π¨ CVE-2026-76596
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76597
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76598
Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76601
Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76602
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76604
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76605
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
π@cveNotify
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76606
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
π@cveNotify
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76607
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
π@cveNotify
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76608
Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-76609
Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-77027
Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.
π@cveNotify
Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-77992
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
π@cveNotify
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
π@cveNotify
Fabrikar
Fabrik - Joomla Custom Website Application Builder - Home
Fabrik, is an open source application development, form and database management component.
π¨ CVE-2026-4703
The WS Form LITE β Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
π@cveNotify
The WS Form LITE β Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
π@cveNotify
π¨ CVE-2026-47895
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
π@cveNotify
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
π@cveNotify
GitHub
Release strongSwan 6.0.7 Β· strongswan/strongswan
Vulnerabilities
CVE-2026-47895 - Fixed a vulnerability in libstrongswan related to the cloning of certain identities that can result in an double-free and potentially remote code execution. Affec...
CVE-2026-47895 - Fixed a vulnerability in libstrongswan related to the cloning of certain identities that can result in an double-free and potentially remote code execution. Affec...
π¨ CVE-2026-18027
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key.
π@cveNotify
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key.
π@cveNotify
π¨ CVE-2026-78136
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
π@cveNotify
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.
π@cveNotify
GitHub
GitHub - cduram/CHIRP-CodeExecution_via_Malicious_ImageFile: Arbitrary Code Execution via eval() in Kenwood ITM Driver
Arbitrary Code Execution via eval() in Kenwood ITM Driver - cduram/CHIRP-CodeExecution_via_Malicious_ImageFile
π¨ CVE-2026-10053
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
π@cveNotify
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
π@cveNotify
GitLab
GitLab.org / GitLab Β· GitLab
GitLab is the open-source DevSecOps platform that provides a complete software development lifecycle toolchain including source control, CI/CD, security scanning, and project management in a single application.
π¨ CVE-2026-78155
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
π@cveNotify
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
π@cveNotify
GitLab
tenant DB-owner to pod RCE via metrics-exporter superuser dblink with unpinned search_path (#3177) Β· Issues Β· OnGres Inc. / StackGresβ¦
Summary The StackGres metrics exporter connects to PostgreSQL as the cluster SUPERUSER with no role demotion, and fans...
π¨ CVE-2026-78169
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
π@cveNotify
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
π@cveNotify
GitHub
CVE-VUL/107.md at main Β· 7wkajk/CVE-VUL
Contribute to 7wkajk/CVE-VUL development by creating an account on GitHub.
π¨ CVE-2026-66897
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
π@cveNotify
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.
π@cveNotify
GitHub
Instance template path traversal allows arbitrary host file write as root
### Summary
A path traversal in the instance template code lets a user with `can_edit` on a single container write files anywhere on the host as root. The template target path from `metadata.yam...
A path traversal in the instance template code lets a user with `can_edit` on a single container write files anywhere on the host as root. The template target path from `metadata.yam...