Search

Find a vulnerability

Search criteria

    8191 vulnerabilities

    CVE-2026-105131 (GCVE-0-2026-105131)

    Vulnerability from cvelistv5 – Published: 2026-10-04 01:20 – Updated: 2026-10-04 01:20
    VLAI
    Title
    mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint
    Summary
    ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    mayswind ezBookkeeping Affected: 1.2.0 , < 2.0.1 (semver)
        cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-23 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:golang/github.com/mayswind/ezbookkeeping",
              "product": "ezBookkeeping",
              "vendor": "mayswind",
              "versions": [
                {
                  "lessThan": "2.0.1",
                  "status": "affected",
                  "version": "1.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.0.1",
                      "versionStartIncluding": "1.2.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-04T01:20:29.985Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-wq25-mpcf-2mfc)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-wq25-mpcf-2mfc"
            },
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/mayswind/ezbookkeeping/commit/9a92b07be8a7034665abfdb35b036210a1d57bf9"
            },
            {
              "name": "ezBookkeeping v2.0.1 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.1"
            },
            {
              "name": "TokenRefreshHandler at v2.0.0",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/mayswind/ezbookkeeping/blob/v2.0.0/pkg/api/tokens.go#L327-L380"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/mayswind/ezbookkeeping"
            },
            {
              "name": "VulnCheck Advisory: mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-1.2.0-before-2.0.1-privilege-escalation-via-token-refresh-endpoint"
            }
          ],
          "title": "mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105131",
        "datePublished": "2026-10-04T01:20:29.985Z",
        "dateReserved": "2026-10-03T12:05:26.756Z",
        "dateUpdated": "2026-10-04T01:20:29.985Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105130 (GCVE-0-2026-105130)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
    VLAI
    Title
    LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit
    Summary
    LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 1.4.0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "1.4.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:02.301Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-gw6g-9wx9-3fpj)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Auth/RegisterController.php#L175-L188"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/Auth/RegistrationGuardService.php#L77-L105"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/343"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/1bc7b7e2d32dd0bbee8f39a7ed8a3316ae657d50"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-1.4.0-before-1.4.8-race-condition-bypasses-per-ip-registration-limit"
            }
          ],
          "title": "LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105130",
        "datePublished": "2026-10-03T23:40:02.301Z",
        "dateReserved": "2026-10-03T12:05:26.756Z",
        "dateUpdated": "2026-10-03T23:40:02.301Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105129 (GCVE-0-2026-105129)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
    VLAI
    Title
    LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API
    Summary
    LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:01.650Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-xgmw-7ppx-v7hq)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/340"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105129",
        "datePublished": "2026-10-03T23:40:01.650Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T23:40:01.650Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105128 (GCVE-0-2026-105128)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
    VLAI
    Title
    LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url
    Summary
    LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:01.065Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-j2vp-w788-8fcf)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/341"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105128",
        "datePublished": "2026-10-03T23:40:01.065Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T23:40:01.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105127 (GCVE-0-2026-105127)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
    VLAI
    Title
    LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints
    Summary
    LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 1.4.2 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "1.4.2",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:40:00.470Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-v36p-8578-8gch)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch"
            },
            {
              "name": "GitHub Security Advisory (GHSA-5hq2-r2f3-9vp9)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/339"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints"
            }
          ],
          "title": "LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105127",
        "datePublished": "2026-10-03T23:40:00.470Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T23:40:00.470Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105126 (GCVE-0-2026-105126)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:39 – Updated: 2026-10-03 23:39
    VLAI
    Title
    LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
    Summary
    LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-30 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-09-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:39:59.775Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-555v-6rfr-r969)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-555v-6rfr-r969"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L144"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L180"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/RolePolicy.php#L39-L50"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/CoreUpgrade/UploadRequest.php#L23"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/344"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/286f150e4d0c924ec1ce7eb256b2326e871e9517"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-privilege-escalation-via-superadmin-role-tampering"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105126",
        "datePublished": "2026-10-03T23:39:59.775Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T23:39:59.775Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105125 (GCVE-0-2026-105125)

    Vulnerability from cvelistv5 – Published: 2026-10-03 23:39 – Updated: 2026-10-03 23:39
    VLAI
    Title
    LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
    Summary
    LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    laradashboard laradashboard Affected: 0 , < 1.4.8 (semver)
    Unaffected: 1.4.8 (semver)
        cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-01 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/laradashboard/laradashboard",
              "product": "laradashboard",
              "vendor": "laradashboard",
              "versions": [
                {
                  "lessThan": "1.4.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.4.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.4.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "EVIL0RD"
            }
          ],
          "datePublic": "2026-10-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T23:39:59.168Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-43jp-66c9-7cgh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46"
            },
            {
              "tags": [
                "patch",
                "issue-tracking"
              ],
              "url": "https://github.com/laradashboard/laradashboard/pull/350"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e"
            },
            {
              "name": "laradashboard v1.4.8 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/laradashboard/laradashboard"
            },
            {
              "name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint"
            }
          ],
          "title": "LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105125",
        "datePublished": "2026-10-03T23:39:59.168Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T23:39:59.168Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105124 (GCVE-0-2026-105124)

    Vulnerability from cvelistv5 – Published: 2026-10-03 22:30 – Updated: 2026-10-03 22:30
    VLAI
    Title
    W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments
    Summary
    W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    vincent-peugnet wcms Affected: 0 , ≤ 3.18.0 (semver)
        cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-02 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "wcms",
              "vendor": "vincent-peugnet",
              "versions": [
                {
                  "lessThanOrEqual": "3.18.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "3.18.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ikram-4"
            }
          ],
          "datePublic": "2026-10-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T22:30:13.022Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #662",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/issues/662"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vincent-peugnet/wcms"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerconnect.php#L56"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/adminlog.php#L71"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/editrightbar.php#L110"
            },
            {
              "name": "VulnCheck Advisory: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-unauthenticated-stored-xss-via-login-username-and-comments"
            }
          ],
          "title": "W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105124",
        "datePublished": "2026-10-03T22:30:13.022Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T22:30:13.022Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105123 (GCVE-0-2026-105123)

    Vulnerability from cvelistv5 – Published: 2026-10-03 22:30 – Updated: 2026-10-03 22:30
    VLAI
    Title
    W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API
    Summary
    W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path].
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Impacted products
    Vendor Product Version
    vincent-peugnet wcms Affected: 0 , ≤ 3.18.0 (semver)
        cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-10-02 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "wcms",
              "vendor": "vincent-peugnet",
              "versions": [
                {
                  "lessThanOrEqual": "3.18.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "3.18.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "ikram-4"
            }
          ],
          "datePublic": "2026-10-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T22:30:12.394Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #662",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/issues/662"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/vincent-peugnet/wcms"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerapimedia.php#L24-L44"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Media.php#L98"
            },
            {
              "name": "VulnCheck Advisory: W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-rce-and-arbitrary-file-write-via-media-upload-api"
            }
          ],
          "title": "W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105123",
        "datePublished": "2026-10-03T22:30:12.394Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T22:30:12.394Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105122 (GCVE-0-2026-105122)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri
    Summary
    OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
        cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "arpitjain099"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "santhreal"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "alex-sc"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "jamesbishup"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "ayhambashtawi2-lang"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:45.551Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g7cv-hh35-cc7c)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-g7cv-hh35-cc7c"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-ssrf-via-openid-connect-client-jwks-uri"
            }
          ],
          "title": "OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105122",
        "datePublished": "2026-10-03T12:14:45.551Z",
        "dateReserved": "2026-10-03T12:05:26.755Z",
        "dateUpdated": "2026-10-03T12:14:45.551Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105121 (GCVE-0-2026-105121)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping
    Summary
    OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
    CWE
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
        cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "arpitjain099"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester\u0027s realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-285",
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:44.905Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-hmwh-9r8r-44gw)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping"
            }
          ],
          "title": "OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105121",
        "datePublished": "2026-10-03T12:14:44.905Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:44.905Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105120 (GCVE-0-2026-105120)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
    Summary
    OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core-rest",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "vharseko"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:44.244Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-x8cj-3hqv-cgwh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-x8cj-3hqv-cgwh"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-cross-realm-session-disclosure-via-sessions-rest-endpoint"
            }
          ],
          "title": "OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105120",
        "datePublished": "2026-10-03T12:14:44.244Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:44.244Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105119 (GCVE-0-2026-105119)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows
    Summary
    OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
    CWE
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
        cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "arpitjain099"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client\u0027s tokens with any non-empty code_verifier."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-285",
                  "description": "Improper Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:43.643Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-5p2f-7vcr-6vfh)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-5p2f-7vcr-6vfh"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-pkce-enforcement-bypass-via-oauth-2.0-hybrid-flows"
            }
          ],
          "title": "OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105119",
        "datePublished": "2026-10-03T12:14:43.643Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:43.643Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105118 (GCVE-0-2026-105118)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession
    Summary
    OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
    CWE
    • CWE-347 - Improper Verification of Cryptographic Signature
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
        cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "rockmelodies"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "santhreal"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host\u0027s trust."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-347",
                  "description": "Improper Verification of Cryptographic Signature",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:43.044Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-6f8c-crwq-jqm3)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-6f8c-crwq-jqm3"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-open-redirect-via-unverified-id-token-hint-in-endsession"
            }
          ],
          "title": "OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105118",
        "datePublished": "2026-10-03T12:14:43.044Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:43.044Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105117 (GCVE-0-2026-105117)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions
    Summary
    OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core-rest",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "santhreal"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation\u0027s configured From address, or abuse register as a relay to arbitrary recipients."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:42.310Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-mw38-8gr7-c4x2)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-mw38-8gr7-c4x2"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-email-content-injection-via-users-rest-self-service-actions"
            }
          ],
          "title": "OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105117",
        "datePublished": "2026-10-03T12:14:42.310Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:42.310Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105116 (GCVE-0-2026-105116)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page
    Summary
    OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-server-only",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-federation-library",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-auth-saml2",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            },
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "santhreal"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:41.631Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-v796-mg6j-9c5m)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-v796-mg6j-9c5m"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-latent-xss-in-saml-load-balancer-cookie-bounce-page"
            }
          ],
          "title": "OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105116",
        "datePublished": "2026-10-03T12:14:41.631Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:41.631Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105115 (GCVE-0-2026-105115)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
    Summary
    OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
        cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "manus-use"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "alex-sc"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "maximthomas"
            },
            {
              "lang": "en",
              "type": "analyst",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:40.894Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-wxmx-q96f-w4gw)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-wxmx-q96f-w4gw"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-unauthenticated-arbitrary-class-instantiation-via-jax-rpc-interface"
            }
          ],
          "title": "OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105115",
        "datePublished": "2026-10-03T12:14:40.894Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:40.894Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105114 (GCVE-0-2026-105114)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page
    Summary
    OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    OpenIdentityPlatform OpenAM Affected: 0 , < 16.1.3 (semver)
    Unaffected: 16.1.3 (semver)
        cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
              "product": "OpenAM",
              "vendor": "OpenIdentityPlatform",
              "versions": [
                {
                  "lessThan": "16.1.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "16.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Buggs777"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "tsujiguchitky"
            }
          ],
          "datePublic": "2026-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:39.964Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-3m32-w9x3-vvq8)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-3m32-w9x3-vvq8"
            },
            {
              "name": "VulnCheck Advisory: OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-reflected-xss-via-oauth2-authorization-error-page"
            }
          ],
          "title": "OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105114",
        "datePublished": "2026-10-03T12:14:39.964Z",
        "dateReserved": "2026-10-03T12:04:36.964Z",
        "dateUpdated": "2026-10-03T12:14:39.964Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105113 (GCVE-0-2026-105113)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock
    Summary
    Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
    CWE
    References
    Impacted products
    Vendor Product Version
    nezhahq nezha Affected: 1.8.0 , < 2.3.13 (semver)
    Unaffected: 2.3.13 (semver)
    Create a notification for this product.
    Date Public
    2026-09-19 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:golang/github.com/nezhahq/nezha",
              "product": "nezha",
              "vendor": "nezhahq",
              "versions": [
                {
                  "lessThan": "2.3.13",
                  "status": "affected",
                  "version": "1.8.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2.3.13",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "sondt99"
            }
          ],
          "datePublic": "2026-09-19T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-667",
                  "description": "Improper Locking",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:39.317Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-7j7v-j77m-6g3m)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/nezhahq/nezha/security/advisories/GHSA-7j7v-j77m-6g3m"
            },
            {
              "name": "VulnCheck Advisory: Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nezha-1.8.0-before-2.3.13-denial-of-service-via-notification-mutex-deadlock"
            }
          ],
          "title": "Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105113",
        "datePublished": "2026-10-03T12:14:39.317Z",
        "dateReserved": "2026-10-03T12:04:36.963Z",
        "dateUpdated": "2026-10-03T12:14:39.317Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105112 (GCVE-0-2026-105112)

    Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
    VLAI
    Title
    Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints
    Summary
    Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart.
    CWE
    • CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
    References
    Impacted products
    Vendor Product Version
    nezhahq nezha Affected: 1.8.0 , < 2.3.13 (semver)
    Unaffected: 2.3.13 (semver)
    Create a notification for this product.
    Date Public
    2026-09-19 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:golang/github.com/nezhahq/nezha",
              "product": "nezha",
              "vendor": "nezhahq",
              "versions": [
                {
                  "lessThan": "2.3.13",
                  "status": "affected",
                  "version": "1.8.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2.3.13",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "sondt99"
            }
          ],
          "datePublic": "2026-09-19T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-362",
                  "description": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T12:14:38.663Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-53vr-p24v-qvwf)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/nezhahq/nezha/security/advisories/GHSA-53vr-p24v-qvwf"
            },
            {
              "name": "VulnCheck Advisory: Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/nezha-1.8.0-before-2.3.13-deadlock-dos-via-notification-group-endpoints"
            }
          ],
          "title": "Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105112",
        "datePublished": "2026-10-03T12:14:38.663Z",
        "dateReserved": "2026-10-03T12:04:36.963Z",
        "dateUpdated": "2026-10-03T12:14:38.663Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105083 (GCVE-0-2026-105083)

    Vulnerability from cvelistv5 – Published: 2026-10-03 01:11 – Updated: 2026-10-03 01:11
    VLAI
    Title
    ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE
    Summary
    ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
    CWE
    • CWE-693 - Protection Mechanism Failure
    Impacted products
    Vendor Product Version
    ImageMagick ImageMagick Affected: 7.0.0-0 , < 7.1.2-32 (custom)
    Affected: 0 , < 6.9.13-57 (custom)
        cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
        cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-27 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "ImageMagick",
              "vendor": "ImageMagick",
              "versions": [
                {
                  "lessThan": "7.1.2-32",
                  "status": "affected",
                  "version": "7.0.0-0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "6.9.13-57",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "7.1.2-32",
                      "versionStartIncluding": "7.0.0-0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9.13-57",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yanhaoxi"
            }
          ],
          "datePublic": "2026-09-27T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in \u0027]\u003e\u0027 makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 1.8,
                "baseSeverity": "LOW",
                "privilegesRequired": "HIGH",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "LOW",
                "baseScore": 3.9,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-693",
                  "description": "Protection Mechanism Failure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-03T01:11:12.822Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-jjp4-3fwf-393j)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jjp4-3fwf-393j"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick/commit/1926ccf119141c26274c120d1899dffae19b0c71"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick/commit/399d4bd3b081f44c7fef78153f65e8cdebed9f1a"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick6/commit/da6022b2efe6cce8a2fd8f9e51188a45a3b9d558"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick6/commit/402ebc5353e569234908962cbdf451531ff66a57"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/MagickCore/policy.c#L1138-L1145"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ImageMagick/ImageMagick"
            },
            {
              "name": "VulnCheck Advisory: ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-security-policy-bypass-via-policy-xml-doctype"
            }
          ],
          "title": "ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105083",
        "datePublished": "2026-10-03T01:11:12.822Z",
        "dateReserved": "2026-10-03T01:03:07.467Z",
        "dateUpdated": "2026-10-03T01:11:12.822Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105030 (GCVE-0-2026-105030)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
    Summary
    Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    rajnandan1 kener Affected: 4.0.0 , < 4.1.6 (semver)
    Unaffected: 4.1.6 (semver)
    Create a notification for this product.
    Date Public
    2026-09-16 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "kener",
              "repo": "https://github.com/rajnandan1/kener",
              "vendor": "rajnandan1",
              "versions": [
                {
                  "lessThan": "4.1.6",
                  "status": "affected",
                  "version": "4.0.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "4.1.6",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "George Chen"
            }
          ],
          "datePublic": "2026-09-16T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:49.929Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #848",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/rajnandan1/kener/issues/848"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/rajnandan1/kener/commit/e8ce31898bf73ffe6be07c9b299da2a7330ddba5"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/rajnandan1/kener"
            },
            {
              "name": "VulnCheck Advisory: Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/kener-4.0.0-before-4.1.6-hidden-monitor-data-disclosure-via-dashboard-api"
            }
          ],
          "title": "Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105030",
        "datePublished": "2026-10-02T23:28:49.929Z",
        "dateReserved": "2026-10-02T21:13:54.716Z",
        "dateUpdated": "2026-10-02T23:28:49.929Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105029 (GCVE-0-2026-105029)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
    Summary
    UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    uvdesk support-center-bundle Affected: 0 , < 1.1.3.3 (custom)
    Unaffected: 1.1.3.3 (custom)
    Create a notification for this product.
    uvdesk community-skeleton Affected: 0 , < 1.1.8 (semver)
    Unaffected: 1.1.8 (semver)
    Create a notification for this product.
    Date Public
    2025-06-06 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/support-center-bundle",
              "product": "support-center-bundle",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.3.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.3.3",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/uvdesk/community-skeleton",
              "product": "community-skeleton",
              "vendor": "uvdesk",
              "versions": [
                {
                  "lessThan": "1.1.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.1.8",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:uvdesk:community-skeleton:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.1.8",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "leediay153"
            }
          ],
          "datePublic": "2025-06-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers\u0027 tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:49.296Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/uvdesk/support-center-bundle/commit/3fa884a3adf0f317f354f83a1f9fa531234a551f"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://hackmd.io/@leediay/idor-rate-ticket_uvdesk"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/uvdesk/support-center-bundle"
            },
            {
              "name": "VulnCheck Advisory: UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/uvdesk-support-center-bundle-before-1.1.3.3-idor-via-rateticket-ticket-rating-endpoint"
            }
          ],
          "title": "UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-105029",
        "datePublished": "2026-10-02T23:28:49.296Z",
        "dateReserved": "2026-10-02T21:13:54.347Z",
        "dateUpdated": "2026-10-02T23:28:49.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104479 (GCVE-0-2026-104479)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    Shopclass before 6.2.0 Stored XSS via Listing Description Field
    Summary
    Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    mindstellar shopclass Affected: 0 , < 6.2.0 (semver)
    Unaffected: 6.2.0 (semver)
    Create a notification for this product.
    Date Public
    2026-08-27 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "shopclass",
              "repo": "https://github.com/mindstellar/shopclass",
              "vendor": "mindstellar",
              "versions": [
                {
                  "lessThan": "6.2.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Islomjon Tursunov"
            }
          ],
          "datePublic": "2026-08-27T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:48.624Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/mindstellar/shopclass/commit/c196f70906522c9b9172c24f1b42cd0a02357422"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/mindstellar/shopclass"
            },
            {
              "name": "VulnCheck Advisory: Shopclass before 6.2.0 Stored XSS via Listing Description Field",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/shopclass-before-6.2.0-stored-xss-via-listing-description-field"
            }
          ],
          "title": "Shopclass before 6.2.0 Stored XSS via Listing Description Field",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104479",
        "datePublished": "2026-10-02T23:28:48.624Z",
        "dateReserved": "2026-10-02T00:55:58.388Z",
        "dateUpdated": "2026-10-02T23:28:48.624Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104478 (GCVE-0-2026-104478)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    Formwork before 2.3.13 Path Traversal via BackupController Download and Delete
    Summary
    Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    getformwork formwork Affected: 0 , < 2.3.13 (semver)
    Unaffected: 2.3.13 (semver)
        cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-22 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:composer/getformwork/formwork",
              "product": "formwork",
              "vendor": "getformwork",
              "versions": [
                {
                  "lessThan": "2.3.13",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2.3.13",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.3.13",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Islomjon Tursunov"
            }
          ],
          "datePublic": "2026-08-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:48.001Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/getformwork/formwork/commit/89e7821a6fcee89474cd401b3dde0c1dccb0687f"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/getformwork/formwork"
            },
            {
              "name": "VulnCheck Advisory: Formwork before 2.3.13 Path Traversal via BackupController Download and Delete",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/formwork-before-2.3.13-path-traversal-via-backupcontroller-download-and-delete"
            }
          ],
          "title": "Formwork before 2.3.13 Path Traversal via BackupController Download and Delete",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104478",
        "datePublished": "2026-10-02T23:28:48.001Z",
        "dateReserved": "2026-10-02T00:55:58.388Z",
        "dateUpdated": "2026-10-02T23:28:48.001Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104477 (GCVE-0-2026-104477)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    Showdown through 2.1.0 XSS via unescaped quote in href and src attributes
    Summary
    Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    showdownjs showdown Affected: 0 , ≤ 2.1.0 (semver)
        cpe:2.3:a:showdownjs:showdown:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-06-27 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:npm/showdown",
              "product": "showdown",
              "vendor": "showdownjs",
              "versions": [
                {
                  "lessThanOrEqual": "2.1.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:showdownjs:showdown:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.1.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Muhammad Sobirov"
            }
          ],
          "datePublic": "2026-06-27T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.1,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:47.414Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/showdownjs/showdown/commit/4fb992cd26631c108ec0410342630c80207ec7c6"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/showdownjs/showdown"
            },
            {
              "name": "VulnCheck Advisory: Showdown through 2.1.0 XSS via unescaped quote in href and src attributes",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/showdown-through-2.1.0-xss-via-unescaped-quote-in-href-and-src-attributes"
            }
          ],
          "title": "Showdown through 2.1.0 XSS via unescaped quote in href and src attributes",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104477",
        "datePublished": "2026-10-02T23:28:47.414Z",
        "dateReserved": "2026-10-02T00:55:58.388Z",
        "dateUpdated": "2026-10-02T23:28:47.414Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104476 (GCVE-0-2026-104476)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive
    Summary
    Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    backdrop backdrop Affected: 0 , < 1.35.1 (semver)
    Unaffected: 1.35.1 (semver)
        cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-23 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "backdrop",
              "vendor": "backdrop",
              "versions": [
                {
                  "lessThan": "1.35.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.35.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.35.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dilip Choudhary"
            }
          ],
          "datePublic": "2026-09-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:46.804Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "Patch Commit",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749"
            },
            {
              "name": "BACKDROP-SA-CORE-2026-006",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://backdropcms.org/security/backdrop-sa-core-2026-006"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/backdrop/backdrop"
            },
            {
              "name": "VulnCheck Advisory: Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive"
            }
          ],
          "title": "Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104476",
        "datePublished": "2026-10-02T23:28:46.804Z",
        "dateReserved": "2026-10-02T00:55:58.388Z",
        "dateUpdated": "2026-10-02T23:28:46.804Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104475 (GCVE-0-2026-104475)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload
    Summary
    IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    idurar idurar-erp-crm Affected: 0 , ≤ 4.1.1 (semver)
    Create a notification for this product.
    Date Public
    2026-01-10 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "idurar-erp-crm",
              "vendor": "idurar",
              "versions": [
                {
                  "lessThanOrEqual": "4.1.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Jashn Wahi"
            }
          ],
          "datePublic": "2026-01-10T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims\u0027 browsers when served from the /public route."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:46.132Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #1414",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/idurar/idurar-erp-crm/issues/1414"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/idurar/idurar-erp-crm/blob/4.1.1/backend/src/middlewares/uploadMiddleware/utils/fileFilterMiddleware.js"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/idurar/idurar-erp-crm"
            },
            {
              "name": "VulnCheck Advisory: IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/idurar-erp-crm-through-4.1.1-stored-xss-via-svg-upload"
            }
          ],
          "title": "IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104475",
        "datePublished": "2026-10-02T23:28:46.132Z",
        "dateReserved": "2026-10-02T00:55:58.387Z",
        "dateUpdated": "2026-10-02T23:28:46.132Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104474 (GCVE-0-2026-104474)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
    Summary
    OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
    CWE
    • CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
    Impacted products
    Vendor Product Version
    litespeedtech openlitespeed Affected: 0 , < 1.9.3 (semver)
    Unaffected: 1.9.3 (semver)
        cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-29 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/litespeedtech/openlitespeed",
              "product": "openlitespeed",
              "repo": "https://github.com/litespeedtech/openlitespeed",
              "vendor": "litespeedtech",
              "versions": [
                {
                  "lessThan": "1.9.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "1.9.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.9.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "FCI Cloud Security"
            }
          ],
          "datePublic": "2026-09-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-367",
                  "description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:45.481Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "OpenLiteSpeed Version 1.9.x Release Log",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://openlitespeed.org/release-log/version-1-9-x/"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/litespeedtech/openlitespeed/commit/468523ce84388cea9ba6633c26517bc05b3e2bc1"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/litespeedtech/openlitespeed/blob/v1.9.2/dist/admin/misc/lsup.sh#L538"
            },
            {
              "name": "VulnCheck Advisory: OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/openlitespeed-before-1.9.3-local-privilege-escalation-via-lsup-sh-auto-update"
            }
          ],
          "title": "OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104474",
        "datePublished": "2026-10-02T23:28:45.481Z",
        "dateReserved": "2026-10-02T00:55:58.387Z",
        "dateUpdated": "2026-10-02T23:28:45.481Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104433 (GCVE-0-2026-104433)

    Vulnerability from cvelistv5 – Published: 2026-10-02 23:28 – Updated: 2026-10-02 23:28
    VLAI
    Title
    Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString
    Summary
    Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
    CWE
    Impacted products
    Vendor Product Version
    kvcache-ai Mooncake Affected: 0 , < 0.3.12 (custom)
    Unaffected: 0.3.12 (custom)
    Create a notification for this product.
    Date Public
    2026-10-02 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:pypi/mooncake-transfer-engine",
              "product": "Mooncake",
              "vendor": "kvcache-ai",
              "versions": [
                {
                  "lessThan": "0.3.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "0.3.12",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Mingkai Yu"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Xiangjun Sun"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Jiajia Liu"
            }
          ],
          "datePublic": "2026-10-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "Out-of-bounds Read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T23:28:44.691Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Issue #4452",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/issues/4452"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake/commit/c142b40590259360196d8e504b2193382529e7b4"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/kvcache-ai/Mooncake"
            },
            {
              "name": "VulnCheck Advisory: Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/mooncake-before-0.3.12-out-of-bounds-read-via-p2p-handshake-readstring"
            }
          ],
          "title": "Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104433",
        "datePublished": "2026-10-02T23:28:44.691Z",
        "dateReserved": "2026-10-02T00:50:26.603Z",
        "dateUpdated": "2026-10-02T23:28:44.691Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }