CVE tracker
395 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-82383 - Apache Roller: Anonymous setup action allows frontpage configuration tampering

CVE ID :CVE-2026-82383
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default configuration is required; the result can redirect or break the site's public frontpage, with administrative recovery available. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts the write to global administrators.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82384 - Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint

CVE ID :CVE-2026-82384
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82385 - Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files

CVE ID :CVE-2026-82385
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to load a classpath resource outside the theme namespace. Roller treats weblog administrators as untrusted and enables a Velocity sandbox, but the include and parse directives are not confined by it. No non-default configuration is required; this affects any weblog whose administrator can author templates. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which confines includes to the active theme and removes classpath resource loading from weblog rendering.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82386 - Apache Roller: XML external entity processing in OPML bookmark import

CVE ID :CVE-2026-82386
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator bookmark-import action. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which uses a hardened parser that disables external entities and document type declarations.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82387 - Apache Roller: Stored cross-site scripting via uploaded media content type

CVE ID :CVE-2026-82387
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82546 - Apache Roller: Stored cross-site scripting through incoming Trackback links

CVE ID :CVE-2026-82546
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91204 - Apache Roller: Stored javascript: URI in HTML comments

CVE ID :CVE-2026-91204
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91206 - Apache Roller: Reflected XSS in the optional LDAP comment authenticator

CVE ID :CVE-2026-91206
Published : Sept. 28, 2026, 8:16 a.m. | 1 hour, 9 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94282 - Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion

CVE ID :CVE-2026-94282
Published : Sept. 28, 2026, 8:18 a.m. | 1 hour, 8 minutes ago
Description :An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82969 - Stored XSS in BİMSER's eBA Plus

CVE ID :CVE-2026-82969
Published : Sept. 28, 2026, 8:24 a.m. | 1 hour, 1 minute ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86507 - Apache Roller: Stored XSS in comment moderation via comment author URL

CVE ID :CVE-2026-86507
Published : Sept. 28, 2026, 8:27 a.m. | 59 minutes ago
Description :Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85134 - Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus

CVE ID :CVE-2026-85134
Published : Sept. 28, 2026, 8:28 a.m. | 57 minutes ago
Description :Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101015 - Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in input

CVE ID :CVE-2026-101015
Published : Sept. 28, 2026, 8:30 a.m. | 56 minutes ago
Description :A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82915 - Path Traversal in Bimser Solution Software's eBA Plus

CVE ID :CVE-2026-82915
Published : Sept. 28, 2026, 8:32 a.m. | 54 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94283 - Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser

CVE ID :CVE-2026-94283
Published : Sept. 28, 2026, 8:34 a.m. | 52 minutes ago
Description :An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94284 - Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser

CVE ID :CVE-2026-94284
Published : Sept. 28, 2026, 8:42 a.m. | 43 minutes ago
Description :An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101016 - Trusted Domain Project OpenDMARC opendmarc_policy.c opendmarc_policy_parse_dmarc exceptional condition

CVE ID :CVE-2026-101016
Published : Sept. 28, 2026, 8:45 a.m. | 41 minutes ago
Description :A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94285 - Out-of-bounds read in libX11's byte-oriented codeset parser

CVE ID :CVE-2026-94285
Published : Sept. 28, 2026, 8:45 a.m. | 40 minutes ago
Description :An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94286 - Out-of-bounds read in libXtst's RECORD reply parser

CVE ID :CVE-2026-94286
Published : Sept. 28, 2026, 8:50 a.m. | 35 minutes ago
Description :An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94287 - Denial of service via unsigned underflow in libXpm's write path

CVE ID :CVE-2026-94287
Published : Sept. 28, 2026, 8:57 a.m. | 29 minutes ago
Description :A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101017 - Trusted Domain Project OpenDMARC opendmarc_policy.c strcasecmp exceptional condition

CVE ID :CVE-2026-101017
Published : Sept. 28, 2026, 9 a.m. | 26 minutes ago
Description :A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...