CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2026-82395

    Last Modified: 1 Sept 2026

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows MediaManager::move() to reassign the item without checking that source. An authenticated backend user with edit permission on one collection and knowledge of a target media identifier can name the allowed collection in the request, move an item out of a restricted collection, and then view or download content the user was not permitted to access. This issue is fixed in versions 2.6.25 and 3.0.8.

    Published: 31 Aug 2026
    5.3
    Medium

    CVE-2026-82394

    Last Modified: 2 Sept 2026

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource in PreviewLinkManager::generate() or PreviewLinkManager::revoke(). An authenticated administration user who knows a target resource identifier can create or revoke a preview link for any page, article, or snippet, including content in a webspace or area the user cannot view. A generated preview URL is public and resolves content by an opaque token, allowing the user or anyone receiving the link to read restricted content without authentication. This issue is fixed in versions 2.6.25 and 3.0.8.

    Published: 31 Aug 2026
    8.2
    High

    CVE-2026-77348

    Last Modified: 3 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships a second, near-identical, unauthenticated logo-image search endpoint — endpoints/payments/search.php — that was not given the same hardening. It still passes the HTTP_PROXY/HTTPS_PROXY environment variable straight into CURLOPT_PROXY. This issue has been patched in version 5.0.0.

    Published: 31 Aug 2026
    5.5
    Medium

    CVE-2026-82921

    Last Modified: 1 Sept 2026

    A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    3.5
    Low

    CVE-2026-77351

    Last Modified: 1 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled notification cron job runs, it passes the stored host directly to PHPMailer, causing the Wallos server to open an outbound TCP connection to whatever address the attacker specified. This gives a low-privileged attacker a reliable mechanism to probe internal network services from the server's perspective. This issue has been patched in version 5.0.0.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-82393

    Last Modified: 1 Sept 2026

    pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-resolver/src/index.ts, and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts, causing package extraction outside node_modules and allowing attacker-controlled files to overwrite arbitrary filesystem paths even when --ignore-scripts is used. The overwrite can replace shell startup files, Git hooks, or installed package code and lead to code execution. This issue is fixed in versions 10.34.5, and 11.11.0.

    Published: 31 Aug 2026
    8.7
    High

    CVE-2026-82882

    Last Modified: 2 Sept 2026

    Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-82392

    Last Modified: 1 Sept 2026

    pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user's privileges. This issue is fixed in versions 10.34.5 and 11.11.0.

    Published: 31 Aug 2026
    5.5
    Medium

    CVE-2026-82919

    Last Modified: 31 Aug 2026

    A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    6.9
    Medium

    CVE-2026-62993

    Last Modified: 2 Sept 2026

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used Security::isTrustedUri() to validate only the initial remote URL against trusted_uri when a security policy was active. For resources handled by file_get_contents(), including HTTPS URLs, PHP followed HTTP redirects by default. An attacker who could supply or influence a fetch target and had an open redirect on a trusted host could redirect the request to an attacker-chosen internal endpoint, bypass the trusted_uri allowlist, and perform server-side request forgery. This issue is fixed in versions 4.5.7 and 5.8.2.

    Published: 31 Aug 2026
    8.2
    High

    CVE-2026-75594

    Last Modified: 1 Sept 2026

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's built-in server, or Apache with AllowEncodedSlashes enabled, a remote attacker could submit encoded slash characters such as %2f in the filename and traverse outside the parent's media directory. Differences between responses for existing and nonexistent thumbnail configurations disclosed whether an arbitrary .json file existed, and a .json file containing a valid filename key could cause the referenced image to be returned and the job file to be deleted. The related file::version path in src/Filesystem/Asset.php also accepted ../ sequences outside the intended index root. This issue is fixed in versions 4.9.5 and 5.5.2.

    Published: 31 Aug 2026
    8.1
    High

    CVE-2026-61641

    Last Modified: 1 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverified email (multi-tenant IdPs, IdPs with open self-registration, or any IdP the attacker partly controls), an attacker with no Wallos account can authenticate with the admin's email and be logged in as the admin — full account takeover, no password needed. This issue has been patched in version 4.9.6.

    Published: 31 Aug 2026
    6.9
    Medium

    CVE-2026-75592

    Last Modified: 1 Sept 2026

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Kirby\Filesystem\Dir::realpath() and Kirby\Filesystem\F::realpath(). The checks accepted a sibling directory whose path shared the intended root's string prefix, such as /var/www/site2 next to /var/www/site, because they did not require an exact match or a DIRECTORY_SEPARATOR boundary. A remote attacker could use Kirby\Cms\Media::thumb() to create and access thumbnails from image files in a PHP-readable sibling directory when that directory contained a valid .json thumbnail job file, potentially exposing staging sites, backups, or other internal sites and deleting the job file during processing. This issue is fixed in versions 4.9.5 and 5.5.2.

    Published: 31 Aug 2026
    8.5
    High

    CVE-2026-61640

    Last Modified: 31 Aug 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs which have validate_webhook_url_for_ssrf(), OIDC URLs bypass all protections. Admin sets URL to http://169.254.169.254/latest/meta-data/ for cloud metadata access or internal network pivoting. This issue has been patched in version 4.9.6.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-71415

    Last Modified: 3 Sept 2026

    Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Api\Upload::processChunk() persisted chunk data. An authenticated user with the access.panel permission enabled but with files.create, files.replace, and user/users.update permissions disabled could submit requests with an Upload-Length header and leave unfinished chunks in site/cache/.uploads for 24 hours. Repeating this process could consume attacker-controlled temporary storage, prevent other users from uploading files, or prevent site logic from storing data, although final permission checks still prevented unauthorized files from reaching the content or site/accounts directories. This issue is fixed in version 5.5.2.

    Published: 31 Aug 2026
    5.5
    Medium

    CVE-2026-82914

    Last Modified: 1 Sept 2026

    A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Aug 2026
    8.5
    High

    CVE-2026-61639

    Last Modified: 1 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to write webshell to webroot. Extension filter only applies to post-extraction logo copy step. This issue has been patched in version 4.9.6.

    Published: 31 Aug 2026
    10
    Critical

    CVE-2026-81779

    Last Modified: 1 Sept 2026

    Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.

    Published: 31 Aug 2026
    8.2
    High

    CVE-2026-61638

    Last Modified: 1 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses ssrf_helper.php but email was missed. Any authenticated user can probe internal network, cloud metadata. This issue has been patched in version 4.9.6.

    Published: 31 Aug 2026
    5.4
    Medium

    CVE-2026-81278

    Last Modified: 1 Sept 2026

    Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.

    Published: 31 Aug 2026
    8.1
    High

    CVE-2026-81892

    Last Modified: 3 Sept 2026

    EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL, and the routeName value was not validated. As a result, a path-based access_control rule protecting the target route was never evaluated, so a low-privilege backend user who can reach a single EasyAdmin URL and knows a target route's name can execute that route's controller, bypassing the path-based rule. Only path-based protections are bypassed. Routes whose controller enforces its own authorization with #[IsGranted] or denyAccessUnlessGranted() remain protected because those checks are recomputed against the swapped-in controller. This issue is fixed in versions 4.29.16 and 5.5.1.

    Published: 31 Aug 2026
    7
    High

    CVE-2026-82346

    Last Modified: 1 Sept 2026

    A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

    Published: 31 Aug 2026
    8.1
    High

    CVE-2026-81891

    Last Modified: 1 Sept 2026

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php. An attacker with ZIP upload permission can extract PHP-executable files into a web-accessible files/ directory and achieve remote code execution when the server executes those extensions. This issue is fixed in version 2.1.70.

    Published: 31 Aug 2026
    8.2
    High

    CVE-2026-54600

    Last Modified: 2 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire database. This issue has been patched in version 4.9.4.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-82229

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.

    Published: 31 Aug 2026
    8.1
    High

    CVE-2026-82228

    Last Modified: 1 Sept 2026

    Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

    Published: 31 Aug 2026
    9.8
    Critical

    CVE-2026-82226

    Last Modified: 1 Sept 2026

    Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

    Published: 31 Aug 2026
    7.4
    High

    CVE-2026-82225

    Last Modified: 1 Sept 2026

    Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-82224

    Last Modified: 2 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-82221

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

    Published: 31 Aug 2026
    10
    Critical

    CVE-2026-81780

    Last Modified: 1 Sept 2026

    Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

    Published: 31 Aug 2026
    6.5
    Medium

    CVE-2026-81778

    Last Modified: 1 Sept 2026

    Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-81768

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-81765

    Last Modified: 2 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-81764

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.

    Published: 31 Aug 2026
    9.3
    Critical

    CVE-2026-81763

    Last Modified: 1 Sept 2026

    Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

    Published: 31 Aug 2026
    6.5
    Medium

    CVE-2026-81762

    Last Modified: 1 Sept 2026

    Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.

    Published: 31 Aug 2026
    6.3
    Medium

    CVE-2026-81758

    Last Modified: 1 Sept 2026

    Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.

    Published: 31 Aug 2026
    9.3
    Critical

    CVE-2026-81756

    Last Modified: 2 Sept 2026

    Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-81298

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-81297

    Last Modified: 1 Sept 2026

    Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-81296

    Last Modified: 1 Sept 2026

    Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

    Published: 31 Aug 2026
    9.3
    Critical

    CVE-2026-81293

    Last Modified: 1 Sept 2026

    Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-81291

    Last Modified: 2 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

    Published: 31 Aug 2026
    7.1
    High

    CVE-2026-81290

    Last Modified: 1 Sept 2026

    Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.

    Published: 31 Aug 2026
    8.5
    High

    CVE-2026-81287

    Last Modified: 1 Sept 2026

    Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

    Published: 31 Aug 2026
    6.5
    Medium

    CVE-2026-81280

    Last Modified: 1 Sept 2026

    Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

    Published: 31 Aug 2026
    5.4
    Medium

    CVE-2026-82852

    Last Modified: 2 Sept 2026

    Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.

    Published: 31 Aug 2026
    7.5
    High

    CVE-2026-54599

    Last Modified: 1 Sept 2026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. An attacker can trick a victim into visiting a crafted URL, causing Wallos to exchange the attacker's authorization code and log the victim into the attacker's account. This issue has been patched in version 4.9.4.

    Published: 31 Aug 2026
    2.1
    Low

    CVE-2026-82909

    Last Modified: 2 Sept 2026

    A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.

    Published: 31 Aug 2026