VYPR

CVEs

385,816 total · page 519 of 7,717

  • CVE-2026-72837HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.01

    File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the…

  • CVE-2026-72836HigAug 14, 2026
    risk 0.46cvss 8.1epss 0.01

    FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two…

  • CVE-2026-72835MedAug 14, 2026
    risk 0.37cvss 6.8epss 0.01

    filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path…

  • CVE-2026-72834MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and…

  • CVE-2026-72833HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints (in GroupsController,…

  • CVE-2026-72832MedAug 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which cannot cross the first literal `>`; when a…

  • CVE-2026-72831HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.01

    The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin…

  • CVE-2026-72830HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. The scope cap is applied only inside requirePermission(), while the scheduler and backups gates use a bare…

  • CVE-2026-72829HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that…

  • CVE-2026-72828HigAug 14, 2026
    risk 0.40cvss 7.2epss 0.00

    Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check rather than a scope-aware permission check, so a least-privilege API key…

  • CVE-2026-72827HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the unsandboxed find filter in email…

  • CVE-2026-72826HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.00

    The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's…

  • CVE-2026-72825HigAug 14, 2026
    risk 0.42cvss 7.6epss 0.00

    The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmin() check instead of…

  • CVE-2026-72824HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-privilege API key scoped only to…

  • CVE-2026-72823MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes cap (enforced only in…

  • CVE-2026-72822HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.01

    The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads…

  • CVE-2026-72821MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in…

  • CVE-2026-72820MedAug 14, 2026
    risk 0.25cvss 4.9epss 0.01

    Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose…

  • CVE-2026-72819HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array…

  • CVE-2026-72817MedAug 14, 2026
    risk 0.35cvss 6.5epss 0.00

    go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a…

  • CVE-2026-72816MedAug 14, 2026
    risk 0.35cvss 6.5epss 0.00

    go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request…

  • CVE-2026-72815MedAug 14, 2026
    risk 0.38cvss —epss 0.01

    go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting…

  • CVE-2026-72814MedAug 14, 2026
    risk 0.34cvss —epss 0.00

    The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the service then joins the request path with this…

  • CVE-2026-72813MedAug 14, 2026
    risk 0.38cvss —epss 0.00

    actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.

  • CVE-2026-72812MedAug 14, 2026
    risk 0.35cvss 6.5epss 0.00

    SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush…

  • CVE-2026-72811CriAug 14, 2026
    risk 0.58cvss 10.0epss 0.00

    SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while…

  • CVE-2026-72810HigAug 14, 2026
    risk 0.49cvss 8.6epss 0.01

    SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content…

  • CVE-2026-19822HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may…

  • CVE-2025-71405MedAug 14, 2026
    risk 0.26cvss —epss 0.00

    chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and…

  • CVE-2026-19821HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer…

  • CVE-2026-19815HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer…

  • CVE-2026-19814HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to…

  • CVE-2026-19813HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The…

  • CVE-2026-19812HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible…

  • CVE-2026-19794HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

  • CVE-2026-19811HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The…

  • CVE-2026-19617MedAug 14, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM…

  • CVE-2026-18039HigAug 14, 2026
    risk 0.53cvss 8.1epss 0.00

    The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites…

  • CVE-2026-16810MedAug 14, 2026
    risk 0.42cvss 6.5epss 0.00

    The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the…

  • CVE-2026-16739MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as…

  • CVE-2026-15205HigAug 14, 2026
    risk 0.56cvss 8.6epss 0.00

    The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature.…

  • CVE-2026-14290MedAug 14, 2026
    risk 0.44cvss 6.8epss 0.00

    The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user,…

  • CVE-2026-12949CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter…

  • CVE-2026-12743MedAug 14, 2026
    risk 0.32cvss 4.9epss 0.00

    The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack…

  • CVE-2026-19792HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal…

  • CVE-2026-19791HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer…

  • CVE-2025-10308MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-19790HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer…

  • CVE-2026-19789HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based…

  • CVE-2026-19788HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The…