Skip to content

Menu
  • Home
Menu

CVE-2026-52777 – YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize

Posted on September 5, 2026

CVE ID :CVE-2026-52777 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object…

CVE-2026-52775 – YesWiki Authenticated SQL Injection in ReactionManager

Posted on September 5, 2026

CVE ID :CVE-2026-52775 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch…

CVE-2026-52771 – YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)

Posted on September 5, 2026

CVE ID :CVE-2026-52771 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a…

CVE-2026-52769 – YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`

Posted on September 5, 2026

CVE ID :CVE-2026-52769 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox…

CVE-2026-52767 – YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(…)` accepting `int(-1)`

Posted on September 5, 2026

CVE ID :CVE-2026-52767 Published : Sept. 5, 2026, 12:17 a.m. | 20 minutes ago Description :YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the…

CVE-2026-67402 – ConfigServer Security & Firewall Remote Command Execution Vulnerability

Posted on September 4, 2026

CVE ID :CVE-2026-67402 Published : Sept. 4, 2026, 12:17 a.m. | 20 minutes ago Description :An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3…

CVE-2026-67398 – WHMCS 2Checkout Payment Gateway Missing Authorization Vulnerability

Posted on September 4, 2026

CVE ID :CVE-2026-67398 Published : Sept. 4, 2026, 12:17 a.m. | 20 minutes ago Description :Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0…

CVE-2026-67397 – Plesk Path Traversal Arbitrary Code Execution

Posted on September 4, 2026

CVE ID :CVE-2026-67397 Published : Sept. 4, 2026, 12:17 a.m. | 20 minutes ago Description :Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code…

CVE-2026-85455 – MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet

Posted on September 4, 2026

CVE ID :CVE-2026-85455 Published : Sept. 3, 2026, 11:17 p.m. | 1 hour, 20 minutes ago Description :MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds…

CVE-2026-85452 – MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers

Posted on September 4, 2026

CVE ID :CVE-2026-85452 Published : Sept. 3, 2026, 11:17 p.m. | 1 hour, 20 minutes ago Description :MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable…

Posts pagination

1 2 … 139 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme