CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-85657 - Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.15.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'profile_fields_user_email_value_prefix' Parameter

CVE ID :CVE-2026-85657
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on a link.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90843 - SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection

CVE ID :CVE-2026-90843
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 3d52f65803a2716bff14d938352c6fef45b0cfb6. A patch should be applied to remediate this issue. This issue got fixed with a silent patch.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90844 - PHPGurukul Daily Expense Tracker System Login index.php sql injection

CVE ID :CVE-2026-90844
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90845 - PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting

CVE ID :CVE-2026-90845
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90846 - PHPGurukul Daily Expense Tracker System forgot-password.php sql injection

CVE ID :CVE-2026-90846
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90847 - EFM ipTIME C200E System Setup iux_set.cgi os command injection

CVE ID :CVE-2026-90847
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91750 - WeKnora before 0.7.0 SSRF via Unvalidated HTTP Redirects

CVE ID :CVE-2026-91750
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation by supplying a public URL that redirects to internal network addresses, allowing access to internal services and cloud metadata.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91751 - Flextype CMS through 1.0.0-alpha.3 Path Traversal via Entries REST API

CVE ID :CVE-2026-91751
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91752 - GNU libextractor before 1.15 Stack Overflow via OLE2

CVE ID :CVE-2026-91752
Published : Sept. 15, 2026, 1:16 a.m. | 46 minutes ago
Description :GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91770 - IceHRM before 36.0.0 Broken Access Control via Employee ID

CVE ID :CVE-2026-91770
Published : Sept. 15, 2026, 1:20 a.m. | 42 minutes ago
Description :IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91771 - Weights & Biases wandb before 0.29.0 Path Traversal via File Download

CVE ID :CVE-2026-91771
Published : Sept. 15, 2026, 1:20 a.m. | 42 minutes ago
Description :Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import paths.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91772 - Halo through 2.26.1 Open Redirect via Unvalidated URI Parameter

CVE ID :CVE-2026-91772
Published : Sept. 15, 2026, 1:20 a.m. | 42 minutes ago
Description :Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91773 - Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks

CVE ID :CVE-2026-91773
Published : Sept. 15, 2026, 1:20 a.m. | 42 minutes ago
Description :Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps from private repositories.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91774 - Yao through v1.0.0-rc22 Missing Authorization via OpenAPI team endpoint

CVE ID :CVE-2026-91774
Published : Sept. 15, 2026, 1:20 a.m. | 42 minutes ago
Description :Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records. Attackers can supply a known team identifier to retrieve sensitive team data including name, description, owner information, and settings without membership verification.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90849 - SourceCodester College Notes Gallery Management System login.php sql injection

CVE ID :CVE-2026-90849
Published : Sept. 15, 2026, 1:30 a.m. | 33 minutes ago
Description :A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90850 - PHPGurukul Hostel Management System manage-students.php cross site scripting

CVE ID :CVE-2026-90850
Published : Sept. 15, 2026, 1:45 a.m. | 18 minutes ago
Description :A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88261 - Bizwell xClick Stored Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-88261
Published : Sept. 15, 2026, 3:17 a.m. | 2 hours, 46 minutes ago
Description :Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88262 - bizwell xClick Insufficient Session Expiration Authentication Bypass

CVE ID :CVE-2026-88262
Published : Sept. 15, 2026, 3:17 a.m. | 2 hours, 46 minutes ago
Description :Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90852 - luben zstd-jni Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDict use after free

CVE ID :CVE-2026-90852
Published : Sept. 15, 2026, 3:17 a.m. | 2 hours, 46 minutes ago
Description :A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.7-14 is able to resolve this issue. The name of the patch is a560131d7834598afd9cea6b7c107bc88e915936. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90854 - SourceCodester/katojkalemba Online Food Ordering System category-foods.php sql injection

CVE ID :CVE-2026-90854
Published : Sept. 15, 2026, 3:17 a.m. | 2 hours, 46 minutes ago
Description :A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-90855 - SourceCodester/katojkalemba Online Food Ordering System order.php sql injection

CVE ID :CVE-2026-90855
Published : Sept. 15, 2026, 3:17 a.m. | 2 hours, 46 minutes ago
Description :A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...