CVE tracker
393 subscribers
5.78K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-105113 - Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock

CVE ID :CVE-2026-105113
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105114 - OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page

CVE ID :CVE-2026-105114
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105115 - OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface

CVE ID :CVE-2026-105115
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105116 - OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page

CVE ID :CVE-2026-105116
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105117 - OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions

CVE ID :CVE-2026-105117
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105118 - OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession

CVE ID :CVE-2026-105118
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105119 - OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows

CVE ID :CVE-2026-105119
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105120 - OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint

CVE ID :CVE-2026-105120
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105121 - OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

CVE ID :CVE-2026-105121
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105122 - OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri

CVE ID :CVE-2026-105122
Published : Oct. 3, 2026, 2:16 p.m. | 1 hour, 40 minutes ago
Description :OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103065 - WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability

CVE ID :CVE-2026-103065
Published : Oct. 3, 2026, 3:16 p.m. | 40 minutes ago
Description :Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103342 - WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-103342
Published : Oct. 3, 2026, 3:16 p.m. | 40 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96451 - WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

CVE ID :CVE-2026-96451
Published : Oct. 3, 2026, 4:16 p.m. | 3 hours, 42 minutes ago
Description :Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105123 - W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API

CVE ID :CVE-2026-105123
Published : Oct. 3, 2026, 10:30 p.m. | 1 hour, 29 minutes ago
Description :W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path].
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105124 - W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments

CVE ID :CVE-2026-105124
Published : Oct. 3, 2026, 10:30 p.m. | 1 hour, 29 minutes ago
Description :W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105125 - LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint

CVE ID :CVE-2026-105125
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105126 - LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering

CVE ID :CVE-2026-105126
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105127 - LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints

CVE ID :CVE-2026-105127
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105128 - LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url

CVE ID :CVE-2026-105128
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105129 - LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API

CVE ID :CVE-2026-105129
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105130 - LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit

CVE ID :CVE-2026-105130
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...