π¨ CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
π@cveNotify
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.
π@cveNotify
π¨ CVE-2026-19264
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. An unauthenticated remote attacker can therefore read any file readable by the application process, including the process environment, which exposes the JWT signing secret, the database connection string, and connected provider and billing secrets. Because session tokens are signed with that secret and carry no expiry, this allows forging a non-expiring session as any user, including an administrator, without a password.
π@cveNotify
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. An unauthenticated remote attacker can therefore read any file readable by the application process, including the process environment, which exposes the JWT signing secret, the database connection string, and connected provider and billing secrets. Because session tokens are signed with that secret and carry no expiry, this allows forging a non-expiring session as any user, including an administrator, without a password.
π@cveNotify
Postiz Security Advisories
PSA-2026-TH12B7: Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeoverβ¦
π¨ CVE-2026-15554
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
π@cveNotify
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
π@cveNotify
π¨ CVE-2026-15555
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering β enabling RCE via deserialization gadget chains on every cluster node.
π@cveNotify
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering β enabling RCE via deserialization gadget chains on every cluster node.
π@cveNotify
π¨ CVE-2026-15556
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
π@cveNotify
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.
π@cveNotify
π¨ CVE-2026-15561
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
π@cveNotify
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
π@cveNotify
π¨ CVE-2026-15562
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.
π@cveNotify
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.
π@cveNotify
π¨ CVE-2026-15563
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
π@cveNotify
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
π@cveNotify
π¨ CVE-2026-15565
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
π@cveNotify
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
π@cveNotify
π¨ CVE-2026-15567
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
π@cveNotify
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.
π@cveNotify
π¨ CVE-2026-78337
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
π@cveNotify
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
π@cveNotify
GitHub
fix(security): prevent SVG XSS in company logo upload (CWE-434/CWE-79β¦ Β· Roskus/prospero-flow-crm@aaa4fc7
β¦) (#267)
- Add CompanySaveRequest FormRequest with proper file validation
- Restrict logo uploads to: jpeg, jpg, png, webp, svg
- Add max file size of 2MB
- Create ValidateSafeSvg rule to prevent...
- Add CompanySaveRequest FormRequest with proper file validation
- Restrict logo uploads to: jpeg, jpg, png, webp, svg
- Add max file size of 2MB
- Create ValidateSafeSvg rule to prevent...
π¨ CVE-2025-63080
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
π@cveNotify
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
π@cveNotify
cert.pl
Vulnerabilities in KAON PG5298A/PG5298B routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2025-63080 and CVE-2026-6017) found in KAON PG5298A/PG5298B routers.
π¨ CVE-2026-28153
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
π@cveNotify
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Notification Master β Real-Time WordPress Notifications With Email, SMS, Webhooks & More Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-28162
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Events Made Easy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-28166
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Tourmaster Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-28167
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
π@cveNotify
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
π@cveNotify
Patchstack
Arbitrary File Download in WordPress Super Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-28171
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
π@cveNotify
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
π@cveNotify
Patchstack
Arbitrary File Deletion in WordPress WooCommerce File Approval Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-28190
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
π@cveNotify
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress ProLancer Element Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.