Search
Find a vulnerability
Search criteria
394766 vulnerabilities
No criteria set — showing every indexed entry of the selected sources, newest first by published date.
CVE-2026-105135 (GCVE-0-2026-105135)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:15 – Updated: 2026-10-04 06:15
VLAI
EPSS
VEX
Title
InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection
Summary
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413352 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/413352/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105135 | third-party-advisory |
| https://vuldb.com/submit/943315 | third-party-advisory |
| https://gist.github.com/DReazer/7ad46df9da73d0cf4… | exploit |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| InternLM | MindSearch |
Affected:
0.1.0
cpe:2.3:a:internlm:mindsearch:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:internlm:mindsearch:*:*:*:*:*:*:*:*"
],
"modules": [
"Planner Agent"
],
"product": "MindSearch",
"vendor": "InternLM",
"versions": [
{
"status": "affected",
"version": "0.1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Snkn0w (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 10,
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Code Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:15:12.388Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413352 | InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/413352"
},
{
"name": "VDB-413352 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413352/cti"
},
{
"name": "CVE-2026-105135 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105135"
},
{
"name": "Submit #943315 | InternLM MindSearch 0.1.0 Code Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/943315"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/DReazer/7ad46df9da73d0cf414276e4195b2183"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T15:24:28.000Z",
"value": "VulDB entry last update"
}
],
"title": "InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105135",
"datePublished": "2026-10-04T06:15:12.388Z",
"dateReserved": "2026-10-03T13:19:23.690Z",
"dateUpdated": "2026-10-04T06:15:12.388Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97332 (GCVE-0-2026-97332)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:00 – Updated: 2026-10-04 06:00
VLAI
EPSS
VEX
Title
User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)
Summary
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/d6a144b3-84e3-43… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | User Private Files |
Affected:
0 , < 2.2.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "User Private Files",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.2.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Akshat Parikh (SN1PER)"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users\u0027 private files directly."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-284 Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:00:24.076Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/d6a144b3-84e3-43eb-92d3-fd4505dd0e1c/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "User Private Files \u003c 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite Rule Bypass (Multisite)",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-97332",
"datePublished": "2026-10-04T06:00:24.076Z",
"dateReserved": "2026-09-24T11:58:42.116Z",
"dateUpdated": "2026-10-04T06:00:24.076Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93549 (GCVE-0-2026-93549)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:00 – Updated: 2026-10-04 06:00
VLAI
EPSS
VEX
Title
CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
Summary
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/77f413f6-8753-4c… | exploitvdb-entrytechnical-description |
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CoCart",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.9.7",
"status": "affected",
"version": "4.9.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Naoki Kawahigashi"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core\u0027s REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator\u0027s session."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-352 Cross-Site Request Forgery (CSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:00:23.901Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/77f413f6-8753-4c83-8623-00ad7a1dcaff/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-93549",
"datePublished": "2026-10-04T06:00:23.901Z",
"dateReserved": "2026-09-18T09:25:32.032Z",
"dateUpdated": "2026-10-04T06:00:23.901Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86817 (GCVE-0-2026-86817)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:00 – Updated: 2026-10-04 06:00
VLAI
EPSS
VEX
Title
Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure via Schema Field Default Callback
Summary
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/2a400958-7ed8-43… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Five Star Business Profile and Schema |
Affected:
2.3.20 , < 2.4.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Five Star Business Profile and Schema",
"vendor": "Unknown",
"versions": [
{
"lessThan": "2.4.0",
"status": "affected",
"version": "2.3.20",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Artus KG"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users\u0027 password hashes and arbitrary site option values, in public output readable by unauthenticated visitors."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-200 Information Exposure",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:00:23.722Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/2a400958-7ed8-4358-a46a-2b8e0716a771/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure via Schema Field Default Callback",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-86817",
"datePublished": "2026-10-04T06:00:23.722Z",
"dateReserved": "2026-09-08T13:52:58.085Z",
"dateUpdated": "2026-10-04T06:00:23.722Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104119 (GCVE-0-2026-104119)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:00 – Updated: 2026-10-04 06:00
VLAI
EPSS
VEX
Title
Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials
Summary
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/d6ee7720-9c2d-48… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Simple Shopping Cart |
Affected:
0 , < 5.2.6
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Simple Shopping Cart",
"vendor": "Unknown",
"versions": [
{
"lessThan": "5.2.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Krugov Artyom"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-79 Cross-Site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:00:23.281Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/d6ee7720-9c2d-48b3-b238-0da4fed398a3/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Simple Shopping Cart \u003c 5.2.6 - Admin+ Stored XSS via PayPal API Credentials",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-104119",
"datePublished": "2026-10-04T06:00:23.281Z",
"dateReserved": "2026-10-01T18:14:10.575Z",
"dateUpdated": "2026-10-04T06:00:23.281Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104118 (GCVE-0-2026-104118)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:00 – Updated: 2026-10-04 06:00
VLAI
EPSS
VEX
Title
Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR
Summary
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/d94ebc87-c404-4b… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Razorpay for WooCommerce |
Affected:
0 , < 4.8.8
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Razorpay for WooCommerce",
"vendor": "Unknown",
"versions": [
{
"lessThan": "4.8.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Charles Vosburgh"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:00:23.107Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/d94ebc87-c404-4b30-8291-26c4bc2eb63b/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Razorpay for WooCommerce \u003c 4.8.8 - Unauthenticated Order Shipping Modification via IDOR",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-104118",
"datePublished": "2026-10-04T06:00:23.107Z",
"dateReserved": "2026-10-01T18:12:49.242Z",
"dateUpdated": "2026-10-04T06:00:23.107Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17005 (GCVE-0-2026-17005)
Vulnerability from cvelistv5 – Published: 2026-10-04 06:00 – Updated: 2026-10-04 06:00
VLAI
EPSS
VEX
Title
Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
Summary
The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
Severity
No CVSS data available.
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://wpscan.com/vulnerability/e3973475-18c4-46… | exploitvdb-entrytechnical-description |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unknown | Horizontal scrolling announcements |
Affected:
0 , ≤ 2.6
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "Horizontal scrolling announcements",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "2.6",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "testoun"
},
{
"lang": "en",
"type": "coordinator",
"value": "WPScan"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-79 Cross-Site Scripting (XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T06:00:22.933Z",
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan"
},
"references": [
{
"tags": [
"exploit",
"vdb-entry",
"technical-description"
],
"url": "https://wpscan.com/vulnerability/e3973475-18c4-46a0-b0ca-24e4d2cd58ca/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Horizontal Scrolling Announcements \u003c= 2.6 - Contributor+ Stored XSS via Style Field",
"x_generator": {
"engine": "WPScan CVE Generator"
}
}
},
"cveMetadata": {
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"cveId": "CVE-2026-17005",
"datePublished": "2026-10-04T06:00:22.933Z",
"dateReserved": "2026-07-24T09:48:24.498Z",
"dateUpdated": "2026-10-04T06:00:22.933Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105134 (GCVE-0-2026-105134)
Vulnerability from cvelistv5 – Published: 2026-10-04 05:30 – Updated: 2026-10-04 05:30
VLAI
EPSS
VEX
Title
Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection
Summary
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.
Severity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413351 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/413351/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105134 | third-party-advisory |
| https://vuldb.com/submit/942743 | third-party-advisory |
| https://www.ahsay.com/en/support/help-centre/rele… | patch |
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ahsay:ahsaycbs:*:*:*:*:*:*:*:*"
],
"modules": [
"Replication Receiver"
],
"product": "AhsayCBS",
"vendor": "Ahsay",
"versions": [
{
"status": "affected",
"version": "10.3.0"
},
{
"status": "affected",
"version": "10.3.1"
},
{
"status": "affected",
"version": "10.3.2"
},
{
"status": "unaffected",
"version": "10.3.4"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "nickc (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB Vulnerability Moderation Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 10,
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T05:30:12.882Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413351 | Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/413351"
},
{
"name": "VDB-413351 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413351/cti"
},
{
"name": "CVE-2026-105134 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105134"
},
{
"name": "Submit #942743 | Ahsay Systems Corporation Limited Ahsay CBS 10.3.0 Remote Code Execution via Arbitrary File Write",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/942743"
},
{
"tags": [
"patch"
],
"url": "https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T15:18:49.000Z",
"value": "VulDB entry last update"
}
],
"title": "Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105134",
"datePublished": "2026-10-04T05:30:12.882Z",
"dateReserved": "2026-10-03T13:13:35.953Z",
"dateUpdated": "2026-10-04T05:30:12.882Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105133 (GCVE-0-2026-105133)
Vulnerability from cvelistv5 – Published: 2026-10-04 05:15 – Updated: 2026-10-04 05:15
VLAI
EPSS
VEX
Title
Ahsay AhsayCBS API ApiStructsAction.java checkSysPwd improper authentication
Summary
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
Severity
CWE
- CWE-287 - Improper Authentication
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413350 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/413350/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105133 | third-party-advisory |
| https://vuldb.com/submit/942688 | third-party-advisory |
| https://www.ahsay.com/en/support/help-centre/rele… | patch |
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ahsay:ahsaycbs:*:*:*:*:*:*:*:*"
],
"modules": [
"API"
],
"product": "AhsayCBS",
"vendor": "Ahsay",
"versions": [
{
"status": "affected",
"version": "10.3.0"
},
{
"status": "affected",
"version": "10.3.1"
},
{
"status": "affected",
"version": "10.3.2"
},
{
"status": "unaffected",
"version": "10.3.4"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "nickc (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB Vulnerability Moderation Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T05:15:14.561Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413350 | Ahsay AhsayCBS API ApiStructsAction.java checkSysPwd improper authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/413350"
},
{
"name": "VDB-413350 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413350/cti"
},
{
"name": "CVE-2026-105133 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105133"
},
{
"name": "Submit #942688 | Ahsay Systems Corporation Limited AhsayCBS 10.0.3 Authentication Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/942688"
},
{
"tags": [
"patch"
],
"url": "https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T15:18:44.000Z",
"value": "VulDB entry last update"
}
],
"title": "Ahsay AhsayCBS API ApiStructsAction.java checkSysPwd improper authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105133",
"datePublished": "2026-10-04T05:15:14.561Z",
"dateReserved": "2026-10-03T13:13:31.953Z",
"dateUpdated": "2026-10-04T05:15:14.561Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105099 (GCVE-0-2026-105099)
Vulnerability from cvelistv5 – Published: 2026-10-04 03:30 – Updated: 2026-10-04 03:30
VLAI
EPSS
VEX
Title
Omega Solution CoinEx Crypto Ticket Attachment Upload ticket cross site scripting
Summary
A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413348 | vdb-entry |
| https://vuldb.com/vuln/413348/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105099 | third-party-advisory |
| https://vuldb.com/submit/894325 | third-party-advisory |
| https://github.com/4m3rr0r/PoCVulDb/issues/27 | exploitissue-tracking |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Omega Solution | CoinEx Crypto |
Affected:
2025
cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*"
],
"modules": [
"Ticket Attachment Upload"
],
"product": "CoinEx Crypto",
"vendor": "Omega Solution",
"versions": [
{
"status": "affected",
"version": "2025"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "4m3rr0r (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.5,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross Site Scripting",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Code Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T03:30:16.721Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413348 | Omega Solution CoinEx Crypto Ticket Attachment Upload ticket cross site scripting",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/413348"
},
{
"name": "VDB-413348 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413348/cti"
},
{
"name": "CVE-2026-105099 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105099"
},
{
"name": "Submit #894325 | Omega Solution CoinEx Crypto latest Cross Site Scripting",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894325"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/4m3rr0r/PoCVulDb/issues/27"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T11:48:37.000Z",
"value": "VulDB entry last update"
}
],
"title": "Omega Solution CoinEx Crypto Ticket Attachment Upload ticket cross site scripting",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105099",
"datePublished": "2026-10-04T03:30:16.721Z",
"dateReserved": "2026-10-03T09:43:05.562Z",
"dateUpdated": "2026-10-04T03:30:16.721Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105098 (GCVE-0-2026-105098)
Vulnerability from cvelistv5 – Published: 2026-10-04 02:45 – Updated: 2026-10-04 02:45
VLAI
EPSS
VEX
Title
Omega Solution CoinEx Crypto Support Ticket API customer information disclosure
Summary
A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413347 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/413347/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105098 | third-party-advisory |
| https://vuldb.com/submit/894324 | third-party-advisory |
| https://github.com/4m3rr0r/PoCVulDb/issues/26 | exploitissue-tracking |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Omega Solution | CoinEx Crypto |
Affected:
2025
cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*"
],
"modules": [
"Support Ticket API"
],
"product": "CoinEx Crypto",
"vendor": "Omega Solution",
"versions": [
{
"status": "affected",
"version": "2025"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "4m3rr0r (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "Information Disclosure",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T02:45:13.406Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413347 | Omega Solution CoinEx Crypto Support Ticket API customer information disclosure",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/413347"
},
{
"name": "VDB-413347 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413347/cti"
},
{
"name": "CVE-2026-105098 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105098"
},
{
"name": "Submit #894324 | Omega Solution CoinEx Crypto latest Information Disclosure",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894324"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/4m3rr0r/PoCVulDb/issues/26"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T11:48:33.000Z",
"value": "VulDB entry last update"
}
],
"title": "Omega Solution CoinEx Crypto Support Ticket API customer information disclosure",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105098",
"datePublished": "2026-10-04T02:45:13.406Z",
"dateReserved": "2026-10-03T09:43:01.580Z",
"dateUpdated": "2026-10-04T02:45:13.406Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-88779 (GCVE-0-2026-88779)
Vulnerability from cvelistv5 – Published: 2026-10-04 02:35 – Updated: 2026-10-04 02:35
VLAI
EPSS
VEX
Title
Memory overflow vulnerability leading to Denial of Service
Summary
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Severity
Assigner
References
1 reference
Impacted products
Date Public
2026-10-04 02:19
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ADC",
"vendor": "NetScaler",
"versions": [
{
"lessThan": "14.1-73.41",
"status": "affected",
"version": "0",
"versionType": "Patch"
},
{
"lessThan": "13.1-64.28",
"status": "affected",
"version": "0",
"versionType": "Patch"
},
{
"lessThan": "14.1-73.41 FIPS",
"status": "affected",
"version": "0",
"versionType": "Patch"
},
{
"lessThan": "13.1-37.282",
"status": "affected",
"version": "0",
"versionType": "Patch"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Gateway",
"vendor": "NetScaler",
"versions": [
{
"lessThan": "14.1-73.41",
"status": "affected",
"version": "0",
"versionType": "Patch"
},
{
"lessThan": "13.1-64.28",
"status": "affected",
"version": "0",
"versionType": "Patch"
}
]
}
],
"datePublic": "2026-10-04T02:19:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Vulnerability in NetScaler ADC and NetScaler Gateway.\u003cp\u003eThis issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.\u003c/p\u003e"
}
],
"value": "Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T02:35:35.525Z",
"orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
"shortName": "NetScaler"
},
"references": [
{
"url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Memory overflow vulnerability leading to Denial of Service",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
"assignerShortName": "NetScaler",
"cveId": "CVE-2026-88779",
"datePublished": "2026-10-04T02:35:35.525Z",
"dateReserved": "2026-09-10T07:14:57.370Z",
"dateUpdated": "2026-10-04T02:35:35.525Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105097 (GCVE-0-2026-105097)
Vulnerability from cvelistv5 – Published: 2026-10-04 02:00 – Updated: 2026-10-04 02:00
VLAI
EPSS
VEX
Title
Omega Solution CoinEx Crypto Customer Information API customer-currency authorization
Summary
A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413346 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/413346/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105097 | third-party-advisory |
| https://vuldb.com/submit/894322 | third-party-advisory |
| https://github.com/4m3rr0r/PoCVulDb/issues/25 | exploitissue-tracking |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Omega Solution | CoinEx Crypto |
Affected:
2025
cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*"
],
"modules": [
"Customer Information API"
],
"product": "CoinEx Crypto",
"vendor": "Omega Solution",
"versions": [
{
"status": "affected",
"version": "2025"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "4m3rr0r (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T02:00:11.654Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413346 | Omega Solution CoinEx Crypto Customer Information API customer-currency authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/413346"
},
{
"name": "VDB-413346 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413346/cti"
},
{
"name": "CVE-2026-105097 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105097"
},
{
"name": "Submit #894322 | Omega Solution CoinEx Crypto latest Authorization Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894322"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/4m3rr0r/PoCVulDb/issues/25"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T11:48:29.000Z",
"value": "VulDB entry last update"
}
],
"title": "Omega Solution CoinEx Crypto Customer Information API customer-currency authorization",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105097",
"datePublished": "2026-10-04T02:00:11.654Z",
"dateReserved": "2026-10-03T09:42:57.966Z",
"dateUpdated": "2026-10-04T02:00:11.654Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105131 (GCVE-0-2026-105131)
Vulnerability from cvelistv5 – Published: 2026-10-04 01:20 – Updated: 2026-10-04 01:20
VLAI
EPSS
VEX
Title
mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint
Summary
ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.
Severity
5.4 (Medium)
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/mayswind/ezbookkeeping/securit… | vendor-advisory |
| https://github.com/mayswind/ezbookkeeping/commit/… | patch |
| https://github.com/mayswind/ezbookkeeping/release… | release-notes |
| https://github.com/mayswind/ezbookkeeping/blob/v2… | technical-description |
| https://github.com/mayswind/ezbookkeeping | product |
| https://www.vulncheck.com/advisories/mayswind-ezb… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| mayswind | ezBookkeeping |
Affected:
1.2.0 , < 2.0.1
(semver)
cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:* |
Date Public
2026-09-23 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/mayswind/ezbookkeeping",
"product": "ezBookkeeping",
"vendor": "mayswind",
"versions": [
{
"lessThan": "2.0.1",
"status": "affected",
"version": "1.2.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.0.1",
"versionStartIncluding": "1.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-09-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T01:20:29.985Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-wq25-mpcf-2mfc)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-wq25-mpcf-2mfc"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/mayswind/ezbookkeeping/commit/9a92b07be8a7034665abfdb35b036210a1d57bf9"
},
{
"name": "ezBookkeeping v2.0.1 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.1"
},
{
"name": "TokenRefreshHandler at v2.0.0",
"tags": [
"technical-description"
],
"url": "https://github.com/mayswind/ezbookkeeping/blob/v2.0.0/pkg/api/tokens.go#L327-L380"
},
{
"tags": [
"product"
],
"url": "https://github.com/mayswind/ezbookkeeping"
},
{
"name": "VulnCheck Advisory: mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-1.2.0-before-2.0.1-privilege-escalation-via-token-refresh-endpoint"
}
],
"title": "mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105131",
"datePublished": "2026-10-04T01:20:29.985Z",
"dateReserved": "2026-10-03T12:05:26.756Z",
"dateUpdated": "2026-10-04T01:20:29.985Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105096 (GCVE-0-2026-105096)
Vulnerability from cvelistv5 – Published: 2026-10-04 00:45 – Updated: 2026-10-04 00:45
VLAI
EPSS
VEX
Title
Omega Solution CoinEx Crypto Customer Profile API customer authorization
Summary
A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/413345 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/413345/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-105096 | third-party-advisory |
| https://vuldb.com/submit/894320 | third-party-advisory |
| https://github.com/4m3rr0r/PoCVulDb/issues/24 | exploitissue-tracking |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Omega Solution | CoinEx Crypto |
Affected:
2025
cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*"
],
"modules": [
"Customer Profile API"
],
"product": "CoinEx Crypto",
"vendor": "Omega Solution",
"versions": [
{
"status": "affected",
"version": "2025"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "4m3rr0r (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-04T00:45:15.381Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-413345 | Omega Solution CoinEx Crypto Customer Profile API customer authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/413345"
},
{
"name": "VDB-413345 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/413345/cti"
},
{
"name": "CVE-2026-105096 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-105096"
},
{
"name": "Submit #894320 | Omega Solution CoinEx Crypto latest Authorization Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894320"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/4m3rr0r/PoCVulDb/issues/24"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-10-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-10-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-10-03T11:48:25.000Z",
"value": "VulDB entry last update"
}
],
"title": "Omega Solution CoinEx Crypto Customer Profile API customer authorization",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-105096",
"datePublished": "2026-10-04T00:45:15.381Z",
"dateReserved": "2026-10-03T09:42:53.117Z",
"dateUpdated": "2026-10-04T00:45:15.381Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105130 (GCVE-0-2026-105130)
Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
VLAI
EPSS
VEX
Title
LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit
Summary
LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
Severity
CWE
- CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/pull/343 | patchissue-tracking |
| https://github.com/laradashboard/laradashboard/co… | patch |
| https://github.com/laradashboard/laradashboard/re… | release-notes |
| https://github.com/laradashboard/laradashboard | product |
| https://www.vulncheck.com/advisories/laradashboar… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| laradashboard | laradashboard |
Affected:
1.4.0 , < 1.4.8
(semver)
Unaffected: 1.4.8 (semver) cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* |
Date Public
2026-09-30 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/laradashboard/laradashboard",
"product": "laradashboard",
"vendor": "laradashboard",
"versions": [
{
"lessThan": "1.4.8",
"status": "affected",
"version": "1.4.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.4.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-367",
"description": "Time-of-check Time-of-use (TOCTOU) Race Condition",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T23:40:02.301Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-gw6g-9wx9-3fpj)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Auth/RegisterController.php#L175-L188"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/Auth/RegistrationGuardService.php#L77-L105"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/laradashboard/laradashboard/pull/343"
},
{
"tags": [
"patch"
],
"url": "https://github.com/laradashboard/laradashboard/commit/1bc7b7e2d32dd0bbee8f39a7ed8a3316ae657d50"
},
{
"name": "laradashboard v1.4.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/laradashboard/laradashboard"
},
{
"name": "VulnCheck Advisory: LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/laradashboard-1.4.0-before-1.4.8-race-condition-bypasses-per-ip-registration-limit"
}
],
"title": "LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105130",
"datePublished": "2026-10-03T23:40:02.301Z",
"dateReserved": "2026-10-03T12:05:26.756Z",
"dateUpdated": "2026-10-03T23:40:02.301Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105129 (GCVE-0-2026-105129)
Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
VLAI
EPSS
VEX
Title
LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API
Summary
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
Severity
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
9 references
| URL | Tags |
|---|---|
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/pull/340 | patchissue-tracking |
| https://github.com/laradashboard/laradashboard/co… | patch |
| https://github.com/laradashboard/laradashboard/re… | release-notes |
| https://github.com/laradashboard/laradashboard | product |
| https://www.vulncheck.com/advisories/laradashboar… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| laradashboard | laradashboard |
Affected:
0 , < 1.4.8
(semver)
Unaffected: 1.4.8 (semver) cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* |
Date Public
2026-10-01 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/laradashboard/laradashboard",
"product": "laradashboard",
"vendor": "laradashboard",
"versions": [
{
"lessThan": "1.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.4.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-10-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T23:40:01.650Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xgmw-7ppx-v7hq)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xgmw-7ppx-v7hq"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Api/SettingController.php#L23-L50"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Resources/SettingResource.php#L17-L26"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/SettingPolicy.php#L15-L34"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/laradashboard/laradashboard/pull/340"
},
{
"tags": [
"patch"
],
"url": "https://github.com/laradashboard/laradashboard/commit/532a10efd2cc1338ef3f59236f195df859b2dbe3"
},
{
"name": "laradashboard v1.4.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/laradashboard/laradashboard"
},
{
"name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-incorrect-authorization-exposes-secrets-via-settings-api"
}
],
"title": "LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105129",
"datePublished": "2026-10-03T23:40:01.650Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T23:40:01.650Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105128 (GCVE-0-2026-105128)
Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
VLAI
EPSS
VEX
Title
LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url
Summary
LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
Severity
5.4 (Medium)
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Assigner
References
9 references
| URL | Tags |
|---|---|
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/pull/341 | patchissue-tracking |
| https://github.com/laradashboard/laradashboard/co… | patch |
| https://github.com/laradashboard/laradashboard/re… | release-notes |
| https://github.com/laradashboard/laradashboard | product |
| https://www.vulncheck.com/advisories/laradashboar… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| laradashboard | laradashboard |
Affected:
0 , < 1.4.8
(semver)
Unaffected: 1.4.8 (semver) cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* |
Date Public
2026-09-30 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/laradashboard/laradashboard",
"product": "laradashboard",
"vendor": "laradashboard",
"versions": [
{
"lessThan": "1.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.4.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T23:40:01.065Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-j2vp-w788-8fcf)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/laradashboard/laradashboard/pull/341"
},
{
"tags": [
"patch"
],
"url": "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66"
},
{
"name": "laradashboard v1.4.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/laradashboard/laradashboard"
},
{
"name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url"
}
],
"title": "LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105128",
"datePublished": "2026-10-03T23:40:01.065Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T23:40:01.065Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105127 (GCVE-0-2026-105127)
Vulnerability from cvelistv5 – Published: 2026-10-03 23:40 – Updated: 2026-10-03 23:40
VLAI
EPSS
VEX
Title
LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints
Summary
LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
Severity
5.3 (Medium)
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
11 references
| URL | Tags |
|---|---|
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/pull/339 | patchissue-tracking |
| https://github.com/laradashboard/laradashboard/co… | patch |
| https://github.com/laradashboard/laradashboard/re… | release-notes |
| https://github.com/laradashboard/laradashboard | product |
| https://www.vulncheck.com/advisories/laradashboar… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| laradashboard | laradashboard |
Affected:
1.4.2 , < 1.4.8
(semver)
Unaffected: 1.4.8 (semver) cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* |
Date Public
2026-09-30 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/laradashboard/laradashboard",
"product": "laradashboard",
"vendor": "laradashboard",
"versions": [
{
"lessThan": "1.4.8",
"status": "affected",
"version": "1.4.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.4.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T23:40:00.470Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-v36p-8578-8gch)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch"
},
{
"name": "GitHub Security Advisory (GHSA-5hq2-r2f3-9vp9)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/laradashboard/laradashboard/pull/339"
},
{
"tags": [
"patch"
],
"url": "https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba"
},
{
"name": "laradashboard v1.4.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/laradashboard/laradashboard"
},
{
"name": "VulnCheck Advisory: LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints"
}
],
"title": "LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105127",
"datePublished": "2026-10-03T23:40:00.470Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T23:40:00.470Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105126 (GCVE-0-2026-105126)
Vulnerability from cvelistv5 – Published: 2026-10-03 23:39 – Updated: 2026-10-03 23:39
VLAI
EPSS
VEX
Title
LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
Summary
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Severity
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
10 references
| URL | Tags |
|---|---|
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/pull/344 | patchissue-tracking |
| https://github.com/laradashboard/laradashboard/co… | patch |
| https://github.com/laradashboard/laradashboard/re… | release-notes |
| https://github.com/laradashboard/laradashboard | product |
| https://www.vulncheck.com/advisories/laradashboar… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| laradashboard | laradashboard |
Affected:
0 , < 1.4.8
(semver)
Unaffected: 1.4.8 (semver) cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* |
Date Public
2026-09-30 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/laradashboard/laradashboard",
"product": "laradashboard",
"vendor": "laradashboard",
"versions": [
{
"lessThan": "1.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.4.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T23:39:59.775Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-555v-6rfr-r969)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-555v-6rfr-r969"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L144"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/RoleController.php#L180"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Policies/RolePolicy.php#L39-L50"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/CoreUpgrade/UploadRequest.php#L23"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/laradashboard/laradashboard/pull/344"
},
{
"tags": [
"patch"
],
"url": "https://github.com/laradashboard/laradashboard/commit/286f150e4d0c924ec1ce7eb256b2326e871e9517"
},
{
"name": "laradashboard v1.4.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/laradashboard/laradashboard"
},
{
"name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-privilege-escalation-via-superadmin-role-tampering"
}
],
"title": "LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105126",
"datePublished": "2026-10-03T23:39:59.775Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T23:39:59.775Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105125 (GCVE-0-2026-105125)
Vulnerability from cvelistv5 – Published: 2026-10-03 23:39 – Updated: 2026-10-03 23:39
VLAI
EPSS
VEX
Title
LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
Summary
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Severity
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/laradashboard/laradashboard/se… | vendor-advisory |
| https://github.com/laradashboard/laradashboard/bl… | technical-description |
| https://github.com/laradashboard/laradashboard/pull/350 | patchissue-tracking |
| https://github.com/laradashboard/laradashboard/co… | patch |
| https://github.com/laradashboard/laradashboard/re… | release-notes |
| https://github.com/laradashboard/laradashboard | product |
| https://www.vulncheck.com/advisories/laradashboar… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| laradashboard | laradashboard |
Affected:
0 , < 1.4.8
(semver)
Unaffected: 1.4.8 (semver) cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:* |
Date Public
2026-10-01 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/laradashboard/laradashboard",
"product": "laradashboard",
"vendor": "laradashboard",
"versions": [
{
"lessThan": "1.4.8",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.4.8",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.4.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "EVIL0RD"
}
],
"datePublic": "2026-10-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T23:39:59.168Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-43jp-66c9-7cgh)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/laradashboard/laradashboard/pull/350"
},
{
"tags": [
"patch"
],
"url": "https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e"
},
{
"name": "laradashboard v1.4.8 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8"
},
{
"tags": [
"product"
],
"url": "https://github.com/laradashboard/laradashboard"
},
{
"name": "VulnCheck Advisory: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint"
}
],
"title": "LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105125",
"datePublished": "2026-10-03T23:39:59.168Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T23:39:59.168Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105124 (GCVE-0-2026-105124)
Vulnerability from cvelistv5 – Published: 2026-10-03 22:30 – Updated: 2026-10-03 22:30
VLAI
EPSS
VEX
Title
W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments
Summary
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
Severity
6.1 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/vincent-peugnet/wcms/issues/662 | issue-tracking |
| https://github.com/vincent-peugnet/wcms | product |
| https://github.com/vincent-peugnet/wcms/blob/cda5… | technical-description |
| https://github.com/vincent-peugnet/wcms/blob/cda5… | technical-description |
| https://github.com/vincent-peugnet/wcms/blob/cda5… | technical-description |
| https://www.vulncheck.com/advisories/w-wcms-throu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| vincent-peugnet | wcms |
Affected:
0 , ≤ 3.18.0
(semver)
cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:* |
Date Public
2026-10-02 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "wcms",
"vendor": "vincent-peugnet",
"versions": [
{
"lessThanOrEqual": "3.18.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.18.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ikram-4"
}
],
"datePublic": "2026-10-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T22:30:13.022Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #662",
"tags": [
"issue-tracking"
],
"url": "https://github.com/vincent-peugnet/wcms/issues/662"
},
{
"tags": [
"product"
],
"url": "https://github.com/vincent-peugnet/wcms"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerconnect.php#L56"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/adminlog.php#L71"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/editrightbar.php#L110"
},
{
"name": "VulnCheck Advisory: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-unauthenticated-stored-xss-via-login-username-and-comments"
}
],
"title": "W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105124",
"datePublished": "2026-10-03T22:30:13.022Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T22:30:13.022Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105123 (GCVE-0-2026-105123)
Vulnerability from cvelistv5 – Published: 2026-10-03 22:30 – Updated: 2026-10-03 22:30
VLAI
EPSS
VEX
Title
W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API
Summary
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path].
Severity
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/vincent-peugnet/wcms/issues/662 | issue-tracking |
| https://github.com/vincent-peugnet/wcms | product |
| https://github.com/vincent-peugnet/wcms/blob/cda5… | technical-description |
| https://github.com/vincent-peugnet/wcms/blob/cda5… | technical-description |
| https://www.vulncheck.com/advisories/w-wcms-throu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| vincent-peugnet | wcms |
Affected:
0 , ≤ 3.18.0
(semver)
cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:* |
Date Public
2026-10-02 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "wcms",
"vendor": "vincent-peugnet",
"versions": [
{
"lessThanOrEqual": "3.18.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.18.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "ikram-4"
}
],
"datePublic": "2026-10-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T22:30:12.394Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #662",
"tags": [
"issue-tracking"
],
"url": "https://github.com/vincent-peugnet/wcms/issues/662"
},
{
"tags": [
"product"
],
"url": "https://github.com/vincent-peugnet/wcms"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerapimedia.php#L24-L44"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Media.php#L98"
},
{
"name": "VulnCheck Advisory: W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-rce-and-arbitrary-file-write-via-media-upload-api"
}
],
"title": "W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105123",
"datePublished": "2026-10-03T22:30:12.394Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T22:30:12.394Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96451 (GCVE-0-2026-96451)
Vulnerability from cvelistv5 – Published: 2026-10-03 15:08 – Updated: 2026-10-03 15:08 X_Open Source
VLAI
EPSS
VEX
Title
WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
Summary
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Severity
8.8 (High)
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Ultimate Member | Ultimate Member |
Affected:
0 , ≤ 2.13.1
(custom)
|
Date Public
2026-10-01 14:14
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "ultimate-member",
"product": "Ultimate Member",
"vendor": "Ultimate Member",
"versions": [
{
"changes": [
{
"at": "2.14.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "2.13.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Intrudify | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-01T14:14:29.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.\u003cp\u003eThis issue affects Ultimate Member: from n/a through 2.13.1.\u003c/p\u003e"
}
],
"value": "Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:08:13.855Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/ultimate-member/vulnerability/wordpress-ultimate-member-plugin-2-13-1-privilege-escalation-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Ultimate Member plugin to the latest available version (at least 2.14.0)."
}
],
"value": "Update the WordPress Ultimate Member plugin to the latest available version (at least 2.14.0)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Ultimate Member plugin \u003c= 2.13.1 - Privilege Escalation vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-96451",
"datePublished": "2026-10-03T15:08:13.855Z",
"dateReserved": "2026-09-23T09:45:05.264Z",
"dateUpdated": "2026-10-03T15:08:13.855Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103342 (GCVE-0-2026-103342)
Vulnerability from cvelistv5 – Published: 2026-10-03 14:00 – Updated: 2026-10-03 15:12 X_Open Source
VLAI
EPSS
VEX
Title
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability
Summary
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:09 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) |
Affected:
0 , ≤ 2.0.20
(custom)
|
Date Public
2026-10-01 13:58
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103342",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:09:54.625208Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:12:23.526Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "unlimited-elements-for-elementor",
"product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
"vendor": "Unlimited Elements",
"versions": [
{
"changes": [
{
"at": "2.0.21",
"status": "unaffected"
}
],
"lessThanOrEqual": "2.0.20",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nh4tvd | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-01T13:58:58.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.\u003cp\u003eThis issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.\u003c/p\u003e"
}
],
"value": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20."
}
],
"impacts": [
{
"capecId": "CAPEC-591",
"descriptions": [
{
"lang": "en",
"value": "Reflected XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T14:00:11.382Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/unlimited-elements-for-elementor/vulnerability/wordpress-unlimited-elements-for-elementor-free-widgets-addons-templates-plugin-2-0-20-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21)."
}
],
"value": "Update the WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin to the latest available version (at least 2.0.21)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin \u003c= 2.0.20 - Cross Site Scripting (XSS) vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103342",
"datePublished": "2026-10-03T14:00:11.382Z",
"dateReserved": "2026-09-30T12:43:33.093Z",
"dateUpdated": "2026-10-03T15:12:23.526Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103065 (GCVE-0-2026-103065)
Vulnerability from cvelistv5 – Published: 2026-10-03 14:00 – Updated: 2026-10-03 15:12 X_Open Source
VLAI
EPSS
VEX
Title
WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability
Summary
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
Severity
8.2 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:10 UTC
CWE
- CWE-1284 - Improper Validation of Specified Quantity in Input
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
Date Public
2026-10-01 13:48
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103065",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:10:09.710037Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:12:23.648Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "kirki",
"product": "Kirki",
"vendor": "Themeum",
"versions": [
{
"changes": [
{
"at": "6.3.2",
"status": "unaffected"
}
],
"lessThanOrEqual": "6.3.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Dthangws | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-10-01T13:48:44.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.\u003cp\u003eThis issue affects Kirki: from n/a through 6.3.1.\u003c/p\u003e"
}
],
"value": "Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1284",
"description": "Improper Validation of Specified Quantity in Input",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T14:00:11.348Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-3-1-arbitrary-code-execution-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Kirki plugin to the latest available version (at least 6.3.2)."
}
],
"value": "Update the WordPress Kirki plugin to the latest available version (at least 6.3.2)."
}
],
"tags": [
"x_open-source"
],
"title": "WordPress Kirki plugin \u003c= 6.3.1 - Arbitrary Code Execution vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-103065",
"datePublished": "2026-10-03T14:00:11.348Z",
"dateReserved": "2026-09-30T00:15:58.644Z",
"dateUpdated": "2026-10-03T15:12:23.648Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105122 (GCVE-0-2026-105122)
Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
VLAI
EPSS
VEX
Title
OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri
Summary
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
Severity
5.4 (Medium)
CWE
- CWE-918 - Server-Side Request Forgery (SSRF)
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/OpenIdentityPlatform/OpenAM/se… | vendor-advisory |
| https://www.vulncheck.com/advisories/openam-befor… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| OpenIdentityPlatform | OpenAM |
Affected:
0 , < 16.1.3
(semver)
Unaffected: 16.1.3 (semver) cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:* |
Date Public
2026-09-18 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "arpitjain099"
},
{
"lang": "en",
"type": "reporter",
"value": "santhreal"
},
{
"lang": "en",
"type": "reporter",
"value": "alex-sc"
},
{
"lang": "en",
"type": "reporter",
"value": "jamesbishup"
},
{
"lang": "en",
"type": "reporter",
"value": "ayhambashtawi2-lang"
},
{
"lang": "en",
"type": "finder",
"value": "maximthomas"
},
{
"lang": "en",
"type": "finder",
"value": "tsujiguchitky"
}
],
"datePublic": "2026-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-918",
"description": "Server-Side Request Forgery (SSRF)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T12:14:45.551Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-g7cv-hh35-cc7c)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-g7cv-hh35-cc7c"
},
{
"name": "VulnCheck Advisory: OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-ssrf-via-openid-connect-client-jwks-uri"
}
],
"title": "OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105122",
"datePublished": "2026-10-03T12:14:45.551Z",
"dateReserved": "2026-10-03T12:05:26.755Z",
"dateUpdated": "2026-10-03T12:14:45.551Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105121 (GCVE-0-2026-105121)
Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
VLAI
EPSS
VEX
Title
OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping
Summary
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Severity
4.9 (Medium)
CWE
- CWE-285 - Improper Authorization
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/OpenIdentityPlatform/OpenAM/se… | vendor-advisory |
| https://www.vulncheck.com/advisories/openam-befor… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| OpenIdentityPlatform | OpenAM |
Affected:
0 , < 16.1.3
(semver)
Unaffected: 16.1.3 (semver) cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:* |
Date Public
2026-09-18 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "arpitjain099"
},
{
"lang": "en",
"type": "finder",
"value": "maximthomas"
},
{
"lang": "en",
"type": "finder",
"value": "tsujiguchitky"
}
],
"datePublic": "2026-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester\u0027s realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T12:14:44.905Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-hmwh-9r8r-44gw)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw"
},
{
"name": "VulnCheck Advisory: OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping"
}
],
"title": "OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105121",
"datePublished": "2026-10-03T12:14:44.905Z",
"dateReserved": "2026-10-03T12:04:36.964Z",
"dateUpdated": "2026-10-03T12:14:44.905Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105120 (GCVE-0-2026-105120)
Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
VLAI
EPSS
VEX
Title
OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
Summary
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
Severity
4.9 (Medium)
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/OpenIdentityPlatform/OpenAM/se… | vendor-advisory |
| https://www.vulncheck.com/advisories/openam-befor… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| OpenIdentityPlatform | OpenAM |
Affected:
0 , < 16.1.3
(semver)
Unaffected: 16.1.3 (semver) |
Date Public
2026-09-18 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core-rest",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "vharseko"
},
{
"lang": "en",
"type": "finder",
"value": "maximthomas"
},
{
"lang": "en",
"type": "finder",
"value": "tsujiguchitky"
}
],
"datePublic": "2026-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T12:14:44.244Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-x8cj-3hqv-cgwh)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-x8cj-3hqv-cgwh"
},
{
"name": "VulnCheck Advisory: OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-cross-realm-session-disclosure-via-sessions-rest-endpoint"
}
],
"title": "OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105120",
"datePublished": "2026-10-03T12:14:44.244Z",
"dateReserved": "2026-10-03T12:04:36.964Z",
"dateUpdated": "2026-10-03T12:14:44.244Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105119 (GCVE-0-2026-105119)
Vulnerability from cvelistv5 – Published: 2026-10-03 12:14 – Updated: 2026-10-03 12:14
VLAI
EPSS
VEX
Title
OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows
Summary
OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
Severity
CWE
- CWE-285 - Improper Authorization
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/OpenIdentityPlatform/OpenAM/se… | vendor-advisory |
| https://www.vulncheck.com/advisories/openam-befor… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| OpenIdentityPlatform | OpenAM |
Affected:
0 , < 16.1.3
(semver)
Unaffected: 16.1.3 (semver) cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:* |
Date Public
2026-09-18 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:maven/org.openidentityplatform.openam/openam-oauth2",
"product": "OpenAM",
"vendor": "OpenIdentityPlatform",
"versions": [
{
"lessThan": "16.1.3",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "16.1.3",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "arpitjain099"
},
{
"lang": "en",
"type": "finder",
"value": "maximthomas"
},
{
"lang": "en",
"type": "finder",
"value": "tsujiguchitky"
}
],
"datePublic": "2026-09-18T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client\u0027s tokens with any non-empty code_verifier."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T12:14:43.643Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-5p2f-7vcr-6vfh)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-5p2f-7vcr-6vfh"
},
{
"name": "VulnCheck Advisory: OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-pkce-enforcement-bypass-via-oauth-2.0-hybrid-flows"
}
],
"title": "OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-105119",
"datePublished": "2026-10-03T12:14:43.643Z",
"dateReserved": "2026-10-03T12:04:36.964Z",
"dateUpdated": "2026-10-03T12:14:43.643Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}