 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstrea | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-49489 | OpenCATS - SQL Injection in DataGrid sortDirection Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5385 | GLPI 11.0.0 - Stored XSS in knowledge base | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-57862 | Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-62234 | Grav < 2.0.4 SSRF via Unrestricted cURL Protocols | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-64657 | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-72855 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-73629 | Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-75855 | ArcadeDB before 26.8.1 Path Traversal via create/drop database | 340007 , 344360 , 390709 |
| CVE-2026-75898 | RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2025-59711 | biztalk360 Path Traversal Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-34576 | Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34966 | Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-63313 | 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65056 | mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-69086 | SiYuan before v3.7.3 Path Traversal via unvalidated avID | 340007 , 344360 , 390709 |
| CVE-2026-75842 | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV | 340007 , 340029 , 344360 , 344370 , 390109 , 390709 |
| CVE-2025-69755 | Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-14920 | AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 380026 , 380122 , 390572 |
| CVE-2026-16268 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34725 | dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-40075 | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-43910 | Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-45711 | Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs | 340007 , 344360 , 390709 |
| CVE-2026-48126 | Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54691 | datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-56670 | ComfyUI: Stored XSS via SVG file upload on the /view endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73658 | Trigger.dev: Cross-tenant object store read and write via URL path traversal | 347009 |
| CVE-2026-74907 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-15258 | Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-33236 | NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-33437 | Stirling PDF: Stored XSS in Info Summary | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-34365 | InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34366 | InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-34522 | SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directory | 340007 , 344360 , 390709 |
| CVE-2026-39341 | SQL injection in ChurchCRM.0 | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-39344 | Reflected XSS the login page through the 'username' parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-45344 | LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-46484 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-47398 | PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20 | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-48060 | Litestar: HTML Injection Through CSRF Token | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48081 | OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-48695 | fastnetmon Command Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-50143 | Actor MCP path authority injection leaks Apify token | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-50758 | DayuanJiang next-ai-draw-io 0.4.13 Arbitrary Code Execution Vulnerability | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71320 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73659 | Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-65600 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-67179 | Genkit improper host header validation | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-67309 | Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-27621 | UpTrain has a Constant Default API Key | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-34163 | Server-Side Request Forgery via MCP Tools Endpoint in FastGPT | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-34936 | PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-39361 | OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_url | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-39965 | TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-40519 | Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins() | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-42345 | FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, a | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-44285 | FastGPT: SSRF Protection Bypass via externalFile in Dataset Preview API | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45806 | Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-47179 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-58314 | Two SSRF findings in Gitea 1.26.2 | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-61835 | Directus: SSRF Protection Bypass via 0.0.0.0 in File Import | 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63764 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 |
| CVE-2026-67346 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-71303 | Lemur: Incomplete fix for CVE-2026-55166 – ACME authority update endpoint allows non-admin to replace acme_url with i | 337109 , 337110 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-71365 | Awx: webhook status callback ssrf leaks the git pat | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-73498 | MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_at | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-8183 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-16969 | DFIR-IRIS Stored XSS in Assets | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-18360 | DFIR-IRIS Stored XSS in Custom Attributes | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-18361 | DFIR-IRIS Stored XSS in Datastore Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-39369 | WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs | 340007 , 344360 , 390709 |
| CVE-2026-44239 | FreePBX: Authenticated Local File Inclusion in Dashboard Module | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-45082 | Karakeep has a SSRF Protection Bypass via Redirect Handling | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-63094 | SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft | 344365 |
| CVE-2026-65695 | Office-Word-MCP-Server 1.1.11 Path Traversal via document tools | 344360 , 390709 |
| CVE-2025-45145 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-10716 | Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-12592 | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header | 333141 , 334168 , 340003 , 340099 , 340158 , 341099 , 342259 |
| CVE-2026-12987 | Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-16573 | Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload | 346755 |
| CVE-2026-32820 | dataCycle Public Markdown Path Traversal Via /docs/*path | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-36783 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-36796 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-39359 | Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name | 340007 , 344360 , 390709 |
| CVE-2026-39844 | NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization | 344360 , 390709 |
| CVE-2026-39847 | Emmett has a path traversal in internal assets handler | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-44657 | MantisBT: Stored XSS in File Download | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-50776 | Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-51077 | Dede CMS v.5.7.118 SQL Injection Vulnerability | 340145 , 380122 |
| CVE-2026-51078 | Dede CMS v.5.7.118 Information Disclosure Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-52476 | aiflowy <= 2.1.2 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655 |
| CVE-2026-54293 | NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read | 347009 |
| CVE-2026-5487 | DriveLock Directory Traversal Information Disclosure Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-5491 | DriveLock Directory Traversal Information Disclosure Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-56671 | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read | 344360 , 347009 , 390709 |
| CVE-2026-59765 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-71209 | audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Trave | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-49857 | auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback | 337109 , 337110 , 344360 , 398004 , 398021 , 398022 |
| CVE-2026-70666 | Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-7460 | mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755 , 350147 , 350148 |
| CVE-2025-67405 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-67406 | Advocate office management system Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-67407 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-67408 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69944 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69945 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-69949 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-10870 | Shibby Tomato Web UI rc start_dhcpc os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10871 | Shibby Tomato Web UI rc start_6rd_tunnel os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10873 | Shibby Tomato Web UI rstats rstats_path os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-18900 | H3C NX15 Backend RPC esps file.exec os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-8203 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-31339 | simple inventory system SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-13157 | Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload | 351000 |
| CVE-2026-13158 | Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload | 351000 , 382238 , 390501 |
| CVE-2026-13392 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) | 340014 , 340029 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-15244 | HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search | 340748 , 344360 , 347006 , 390709 |
| CVE-2026-20297 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-27834 | Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-27885 | Piwigo: SQL Injection in Activity.getList | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-33715 | Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-34607 | Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE | 344360 , 347009 |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-39343 | ChurchCRM has a SQL Injection in Event Type Editor (Admin) | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-39387 | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-4267 | Query Monitor <= 3.20.3 - Reflected Cross-Site Scripting via Request URI | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 |
| CVE-2026-6229 | Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-71284 | Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-7537 | MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Par | 351000 |
| CVE-2018-25346 | WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2018-25352 | WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2018-25392 | MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25393 | Navigate CMS 2.8.5 Path Traversal via navigate_download.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2018-25410 | SIM-PKH 2.4.1 SQL Injection via media.php id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25421 | Open STA Manager 2.3 Arbitrary File Download via Path Traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2018-25429 | Paroiciel 11.20 SQL Injection via zProIdPro Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25430 | Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2018-25431 | No-Cms 1.0 SQL Injection via order_by Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25664 | SuiteCRM 7.10.7 SQL Injection via record Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-12970 | LearnPress < 4.4.1 - Reflected XSS via c_search | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-13725 | Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax | 346755 |
| CVE-2026-14234 | WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-14239 | Tourmaster < 5.4.8 - Stored XSS via CSRF | 333141 , 340087 , 340095 , 340099 , 340148 , 341099 , 341266 , 346755 |
| CVE-2026-14870 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id | 340087 , 340099 , 341099 , 341266 |
| CVE-2026-16007 | Authenticated SQL Injection in AppFlowy | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-18737 | Shlink Blind SQL Injection via tags/stats orderBy Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-22664 | prompts.chat SSRF via Fal.ai Media Status Polling | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-33714 | Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2) | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34598 | YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter" | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-39370 | WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltr | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-42339 | New API: SSRF Filter Bypass via 0.0.0.0 | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45725 | compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal | 347009 |
| CVE-2026-46555 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-48231 | Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48232 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48233 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48234 | Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48236 | Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48237 | Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48238 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48239 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48240 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63080 | Aptabase SQL Injection via ClickHouse query backend | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-64826 | rConfig < 8.2.13 Path Traversal File Read via FileDownloadController | 344360 , 347009 , 390709 |
| CVE-2026-6858 | Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71964 | CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72607 | Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-72609 | Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-74247 | Quay: ssrf via build archive_url in quay build api | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-75830 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy | 340007 , 344360 |
| CVE-2026-75844 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-9833 | Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-10107 | MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-40506 | OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-55746 | Cotonti stored XSS via PFS folder title | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-58411 | ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-69704 | Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-73033 | Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-74038 | Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment | 340007 , 344360 |
| CVE-2022-50954 | WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion | 340007 , 344360 , 347009 , 390709 |
| CVE-2022-50956 | WordPress Plugin amministrazione-aperta 3.7.3 Local File Read | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-11450 | GL.iNet GL-MT3000 Path Normalization dlopen command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-39383 | Gotenberg unauthenticated blind SSRF via unfiltered webhook URL | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-39838 | ProofreadPage improperly sanitizes multiline styles using Sanitizer::checkCSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-39936 | Stored XSS in Score due to usage of non-reserved data attributes | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-40598 | MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-41917 | OpenKM 6.3.12 Local File Inclusion via Admin Scripting | 344360 , 347009 |
| CVE-2026-44651 | SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-44652 | SillyTavern: SSRF vulnerability in the CORS proxy middleware | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-45731 | WWBN AVideo: Authenticated Arbitrary File Read in view/update.php | 340007 , 344360 , 390709 |
| CVE-2026-45774 | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-46337 | WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54885 | Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-5739 | PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-59238 | Stored XSS in Pentestify via unsanitized finding images and report client logo | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-69092 | Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73058 | stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2025-59709 | biztalk360 Path Traversal Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-13605 | Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-14817 | Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-14827 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-14833 | Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-14872 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter | 340017 , 340144 , 340156 , 340157 , 380122 |
| CVE-2026-15047 | s2Member < 260805 - Contributor+ Stored XSS via Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-15153 | WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16069 | Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-16559 | YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-33741 | EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35593 | Trilium Notes has Local File Inclusion via upload modified file API endpoint | 340007 , 344360 , 390709 |
| CVE-2026-39311 | Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) via Unsanitized SVG Attachments | 333140 , 333141 , 340095 , 340099 , 341099 , 342259 , 344363 |
| CVE-2026-67352 | luci-app-https-dns-proxy Stored XSS via resolver_url | 333140 , 333141 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71475 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-34216 | CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-45870 | LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-11442 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | 330791 , 340152 , 340748 , 344360 , 347006 , 390709 , 390716 |
| CVE-2026-14554 | Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters | 340017 , 340144 , 340156 , 340157 , 380122 |
| CVE-2026-15974 | sglang Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-16065 | Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import | 340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122 |
| CVE-2026-16548 | Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint | 351000 |
| CVE-2026-26379 | koha Server-Side Request Forgery Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34740 | AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34787 | Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter | 344360 , 347009 |
| CVE-2026-34788 | Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-35718 | fd8136 firmware Path Traversal Vulnerability | 344360 , 347009 |
| CVE-2026-36227 | Easy Chat Server 3.1 Arbitrary Code Execution Vulnerability | 340007 , 344360 , 390709 |
| CVE-2026-39229 | Bolt CMS through 3.7.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-39368 | WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 | 340007 , 344360 , 390709 |
| CVE-2026-46556 | FlaskBB: SSRF in get_image_info() via unrestricted avatar URL | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-48093 | Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed | 333140 |
| CVE-2026-52371 | xxl-job v3.4.0 Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-52607 | reportico-web <= 8.1.0 Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-58442 | Repository migration SSRF via multi-answer DNS allow-list bypass | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-63667 | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal | 340007 , 344360 , 390709 |
| CVE-2026-72608 | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-72739 | Dokploy: Command Injection via Compose Shell Execution | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73573 | zimbra collaboration suite Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-73574 | zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-7646 | Langflow is affected by security vulnerabilities in Model Context Protocol features | 344360 , 347009 , 390709 |
| CVE-2026-7658 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | 340007 , 344360 , 390709 |
| CVE-2025-15064 | Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets | 346755 |
| CVE-2026-0737 | Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-0738 | Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 346755 |
| CVE-2026-36214 | osTicket Cross-Site Scripting Vulnerability | 333140 , 342259 |
| CVE-2026-3885 | WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_bo | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45573 | Decidim: Push subscriptions can be abused for server-side requests | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45797 | HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-50592 | Znuny Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-34371 | LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversal | 340007 , 344360 , 390709 |
| CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps .map Handling | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-42335 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-42344 | FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-42538 | IRIS has an Insecure File Upload | 351000 |
| CVE-2026-44284 | FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassable | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-49120 | Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-56722 | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI | 344360 , 390709 |
| CVE-2026-63107 | LimeSurvey SSRF via REST API Survey Template Host Header | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63643 | MagicMirror: ssrf calendar .js | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-63731 | HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-63769 | Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-65012 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-65593 | n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-67620 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-70667 | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fi | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-73530 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2018-6882 | zimbra collaboration suite Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-65341 | Ecommerce Fruits Bazar 1.0 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-11588 | EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11881 | Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-12982 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-13330 | Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-14190 | Sina Extension for Elementor < 3.10.2 - Reflected XSS | 346755 |
| CVE-2026-14207 | LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-14841 | King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget | 346755 |
| CVE-2026-14845 | NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-14921 | Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 346755 |
| CVE-2026-17532 | Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-26028 | CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-26483 | Mettle SendPortal 3.0.1 and earlier Cross-Site Scripting Vulnerability | 333140 |
| CVE-2026-30251 | zenshare suite Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-30252 | zencrm Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 , 360030 |
| CVE-2026-33213 | Redash: Open redirect vulnerability in post-login redirect handling | 344365 |
| CVE-2026-34206 | Captcha Protect: Reflected XSS in challenge page via unsanitized destination rendered with text/template | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-34229 | Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34396 | AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34442 | FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout | 340165 , 344365 |
| CVE-2026-34739 | AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34847 | hoppscotch: Open redirect via /enter?redirect= | 344365 |
| CVE-2026-35404 | Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter | 344365 |
| CVE-2026-36324 | SourceCodester Doctor Appointment System 1.0 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-36725 | FastapiAdmin v2.2.0 Cross-Site Scripting Vulnerability | 333140 |
| CVE-2026-37750 | School Management System by mahmoudai1 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-38432 | erpnext Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-38444 | osTicket v1.18.3 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 |
| CVE-2026-38446 | Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-38947 | FluentCMS 1.2.3 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-40295 | Devise: Open Redirect via Unvalidated request.referrer in Timeoutable Session Timeout Handler | 344365 |
| CVE-2026-41580 | Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author) | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-42253 | Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 |
| CVE-2026-51565 | Modules/Docs/DocsController.php in Milk admin <=0.9.8 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-52232 | FS Inc S3150-8T2F Switch 2.2.0D Build 118101 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-52475 | aiflowy <= 2.1.2 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-5776 | Email Encoder < 2.4.7 - Unauthenticated Stored XSS | 333140 , 333141 , 340147 , 340148 |
| CVE-2026-61526 | AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-70620 | Odysseus SSRF via Embedding Endpoint Configuration | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-73084 | Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2023-6717 | Keycloak: xss via assertion consumer service url in saml post-binding flow | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-18403 | LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-41363 | OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-65698 | Void 1.3.4 Path Traversal via AI Agent File-Reading Tools | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-66004 | BlenderMCP Path Traversal via download_polyhaven_asset API | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-8245 | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-13693 | Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal | 340748 , 344360 , 347006 , 390709 |
| CVE-2026-10526 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-16949 | Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-34360 | HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-45709 | Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filte | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63428 | HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's dec | 333140 , 333141 , 340095 , 342259 , 350147 , 350148 |
| CVE-2026-73243 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-40605 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-6428 | Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10178 | code-projects Online Music Site AdminEditAlbum.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10186 | code-projects Online Hospital Management System patient.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10214 | zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-10249 | itsourcecode Online Blood Bank Management System viewrequest.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10250 | itsourcecode Online Blood Bank Management System campsdetails.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10251 | itsourcecode Online House Rental System ajax.php login sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 |
| CVE-2026-10252 | itsourcecode Online House Rental System manage_tenant.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10253 | itsourcecode Online House Rental System manage_payment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10260 | CodeAstro Online Job Portal delete-jobs.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10261 | CodeAstro Online Job Portal application_status.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10262 | code-projects Real State Services Login loginuser.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10263 | SourceCodester Computer Repair Shop Management System manage_product.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10280 | horizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10287 | SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10620 | code-projects Student Admission System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10694 | SourceCodester Online Food Ordering System index.php include file inclusion | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-10704 | SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-11435 | Jinher OA nextselectplan.aspx sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11456 | Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11474 | Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload | 351000 , 393655 |
| CVE-2026-11482 | SourceCodester Class and Exam Timetabling System archive5.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11483 | SourceCodester Class and Exam Timetabling System archive4.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11484 | SourceCodester Class and Exam Timetabling System archive3.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11485 | SourceCodester Class and Exam Timetabling System archive2.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11486 | SourceCodester Class and Exam Timetabling System archive1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11488 | code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11489 | code-projects Online Music Site AdminDeleteAlbum.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11490 | code-projects Online Music Site Search.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11501 | SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11582 | CodeAstro Student Attendance Management System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16125 | zevorn rt-claw http_request net.c claw_net_post server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16127 | zevorn rt-claw http_request tool_net.c claw_net_post server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16128 | zevorn rt-claw http_request swarm.c receiver_thread server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-16152 | SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16154 | SourceCodester Class and Exam Timetabling System edit_room1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16227 | SourceCodester Class and Exam Timetabling System edit_subject.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16228 | SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16252 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-16484 | SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16765 | CodeAstro Online Classroom loginlinkadmin.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16910 | Quay: ssrf in red hat quay notification webhooks (slack/generic) | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-18641 | Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginC | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-18646 | danpros HTMLy Author Name htmly.php path traversal | 340007 , 344360 , 347009 |
| CVE-2026-18788 | Trippo ResponsiveFilemanager dialog.php unrestricted upload | 351000 |
| CVE-2026-18973 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19000 | JeecgBoot Anonymous Chat Attachment send server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19021 | SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19196 | SourceCodester Photo Share Website ajax.php login sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 |
| CVE-2026-19211 | SourceCodester Photo Share Website ajax.php signup sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 |
| CVE-2026-19343 | code-projects Task Management System AdminLogin.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19344 | code-projects Task Management System comment_count_user.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19374 | adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-19384 | SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-19710 | SourceCodester Simple Student Information System view_department.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19753 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19758 | dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal | 340007 , 344360 , 390709 |
| CVE-2026-19762 | DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal | 340007 , 344360 , 390709 |
| CVE-2026-19827 | alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-19899 | SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19919 | code-projects Online Shopping System Login login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19926 | Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-45376 | Decidim: Admin user search allows SQL injection through similarity-based sorting | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5346 | huimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5368 | projectworlds Car Rental Project Parameter login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5551 | itsourcecode Free Hotel Reservation System Parameter login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5554 | code-projects Concert Ticket Reservation System Parameter process_search.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5555 | code-projects Concert Ticket Reservation System Parameter login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5564 | code-projects Simple Laundry System Parameter searchguest.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5565 | code-projects Simple Laundry System Parameter delmemberinfo.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 fs unrestricted upload | 351000 |
| CVE-2026-5575 | SourceCodester/jkev Record Management System Login index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5577 | Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5631 | assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5634 | projectworlds Car Rental Project Parameter book_car.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5672 | code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5677 | Totolink A7100RU cstecgi.cgi CsteSystem os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5678 | Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5688 | Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5689 | Totolink A7100RU cstecgi.cgi setNtpCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5690 | Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5691 | Totolink A7100RU cstecgi.cgi setFirewallType os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5692 | Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5736 | PowerJob detailPlus Endpoint InstanceController.java sql injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5741 | suvarchal docker-mcp-server HTTP index.ts pull_image os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5802 | idachev mcp-javadc HTTP os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5805 | code-projects Easy Blog Site contact_us.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5813 | PHPGurukul Online Course Registration check_availability.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5814 | PHPGurukul Online Course Registration check_availability.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5824 | code-projects Simple Laundry System userchecklogin.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5827 | code-projects Simple IT Discussion Forum question-function.php sql injection | 340147 , 340148 , 340156 , 341256 , 342259 , 346755 |
| CVE-2026-5829 | code-projects Simple IT Discussion Forum content.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 |
| CVE-2026-5832 | atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-68922 | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-7178 | ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-7194 | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-7205 | duartium papers-mcp-server main.py search_papers path traversal | 340007 , 344360 , 390709 |
| CVE-2026-7206 | dubydu sqlite-mcp entry.py extract_to_json sql injection | 340007 , 344360 , 390709 |
| CVE-2026-7212 | edvardlindelof notes-mcp notes_mcp.py path traversal | 340007 , 344360 , 390709 |
| CVE-2026-7214 | eghuzefa engineer-your-data server.py file_inf path traversal | 340007 , 344360 , 390709 |
| CVE-2026-7216 | donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal | 344360 , 390709 |
| CVE-2026-7217 | Deepractice PromptX Document File index.ts read_pdf absolute path traversal | 340007 , 344360 , 390709 |
| CVE-2026-7220 | jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-7221 | TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-7223 | BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery | 334168 , 390719 |
| CVE-2026-7314 | eiceblue spire-doc-mcp-server base.py get_doc_path path traversal | 340007 , 344360 , 390709 |
| CVE-2026-7315 | eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal | 340007 , 344360 , 390709 |
| CVE-2026-7319 | elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal | 340007 , 344360 |
| CVE-2026-75014 | SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75079 | SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75080 | SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75089 | PHPGurukul Complaint Management System check_availability.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-75778 | code-projects Task Management System Login Form index.php select_with_multiple_condition sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-75986 | code-projects Online Job Portal System Password Recovery ForPass.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76048 | SourceCodester Simple Online Food Ordering System ajax.php login sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122 |
| CVE-2026-76049 | SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-9355 | SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9356 | SourceCodester Hospitals Patient Records Management System manage_history.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9364 | projectworlds Online Art Gallery Shop adminHome.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9372 | ItzCrazyKns Vane Model Provider API route.ts server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-9383 | itsourcecode Electronic Judging System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9469 | yashpokharna2555 StudentManagementSystem success.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9470 | yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9474 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-9525 | itsourcecode Electronic Judging System edit_judge.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9526 | itsourcecode Electronic Judging System edit_team.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9528 | itsourcecode Electronic Judging System delete_judge.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9573 | itsourcecode Student Transcript Processing System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9574 | itsourcecode Student Transcript Processing System trans.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9575 | itsourcecode Student Transcript Processing System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9584 | code-projects Project Management System Login chk.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9606 | itsourcecode Courier Management System manage_user.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11569 | Quay: quay: stored xss via filedrop svg upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-14864 | JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode | 333140 , 340095 , 340147 , 342259 , 346755 |
| CVE-2026-15234 | Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-15245 | BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-15262 | Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column | 333141 , 340087 , 340095 , 340099 , 341099 , 341266 |
| CVE-2026-16063 | Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16537 | Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16558 | YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-17010 | Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta | 346755 |
| CVE-2026-18266 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability | 344365 |
| CVE-2026-18395 | Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-26378 | koha Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-30520 | loan management system SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-34212 | Docmost page content has stored XSS via unsanitized attachment URLs | 333140 |
| CVE-2026-34590 | Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34848 | hoppscotch: Stored XSS in team member overflow tooltip via display name | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34974 | phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35403 | LORIS has potential cross-site scripting in survey_accounts module | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35455 | immich has Stored XSS via OCR Text in 360° Panorama Viewer | 333140 , 333141 , 340147 , 341256 , 346755 |
| CVE-2026-36722 | bookcars v8.3 Arbitrary Code Execution Vulnerability | 351000 |
| CVE-2026-39380 | Open Source Point of Sale has Stored XSS in Stock Location (Configuration) | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-39960 | MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values | 333140 , 341256 |
| CVE-2026-39964 | TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45138 | CI4MS: Stored XSS in Blog Content via Broken html_purify Validation Rule | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-45580 | WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48483 | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-48762 | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-54543 | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72570 | cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72583 | fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-7798 | FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter | 337109 , 337110 , 340162 , 340163 , 340165 , 340464 , 340465 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-7869 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | 340007 , 344360 , 390709 |
| CVE-2026-9278 | Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2019-25731 | Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-14860 | Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-15932 | Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-16336 | trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect | 340165 , 344365 |
| CVE-2026-16531 | Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet | 340007 , 344360 , 390709 |
| CVE-2026-16536 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-22662 | prompts.chat Blind SSRF via media-generate | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-25860 | OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler | 333140 , 333141 |
| CVE-2026-34523 | SillyTavern: Path traversal allows file existence oracle | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-35208 | lichess.org has an Unsanitized Stream Title Injection on /streamer | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-36726 | bookcars v8.3 Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-41472 | CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard | 333140 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-44583 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module | 337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022 |
| CVE-2026-47720 | FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48094 | ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-49138 | Nanobot < 0.2.1 SSRF via web_fetch Tool Redirect Following | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-5538 | QingdaoU OnlineJudge judge_server_heartbeat Endpoint JudgeServer.service_url server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5547 | Tenda AC10 httpd formAddMacfilterRule os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5606 | PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5808 | openstatusHQ openstatus Onboarding Endpoint client.tsx cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-59231 | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-59232 | Stored Cross-site Scripting in Prospero Flow CRM lead name field | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-63730 | HyperDX < 2.31.0 SSRF via Webhook Test Endpoint | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-63768 | cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-64626 | AVideo Encoder downloadURL SSRF via unpinned retry fallback | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-64870 | MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-69116 | FlyEnv < 4.18.0 Cross-Site Scripting via v-html | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73038 | NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73082 | Activepieces: Server-side request forgery in MCP tool validation endpoint | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-73244 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing | 340007 , 344360 , 390709 |
| CVE-2026-73422 | Astro: Reflected XSS via unescaped View Transition animation properties | 333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 390585 |
| CVE-2026-73628 | Serendipity 2.3.5 Reflected XSS via search clean-URL route | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-73845 | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer) | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-74858 | jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-9524 | xianrendzw EasyReport REST Endpoint execute sql injection | 340017 , 340145 , 341145 , 341245 , 380026 , 380122 , 390572 |
| CVE-2018-25248 | MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2018-25349 | userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2019-25739 | GigToDo Freelance Marketplace Script 1.3 Persistent XSS | 333140 , 333141 |
| CVE-2021-47931 | Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2021-47947 | Projectsend r1295 Stored Cross-Site Scripting via files-edit.php | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2021-47983 | WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code | 340095 , 346755 |
| CVE-2022-50943 | Moodle LMS 4.0 Cross-Site Scripting via course search.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50948 | Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2022-50958 | WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2022-50959 | WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2022-50960 | WordPress International Sms Contact Form 7 Integration 1.2 XSS | 340087 , 340099 , 341099 , 341266 |
| CVE-2022-50962 | uBidAuction 2.0.1 myOrders Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50963 | uBidAuction 2.0.1 myAuctions active Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50964 | uBidAuction 2.0.1 myAuctions loose Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50965 | uBidAuction 2.0.1 posts manage Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50966 | uBidAuction 2.0.1 news manage Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50968 | uBidAuction 2.0.1 auctions manage Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50969 | uBidAuction 2.0.1 mailingLog manage Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2022-50970 | WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2025-71404 | better-auth before 1.1.16 Reflected XSS via error parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-17597 | Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Verification | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19434 | Stored Cross-site Scripting in Pentestify finding severity field | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19716 | Stored Cross-site Scripting in Pentestify user account deletion via unescaped username | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19761 | DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-19763 | DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-22675 | OCS Inventory NG Server Stored XSS via User-Agent | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-25557 | Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-32113 | Discourse: Open redirect via sso_destination_url cookie in enter | 344365 |
| CVE-2026-32856 | Ellucian Banner Self-Service Reflected XSS via dateConverter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-34161 | Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution | 333140 |
| CVE-2026-34416 | OSCAL-GUI Reflected XSS via project parameter in oscal.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34417 | OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34798 | Endian Firewall /cgi-bin/routing.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34799 | Endian Firewall /manage/dnsmasq/hosts/ remark Stored Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34800 | Endian Firewall /cgi-bin/uplinkeditor.cgi NAME Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-34801 | Endian Firewall /manage/dhcp/fixed_leases/ remark Stored Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34802 | Endian Firewall /cgi-bin/salearn.cgi remark user ham spam Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34803 | Endian Firewall /manage/qos/classes/ name Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-34804 | Endian Firewall /manage/qos/rules/ dscp Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34805 | Endian Firewall /cgi-bin/dnat.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34806 | Endian Firewall /cgi-bin/snat.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34807 | Endian Firewall /cgi-bin/incoming.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34808 | Endian Firewall /cgi-bin/outgoingfw.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34809 | Endian Firewall /cgi-bin/zonefw.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34810 | Endian Firewall /cgi-bin/vpnfw.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34811 | Endian Firewall /cgi-bin/xtaccess.cgi remark Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34812 | Endian Firewall /cgi-bin/proxypolicy.cgi mimetypes Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34813 | Endian Firewall /cgi-bin/proxyuser.cgi user Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34814 | Endian Firewall /cgi-bin/proxygroup.cgi group Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34815 | Endian Firewall /cgi-bin/smtpdomains.cgi DOMAIN Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34816 | Endian Firewall /manage/smtpscan/domainrouting/ domain Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34817 | Endian Firewall /cgi-bin/smtprouting.cgi ADDRESS BCC Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34818 | Endian Firewall /manage/dnsmasq/localdomains/ remark Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34819 | Endian Firewall /cgi-bin/openvpnclient.cgi REMARK Stored Cross-Site Scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34820 | Endian Firewall /manage/ipsec/ remark Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34821 | Endian Firewall /manage/vpnauthentication/user/ remark Stored Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34822 | Endian Firewall /manage/ca/certificate/ new_cert_name Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-34823 | Endian Firewall /manage/password/web/ remark Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35007 | Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35008 | Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35009 | Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35010 | Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35011 | Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35012 | Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35014 | Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35015 | Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35016 | Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35396 | WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage'] | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35398 | WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage'] | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35472 | WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage'] | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35473 | WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage'] | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-35474 | WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect'] | 344365 |
| CVE-2026-35475 | WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect'] | 340165 , 344365 |
| CVE-2026-4093 | Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels) | 333140 , 333141 , 340095 |
| CVE-2026-42336 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-42350 | Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter | 344365 |
| CVE-2026-42840 | ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45551 | Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User Setting Write | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-47106 | Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes API | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48214 | Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48215 | Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48218 | Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name and frm_id Parameters | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48219 | Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48220 | Open ISES Tickets < 3.44.2 Reflected XSS via ics205.php frm_add_str Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48221 | Open ISES Tickets < 3.44.2 Reflected XSS via ics205a.php frm_add_str Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48222 | Open ISES Tickets < 3.44.2 Reflected XSS via ics213.php frm_add_str Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48223 | Open ISES Tickets < 3.44.2 Reflected XSS via ics213rr.php frm_add_str Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48224 | Open ISES Tickets < 3.44.2 Reflected XSS via ics214.php frm_add_str Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48225 | Open ISES Tickets < 3.44.2 Reflected XSS via landb.php _type Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48226 | Open ISES Tickets < 3.44.2 Reflected XSS via os_watch.php ref and mode_orig Parameters | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48227 | Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Parameters | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48228 | Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id Parameters | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48229 | Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48530 | GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48531 | GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48532 | GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48534 | GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48535 | GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48536 | GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48537 | GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48538 | GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-48539 | GFI Archiver < 15.13 Stored XSS via MailInsights.aspx | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-48552 | Nagios Core / XI DOM-based XSS via jsonquery.js | 333140 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48559 | Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-49131 | OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field | 333140 , 333141 |
| CVE-2026-49132 | OPNsense < 26.1.9 Stored XSS via Certificate Description Field | 333140 , 333141 |
| CVE-2026-53992 | Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-57857 | Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message Parameter | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755 |
| CVE-2026-63302 | Local File Inclusion in Quick.CMS | 344360 , 347009 |
| CVE-2026-64628 | Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-65697 | Fathom Lite 1.3.1 Stored XSS via /collect Endpoint | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-66296 | Reflected XSS in oaskit's default HTML error handler | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-66414 | Leantime Open Redirect in Login Controller via redirectUrl Parameter | 344365 |
| CVE-2026-67333 | better-auth before 1.6.13 Stored XSS via javascript redirect_uri | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72743 | SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-72832 | Grav before 2.0.12 Stored XSS via quoted-attribute bypass | 333140 , 333141 |
| CVE-2026-73671 | Saurus CMS Unauthenticated Open Redirect via logout url parameter | 344365 |
| CVE-2026-74908 | Grav plugin-api before 1.0.15 Script Injection via SVG | 351000 |
| CVE-2026-75831 | Grav before 2.0.15 Stored XSS via audio/video source URL | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16955 | AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription | 340007 , 344360 , 390709 |
| CVE-2025-15673 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read | 340007 , 344360 , 390709 |
| CVE-2026-41412 | alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script | 344360 |
| CVE-2026-51564 | the redirect parameter in Milk admin <=0.9.8 Open Redirect Vulnerability | 344365 |
| CVE-2026-53594 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-71283 | Fledge IoT Gateway Backup Restore Tar Path Traversal | 344360 , 390709 |
| CVE-2024-3822 | Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-15669 | Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-14203 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title | 340087 , 340099 , 341099 , 341266 |
| CVE-2026-15233 | Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title | 340087 , 340099 , 341099 , 341266 |
| CVE-2026-34246 | CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 |
| CVE-2026-39390 | CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-39392 | CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-43924 | FOSSBilling has an open redirect via administrator-configured redirect targets | 344365 |
| CVE-2026-46516 | Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments) | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-67612 | OpenEMR 8.2.0 Stored XSS via import_template.php Template Management | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-67617 | Microweber CMS 2.0.20 Stored XSS via tag_names Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-70560 | Ultimate POS Stored XSS via First Name Field in Leave Notifications | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9577 | Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | 344365 |
| CVE-2026-3093 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-42329 | Iris has an Open Redirect issue | 344365 |
| CVE-2026-16273 | Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta | 333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 346755 , 350147 , 350148 |
| CVE-2026-12724 | Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-26477 | dokuwiki Denial of Service Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-32250 | NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index.php?route=/queries/user/ | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-35411 | Directus is an Open Redirect in Admin 2FA Setup Page | 344365 |
| CVE-2026-36239 | PbootCMS v.3.2.11 Cross-site Scripting Vulnerability | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-43936 | e107: Server-Side Request Forgery (SSRF) in the remote file fetcher | 337109 , 337110 , 341737 , 341738 , 344360 , 398021 , 398022 |
| CVE-2026-48012 | Shopware SSO referer trust leading to an arbitrary redirect target | 344365 |
| CVE-2026-49856 | @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-55495 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | 340007 , 344360 , 347009 , 390709 , 390719 |
| CVE-2026-72610 | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-73657 | Trigger.dev: Cross-tenant payload poisoning via packet write + replay | 347009 |
| CVE-2026-10052 | Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config validation endpoints | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-14238 | Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-48013 | Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-14189 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | 340017 , 340144 , 340156 , 340157 , 380122 |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-15381 | WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-15677 | GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories | 346755 |
| CVE-2026-10827 | Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755 , 350147 , 350148 |
| CVE-2026-13393 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite) | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-48051 | Papra: SSRF via HTTP redirect bypass in webhook delivery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-9060 | Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style | 346755 |
| CVE-2026-9061 | Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-9062 | Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal | 340748 , 344360 , 347006 , 390709 |
| CVE-2026-23603 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-55825 | Contao: Possible path traversal in job download URIs | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-49262 | Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-68927 | MobSF: SSRF port restriction bypass in assetlinks_check | 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-42578 | Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation | 390719 |
| CVE-2026-44286 | FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-55554 | Dompdf: Chroot Validation Bypass | 344360 , 390709 |
| CVE-2026-73087 | Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2024-14046 | OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload | 351000 |
| CVE-2025-15098 | YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10153 | westboy CicadasCMS AbstractCacheManager.java search cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10170 | code-projects Visitor Management System phone_0.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10172 | Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10173 | Orthanc Explorer 2 URL StudyList.vue cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10193 | OFCMS ComnController ComnController.java query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10202 | OFCMS JSON Query SystemDictController.java query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10203 | OFCMS JSON Query SystemParamController.java query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10204 | OFCMS JSON Query SysUserController.java query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10209 | code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10213 | AstrBotDevs AstrBot API Endpoint delete path traversal | 340007 , 344360 |
| CVE-2026-10239 | JeecgBoot edit WordUtil.addImage server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-10240 | JeecgBoot test server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10241 | jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10256 | itsourcecode Content Management System save_comment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10258 | itsourcecode Content Management System add_sub_topic.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10265 | itsourcecode Content Management System edit_topic.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10274 | indrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10276 | hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10278 | ishayoyo excel-mcp read_file/write_file index.ts path traversal | 340007 , 344360 , 390709 |
| CVE-2026-10279 | hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10286 | CodeAstro Payroll System home_employee.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10289 | code-projects Hotel and Tourism Reservation System tour.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10296 | itsourcecode Fees Management System ajax.php sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 |
| CVE-2026-10297 | itsourcecode Fees Management System manage_course.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10301 | itsourcecode Fees Management System index.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-10302 | itsourcecode Fees Management System manage_fee.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10558 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | 344360 , 347009 |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-10568 | itsourcecode Fees Management System manage_payment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10662 | ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10690 | wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-10806 | mjperpinosa stumasy add_post.php unrestricted upload | 351000 |
| CVE-2026-10807 | mjperpinosa stumasy change_profile_image.php unrestricted upload | 351000 |
| CVE-2026-10808 | itsourcecode Fees Management System manage_student.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10809 | itsourcecode Fees Management System manage_user.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10810 | itsourcecode Fees Management System navbar.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-10811 | itsourcecode Fees Management System receipt.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10874 | projectworlds Online Art Gallery Shop Project adminHome.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10875 | projectworlds Online Art Gallery Shop Project adminHome.ph sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-11412 | Jinher OA GetFormSn.aspx sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11436 | Mage AI Sign-in Flow index.tsx useMutation cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11467 | jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal | 340007 , 344360 , 390709 |
| CVE-2026-11475 | Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11476 | Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11477 | hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-11495 | CodeAstro Ingredients Stock Management System add_stock.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11506 | CodeAstro Leave Management System search_staff_for_deletion.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11507 | CodeAstro Leave Management System delete_leave_type.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11508 | CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11510 | CodeAstro Leave Management System add_leave.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11512 | itsourcecode Hospital Management System billing.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11513 | itsourcecode Hospital Management System adminaccount.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11514 | itsourcecode Hospital Management System addpatient.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11518 | SourceCodester Inventory System User Management users.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 , 380106 |
| CVE-2026-11529 | designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection | 340016 , 380122 |
| CVE-2026-11558 | CodeAstro Payroll System home_salary.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11559 | CodeAstro Payroll System view_account.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11583 | CodeAstro Student Attendance Management System createClass.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11584 | CodeAstro Student Attendance Management System createClass.php edit sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-11585 | CodeAstro Student Attendance Management System createClassArms.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-12210 | universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-16074 | AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16124 | nextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery | 334168 , 390719 |
| CVE-2026-16131 | itsourcecode Hospital Management System prescriptionrecord.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16194 | zhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-16219 | Croogo CMS Admin File Manager FileManager.php isEditable path traversal | 344360 , 347009 |
| CVE-2026-16220 | code-projects Online Examination System account.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16222 | 1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-16223 | 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-16229 | itsourcecode Courier Management System index.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-16244 | itsourcecode Hospital Management System prescriptionorderreport.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16334 | itsourcecode Hospital Management System prescriptionorder.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16449 | zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16451 | zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload | 351000 |
| CVE-2026-16485 | SourceCodester Class and Exam Timetabling System class.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16486 | SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-17458 | mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-18644 | danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal | 344360 |
| CVE-2026-18645 | danpros HTMLy Admin Content Endpoint admin.php add_content path traversal | 344360 |
| CVE-2026-18766 | chetans9 core-php-admin-panel customers.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-18774 | NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-18896 | lavkush-maurya Student-Registration-System changepass.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-18959 | yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal | 340007 , 344360 , 390709 |
| CVE-2026-18968 | ttttonyhe OBlog tags.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-19020 | itsourcecode Hospital Management System servicetype.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19040 | MissionSquad mcp-api dcrClients.ts server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19067 | itsourcecode Hospital Management System treatment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19068 | itsourcecode Hospital Management System treatmentdetail.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19069 | itsourcecode Hospital Management System treatmentrecord.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19070 | itsourcecode Hospital Management System viewadmin.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19071 | itsourcecode Hospital Management System viewappointment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19210 | SourceCodester Photo Share Website ajax.php save_upload unrestricted upload | 351000 |
| CVE-2026-19246 | HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19340 | anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19347 | itsourcecode Hospital Management System viewdoctor.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19364 | itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19375 | dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19378 | code-projects Task Management System CommentSave.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19752 | EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-19756 | Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal | 340007 , 344360 , 390709 |
| CVE-2026-19767 | itsourcecode Hospital Management System viewdoctortimings.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19828 | 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-19829 | 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal | 344360 , 347009 , 390709 |
| CVE-2026-19894 | itsourcecode Hospital Management System viewmedicine.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19917 | code-projects Online Food Order System delete_food_items1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19920 | code-projects Online Shopping System action.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19921 | code-projects Online Shopping System homeaction.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19923 | code-projects Online Shopping System checkout_process.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19927 | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19932 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19934 | itsourcecode Hospital Management System vieworder.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19958 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19972 | itsourcecode Hospital Management System viewpatient.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19973 | itsourcecode Hospital Management System viewpaymentreport.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19984 | jkawamoto mcp-florence2 init.py get_images server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19998 | code-projects Online Shopping System offersmail.php cross site scripting | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-20000 | itsourcecode Hospital Management System viewprescriptionrecord.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5206 | code-projects Simple Gym Management System Payment sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5470 | mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request for | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5537 | halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5543 | PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5552 | PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5553 | itsourcecode Online Cellphone System Parameter available.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5558 | PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5560 | PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5578 | CodeAstro Online Classroom Parameter addassessment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5579 | CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5580 | CodeAstro Online Classroom Parameter addvideos.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5583 | PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5607 | imprvhub mcp-browser-agent URL Parameter handlers.ts CallToolRequestSchema server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5620 | itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5635 | PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5636 | PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5675 | itsourcecode Construction Management System Parameter borrowed_tool.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5681 | itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5719 | itsourcecode Construction Management System borrowedtool.php sql injection | 340145 , 340156 , 341145 , 380122 , 390572 |
| CVE-2026-5803 | bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery | 337109 , 340162 , 347009 , 390722 |
| CVE-2026-5823 | itsourcecode Construction Management System borrowed_tool_report.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5825 | code-projects Simple Laundry System delmemberinfo.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-5826 | code-projects Simple IT Discussion Forum edit-category.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-59727 | Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-67350 | Serendipity < 2.6.1 Open Redirect via exit.php | 344365 |
| CVE-2026-7196 | CodeAstro Online Classroom guestdetails sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-74842 | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-75077 | SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75078 | SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75086 | itsourcecode Hospital Management System viewroom.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75087 | itsourcecode Hospital Management System viewdepartment.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75088 | itsourcecode Hospital Management System viewbilling.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75876 | xianrendzw EasyReport Move Operations ModuleController.java sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-7890 | Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8231 | CodeAstro Online Catering Ordering System deleteorder.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9302 | 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9342 | SourceCodester Hospitals Patient Records Management System view_history.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9343 | Edimax EW-7438RPn webs formWpsStart os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9347 | Edimax EW-7438RPn webs formWizSurvey os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9415 | code-projects Employee Management System eloginwel.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9416 | code-projects Employee Management System myprofile.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9417 | code-projects Employee Management System myprofileup.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9418 | code-projects Employee Management System changepassemp.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9419 | code-projects Employee Management System empproject.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9424 | Edimax EW-7438RPn Content-Type formWlanMP os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9448 | code-projects Employee Management System applyleave.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9450 | code-projects Employee Management System psubmit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9451 | code-projects Employee Management System applyleaveprocess.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9473 | c-rick jimeng-mcp api.ts generateVideo path traversal | 340007 , 344360 , 390709 |
| CVE-2026-9511 | Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9512 | Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9514 | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9515 | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9518 | hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9519 | stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9520 | blitz-js blitz Sign-in LoginForm.tsx cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-9527 | itsourcecode Electronic Judging System judges.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9531 | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9532 | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9533 | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9534 | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9542 | CodeAstro Leave Management System add_staff.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9566 | teableio teable Sign-up LoginPage.tsx cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-9607 | itsourcecode Courier Management System parcel_list.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10155 | Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10171 | code-projects Online Music Site AdminUpdateAlbum.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10228 | raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10234 | Mettle sendportal Campaign webview cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10244 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10245 | SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10246 | SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10247 | SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-10567 | 1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting | 333140 , 333141 |
| CVE-2026-10583 | nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery | 334168 , 390719 |
| CVE-2026-12211 | Intelbras iNVU 7016 FT Web syslog path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-16088 | halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-16155 | SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16156 | SourceCodester Class and Exam Timetabling System forexam.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16202 | SourceCodester Class and Exam Timetabling System CYS.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16203 | SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-18856 | Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-19209 | SourceCodester Photo Share Website index.php home cross site scripting | 333140 , 333141 , 340147 , 340148 , 342259 , 350147 , 350148 |
| CVE-2026-19383 | saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload | 351000 |
| CVE-2026-19787 | SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19839 | SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload | 351000 |
| CVE-2026-19922 | code-projects Online Shopping System checkout.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19925 | SourceCodester Stock Management System Master.php delete_supplier sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19964 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5576 | SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload | 340156 , 341245 , 351000 , 390501 |
| CVE-2026-5806 | code-projects Easy Blog Site update.php cross site scripting | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-5810 | SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-7222 | code-projects Coaching Management System Complaint Form complaint.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-8139 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9464 | YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-10112 | sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-10514 | 1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting | 333140 |
| CVE-2026-10529 | westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 344370 , 346755 , 350147 , 350148 |
| CVE-2026-11434 | FluentCMS Blocks Plugin blocks cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-11468 | SourceCodester Hospitals Patient Records Management System page room_types cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16129 | princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-16205 | Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19110 | DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19207 | PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-19369 | KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-19373 | PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5621 | ChrisChinchilla Vale-MCP HTTP index.ts os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5834 | code-projects Online Shoe Store admin_running.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-5835 | code-projects Online Shoe Store admin_football.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-5836 | code-projects Online Shoe Store admin_product.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-9564 | SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11502 | JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-19353 | DedeCMS Installation Wizard index.php _4_Setup file inclusion | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |