Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-40488
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
CVE-2026-29179
October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
CVE-2026-27937
October CMS: Reflected XSS via DataTable Form Widget
CVE-2026-26274
October CMS has Safe Mode Bypass via Twig Database Write Operations
CVE-2026-26067
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers
CVE-2026-40098
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
CVE-2026-25525
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
CVE-2026-25524
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
Kimai: Username enumeration via timing on X-AUTH-USER
CVE-2026-23500
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
CVE-2026-31317
Craftql vulnerable to Server-Side Request Forgery
CVE-2026-40308
Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog in My Calendar
Statamic: Unsafe method invocation via query value resolution allows data destruction
WWBN AVideo: RCE cause by clonesite plugin
CVE-2026-24749
Silverstripe Assets Module has a DBFile::getURL() permission bypass
CVE-2026-31843
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
Showing 1 - 20 of 1,000+ results