Vulnérabilités
Aggrégat CVE / GHSA / KEV / OSV — filtrage par étiquette et catégorie.
| ID | Titre | |
|---|---|---|
| MINI-x924-whjr-9g39 |
|
MINI-x924-whjr-9g39 |
| MINI-7277-6wp3-wfmv |
|
MINI-7277-6wp3-wfmv |
| MINI-j77x-868w-frr6 |
|
MINI-j77x-868w-frr6 |
| MINI-5hpq-82jx-6v5m |
|
MINI-5hpq-82jx-6v5m |
| MINI-g6xq-p8mp-w5fh |
|
MINI-g6xq-p8mp-w5fh |
| MINI-5rc9-3ww9-6rf3 |
|
MINI-5rc9-3ww9-6rf3 |
| MINI-w58r-37wm-39q5 |
|
MINI-w58r-37wm-39q5 |
| MINI-j8vp-57wg-c2m3 |
|
MINI-j8vp-57wg-c2m3 |
| MINI-c9xm-qxvc-gqrp |
|
MINI-c9xm-qxvc-gqrp |
| MINI-qh5w-wv3v-pw57 |
|
MINI-qh5w-wv3v-pw57 |
| MINI-f6wq-pxxc-5g6r |
|
MINI-f6wq-pxxc-5g6r |
| MINI-jvp7-mpxq-xgg4 |
|
MINI-jvp7-mpxq-xgg4 |
| MINI-mfwc-hqfv-c7cw |
|
MINI-mfwc-hqfv-c7cw |
| MINI-rc4j-736h-p8wr |
|
MINI-rc4j-736h-p8wr |
| MINI-9qrq-x9f4-p9pr |
|
MINI-9qrq-x9f4-p9pr |
| MINI-4x3c-jr92-fjx4 |
|
MINI-4x3c-jr92-fjx4 |
| MINI-6cmp-9cqc-g9j3 |
|
MINI-6cmp-9cqc-g9j3 |
| MINI-7425-wwpc-w9fx |
|
MINI-7425-wwpc-w9fx |
| MINI-v8fj-rmfr-ffj7 |
|
MINI-v8fj-rmfr-ffj7 |
| MINI-9fgx-xw8p-8xhv |
|
MINI-9fgx-xw8p-8xhv |
| MINI-59fp-gm3c-xxfc |
|
MINI-59fp-gm3c-xxfc |
| MINI-x8x4-pqwv-mj2q |
|
MINI-x8x4-pqwv-mj2q |
| MINI-g9cj-8353-j6p4 |
|
MINI-g9cj-8353-j6p4 |
| MINI-5p85-xhvh-74rm |
|
MINI-5p85-xhvh-74rm |
| MINI-wxr8-m859-4cwf |
|
MINI-wxr8-m859-4cwf |
| MINI-fmxm-hmcx-4crm |
|
MINI-fmxm-hmcx-4crm |
| MINI-5273-3r85-6wg3 |
|
MINI-5273-3r85-6wg3 |
| CVE-2026-53639 |
|
Vulnérabilité dans sylius/sylius (CVE-2026-53639)
vulnérabilité dans sylius/sylius (CVE-2026-53639). Risque d'opérations non autorisées ou de divulgation. Exploitable via `GET /api/v2/shop/payment-requests/{hash}`. Atténuation : mise à jour vers `2.2.6` ou plus.
|
| CVE-2026-53638 |
|
Autorisation incorrecte dans sylius/sylius (CVE-2026-53638)
vulnérabilité dans sylius/sylius (CVE-2026-53638). Risque d'opérations non autorisées ou de divulgation. Exploitable via `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}`. Atténuation : mise à jour vers `2.2.6` ou plus.
|
| CVE-2026-53637 |
|
Vulnérabilité dans sylius/sylius (CVE-2026-53637)
vulnérabilité dans sylius/sylius (CVE-2026-53637). Les données peuvent être altérées par des attaquants. Exploitable via ``sylius_shop.twig.component.cart.form``. Atténuation : mise à jour vers `2.2.6` ou plus.
|
| CVE-2026-52777 |
|
CSRF dans yeswiki/yeswiki (CVE-2026-52777)
vulnérabilité dans yeswiki/yeswiki (CVE-2026-52777). Risque d'opérations non autorisées ou de divulgation. Exploitable via ``__toString``. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CVE-2026-52775 |
|
Injection SQL dans yeswiki/yeswiki (CVE-2026-52775)
injection SQL dans yeswiki/yeswiki (CVE-2026-52775). L'exploitation peut entraîner la prise de contrôle totale du système. Exploitable via `DELETE /wiki/`. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CGA-6hp4-wmm6-xmhx |
|
CGA-6hp4-wmm6-xmhx |
| CGA-2pq2-9pxf-cx2v |
|
CGA-2pq2-9pxf-cx2v |
| CGA-6gq4-7j23-q32x |
|
CGA-6gq4-7j23-q32x |
| CVE-2026-52774 |
|
Vulnérabilité dans yeswiki/yeswiki (CVE-2026-52774)
vulnérabilité dans yeswiki/yeswiki (CVE-2026-52774). Risque d'opérations non autorisées ou de divulgation. Exploitable via ``GET``. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CGA-989q-cj77-mfj4 |
|
CGA-989q-cj77-mfj4 |
| CGA-p6mr-jp48-f5w4 |
|
CGA-p6mr-jp48-f5w4 |
| CVE-2026-52773 |
|
Vulnérabilité dans yeswiki/yeswiki (CVE-2026-52773)
vulnérabilité dans yeswiki/yeswiki (CVE-2026-52773). Risque d'opérations non autorisées ou de divulgation. Exploitable via ``time``. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CGA-73vv-v952-w33p |
|
CGA-73vv-v952-w33p |
| CVE-2026-52772 |
|
Vulnérabilité dans yeswiki/yeswiki (CVE-2026-52772)
vulnérabilité dans yeswiki/yeswiki (CVE-2026-52772). Risque d'opérations non autorisées ou de divulgation. Exploitable via ``field.label``. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CGA-pfh4-493r-7grq |
|
CGA-pfh4-493r-7grq |
| CGA-vmf9-6g69-cr86 |
|
CGA-vmf9-6g69-cr86 |
| CGA-hwpx-w437-xc4c |
|
CGA-hwpx-w437-xc4c |
| CGA-h7r2-rvm8-qp8v |
|
CGA-h7r2-rvm8-qp8v |
| CGA-x32j-mgqx-57q3 |
|
CGA-x32j-mgqx-57q3 |
| CVE-2026-52771 |
|
Injection SQL dans yeswiki/yeswiki (CVE-2026-52771)
injection SQL dans yeswiki/yeswiki (CVE-2026-52771). Des informations confidentielles peuvent être exposées. Exploitable via `POST /api/pages/{tag}`. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CVE-2026-52770 |
|
Injection SQL dans yeswiki/yeswiki (CVE-2026-52770)
injection SQL dans yeswiki/yeswiki (CVE-2026-52770). Des informations confidentielles peuvent être exposées. Exploitable via ``query``. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CVE-2026-52769 |
|
SSRF (Falsification de requête côté serveur) dans yeswiki/yeswiki (CVE-2026-52769)
SSRF dans yeswiki/yeswiki (CVE-2026-52769). Risque d'opérations non autorisées ou de divulgation. Exploitable via `POST /api/forms/{formId}/actor/inbox`. Atténuation : mise à jour vers `4.6.6` ou plus.
|
| CVE-2026-52767 |
|
Vulnérabilité dans yeswiki/yeswiki (CVE-2026-52767)
vulnérabilité dans yeswiki/yeswiki (CVE-2026-52767). Les données peuvent être altérées par des attaquants. Exploitable via `POST /api/forms/{enabled-form-id}/actor/inbox`. Atténuation : mise à jour vers `4.6.6` ou plus.
|