Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2026-48900 Vulnerability in joomla (CVE-2026-48900)
vulnerability in joomla (CVE-2026-48900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48901 Vulnerability in joomla (CVE-2026-48901)
vulnerability in joomla (CVE-2026-48901). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48902 Vulnerability in joomla (CVE-2026-48902)
vulnerability in joomla (CVE-2026-48902). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
CVE-2026-40384 Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
CVE-2026-35220 Cross-Site Request Forgery (CSRF) in joomla (CVE-2026-35220)
vulnerability in joomla (CVE-2026-35220). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
CVE-2026-35221 SQL Injection in joomla (CVE-2026-35221)
SQL injection in joomla (CVE-2026-35221). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links
Joomla! Core - [20260504] - XSS in readmore links
CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules
Joomla! Core - [20260501] - XSS in feed modules
CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations
Joomla! Core - [20260502] - XSS in com_associations
CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory
Joomla! Core - [20260503] - XSS in com_contenthistory
CVE-2026-40564 Vulnerability in apache (CVE-2026-40564)
vulnerability in apache (CVE-2026-40564). Confidential information can be exposed externally.
CVE-2026-8174 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-8174)
vulnerability in wordpress (CVE-2026-8174). Data can be tampered with by attackers.
CVE-2026-43828 Vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828)
vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-44598 Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-43827 Vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827)
vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-48589 Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-42782 Vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782)
vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-42797 Vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797)
vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-46745 Vulnerability in apache-airflow-providers-fab (CVE-2026-46745)
vulnerability in apache-airflow-providers-fab (CVE-2026-46745). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.4` or later.
CVE-2026-45361 Vulnerability in apache-airflow-providers-google (CVE-2026-45361)
vulnerability in apache-airflow-providers-google (CVE-2026-45361). Successful exploitation can lead to full system takeover. Exploitable via ``ComputeEngineSSHHook``. Mitigation: upgrade to `22.0.0` or later.
CVE-2026-45249 Cross-Site Scripting (XSS) in echarts (CVE-2026-45249)
cross-site scripting in echarts (CVE-2026-45249). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.0` or later.
CVE-2026-9374 Vulnerability in vue (CVE-2026-9374)
vulnerability in vue (CVE-2026-9374). Risk of unauthorized operations or information disclosure.
CVE-2026-9349 Information Disclosure in react (CVE-2026-9349)
vulnerability in react (CVE-2026-9349). Risk of unauthorized operations or information disclosure.
CVE-2018-25347 SQL Injection in wordpress (CVE-2018-25347)
SQL injection in wordpress (CVE-2018-25347). Confidential information can be exposed externally.
CVE-2018-25352 SQL Injection in wordpress (CVE-2018-25352)
SQL injection in wordpress (CVE-2018-25352). Confidential information can be exposed externally.
CVE-2018-25346 SQL Injection in wordpress (CVE-2018-25346)
SQL injection in wordpress (CVE-2018-25346). Confidential information can be exposed externally.
CVE-2026-6898 Privilege Escalation in wordpress (CVE-2026-6898)
vulnerability in wordpress (CVE-2026-6898). Successful exploitation can lead to full system takeover.
CVE-2026-9284 Vulnerability in wordpress (CVE-2026-9284)
vulnerability in wordpress (CVE-2026-9284). Confidential information can be exposed externally.
CVE-2026-6419 Privilege Escalation in wordpress (CVE-2026-6419)
vulnerability in wordpress (CVE-2026-6419). Successful exploitation can lead to full system takeover.
CVE-2026-6895 Privilege Escalation in wordpress (CVE-2026-6895)
vulnerability in wordpress (CVE-2026-6895). Successful exploitation can lead to full system takeover.
CVE-2026-6897 Privilege Escalation in wordpress (CVE-2026-6897)
vulnerability in wordpress (CVE-2026-6897). Successful exploitation can lead to full system takeover.
CVE-2026-8347 Vulnerability in concrete5/concrete5 (CVE-2026-8347)
vulnerability in concrete5/concrete5 (CVE-2026-8347). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.5.1` or later.
CVE-2026-9256 Vulnerability in nginx (CVE-2026-9256)
vulnerability in nginx (CVE-2026-9256). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.0, 1.30.2, 1.31.1` or later.
CVE-2026-44930 Vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930)
vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
CVE-2026-44618 XXE (XML External Entity) in org.apache.cxf:cxf-rt-ws-transfer (CVE-2026-44618)
vulnerability in org.apache.cxf:cxf-rt-ws-transfer (CVE-2026-44618). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.11` or later.
CVE-2026-44417 Vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-44417)
vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-44417). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
CVE-2026-46715 Authentication Bypass in Flask-Security-Too (CVE-2026-46715)
authentication bypass in Flask-Security-Too (CVE-2026-46715). Risk of unauthorized operations or information disclosure. Exploitable via `POST /change-username`. Mitigation: upgrade to `5.8.1` or later.
CVE-2026-7615 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7615)
vulnerability in wordpress (CVE-2026-7615). Risk of unauthorized operations or information disclosure.
CVE-2026-7636 Information Disclosure in wordpress (CVE-2026-7636)
vulnerability in wordpress (CVE-2026-7636). Risk of unauthorized operations or information disclosure.
CVE-2026-8679 Vulnerability in wordpress (CVE-2026-8679)
vulnerability in wordpress (CVE-2026-8679). Confidential information can be exposed externally.
CVE-2026-7798 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-7798)
SSRF in wordpress (CVE-2026-7798). Risk of unauthorized operations or information disclosure.
CVE-2026-8684 Vulnerability in wordpress (CVE-2026-8684)
vulnerability in wordpress (CVE-2026-8684). Risk of unauthorized operations or information disclosure.
CVE-2026-8692 Vulnerability in wordpress (CVE-2026-8692)
vulnerability in wordpress (CVE-2026-8692). Risk of unauthorized operations or information disclosure.
CVE-2026-9011 Vulnerability in wordpress (CVE-2026-9011)
vulnerability in wordpress (CVE-2026-9011). Confidential information can be exposed externally.
CVE-2026-9018 Privilege Escalation in wordpress (CVE-2026-9018)
vulnerability in wordpress (CVE-2026-9018). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_eel_register``.
CVE-2026-9104 Cross-Site Scripting (XSS) in wordpress (CVE-2026-9104)
cross-site scripting in wordpress (CVE-2026-9104). Risk of unauthorized operations or information disclosure.
CVE-2026-4070 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-4070)
vulnerability in wordpress (CVE-2026-4070). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →