🌐

Web Application

slug: web-application

🛡 Related vulnerabilities 283

ID Title
CVE-2026-67623 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
CVE-2026-71288 Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
CVE-2026-71287 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
CVE-2026-71280 go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71272 Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-71259 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-55739 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
CVE-2026-54418 Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
CVE-2026-18859 A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
CVE-2026-17347 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
CVE-2026-17346 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON /...
CVE-2026-44097 A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
CVE-2026-44098 This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
CVE-2026-6267 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
CVE-2026-5490 DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote...
CVE-2026-67428 Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
CVE-2026-67424 Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
CVE-2026-67201 V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass...
CVE-2026-65443 Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65447 Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-65446 Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →