Products: 2
    Vulnerabilities: 48
    Known Exploited: 1
    13
    Critical Level Threats
    24
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-77915

    rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php

    Last Modified: Aug 29, 2026
    Published: Aug 24, 2026

    CVE-2026-77914

    rConfig Core 8.0.0 < 8.2.13 Core Path Traversal via Export Download Endpoint

    Last Modified: Aug 25, 2026
    Published: Aug 24, 2026

    CVE-2026-64826

    rConfig < 8.2.13 Path Traversal File Read via FileDownloadController

    Last Modified: Aug 14, 2026
    Published: Aug 12, 2026

    CVE-2026-63102

    rConfig Core < 8.2.8 Privilege Escalation via Users API role field

    Last Modified: Aug 19, 2026
    Published: Jul 20, 2026

    CVE-2023-39109

    rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

    Last Modified: Nov 21, 2024
    Published: Aug 01, 2023
    Items Per Page