Author SQL Injection in FluentCRM Pro <= 3
Description
Author SQL Injection in FluentCRM Pro <= 3
AI Analyst Comment
Remediation
Apply vendor patches immediately. Review database access controls and enable query logging.
Search and filter 23295 vulnerabilities with AI analyst insights
Author SQL Injection in FluentCRM Pro <= 3
Author SQL Injection in FluentCRM Pro <= 3
Apply vendor patches immediately. Review database access controls and enable query logging.
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1
---METADATA---
VENDOR: Extend
PRODUCT: Lead Generation Contact Widget & AI Chatbot (SiteLeads)
AFFECTED_VERSIONS: n/a through 1.2.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The SiteLeads WordPress plugin is vulnerable to unauthenticated sensitive data exposure, allowing unauthorized access to system information via the plugin's interface.
Executive Summary:
A critical unauthenticated information disclosure vulnerability in the SiteLeads WordPress plugin exposes sensitive system data, posing a significant risk of reconnaissance and potential further exploitation.
Vulnerability Details
CVE-ID: CVE-2026-78268
Affected Software: Extend Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads
Affected Versions: n/a through 1.2.0
Vulnerability: The plugin suffers from an exposure of sensitive system information (CWE-497), which can be triggered by an unauthenticated attacker via a network-based request.
Business Impact
Successful exploitation allows unauthorized parties to harvest sensitive system information, which facilitates targeted attacks against the hosting environment. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent the compromise of infrastructure details that could lead to full system takeover.
Remediation Plan
Immediate Action: Update the SiteLeads plugin to version 1.2.1 or later immediately.
Proactive Monitoring: Review web server access logs for unusual traffic patterns or unauthorized requests directed at plugin-specific endpoints.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized access to the plugin directory and sensitive API endpoints until the update is applied.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 25, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's unauthenticated nature makes it highly accessible to automated scanners.
Analyst Recommendation
The vulnerability presents a clear risk to data confidentiality and infrastructure security. Administrators must prioritize updating to version 1.2.1 to close this exposure vector and prevent potential reconnaissance activities.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The TranslatePress WordPress plugin contains an unauthenticated privilege escalation vulnerability, allowing remote attackers to gain unauthorized adm...
The TranslatePress WordPress plugin contains an unauthenticated privilege escalation vulnerability, allowing remote attackers to gain unauthorized administrative access.
---METADATA---
VENDOR: Cozmoslabs
PRODUCT: TranslatePress
AFFECTED_VERSIONS: n/a through 3.3.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The TranslatePress WordPress plugin contains an unauthenticated privilege escalation vulnerability, allowing remote attackers to gain unauthorized administrative access.
Executive Summary:
A critical privilege escalation flaw in the TranslatePress WordPress plugin allows unauthenticated attackers to obtain unauthorized administrative privileges.
Vulnerability Details
CVE-ID: CVE-2026-78267
Affected Software: Cozmoslabs TranslatePress
Affected Versions: n/a through 3.3.2
Vulnerability: This vulnerability involves incorrect privilege assignment (CWE-266) within the TranslatePress plugin. It permits an unauthenticated attacker to escalate their privileges to an administrative level, effectively granting them full control over the affected WordPress installation.
Business Impact
A successful exploit provides an attacker with complete control over the WordPress site, leading to potential data theft, site defacement, or the installation of malicious software. With a CVSS score of 9.8, this vulnerability poses an extreme risk to the integrity and availability of the entire web platform.
Remediation Plan
Immediate Action: Update the TranslatePress plugin to version 3.3.3 or the latest available version immediately.
Proactive Monitoring: Audit user account creation logs for suspicious administrative account activity or unauthorized modifications to site configurations.
Compensating Controls: Utilize a Web Application Firewall (WAF) to detect and block common privilege escalation patterns targeting WordPress plugins.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of Aug 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly severe because it allows for total system compromise without any prior authentication.
Analyst Recommendation
Given the critical severity of this privilege escalation flaw, immediate remediation is required. Organizations should update the plugin without delay to prevent potential site takeover and ensure that all administrative accounts are reviewed for signs of unauthorized activity.
Update Cozmoslabs TranslatePress to the latest version. Monitor for exploitation attempts and review access logs.
The Events Calendar plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing remote attackers to execute arbitrary code.
The Events Calendar plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing remote attackers to execute arbitrary code.
---METADATA---
VENDOR: Nexcess
PRODUCT: The Events Calendar
AFFECTED_VERSIONS: n/a through 6.17.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The Events Calendar plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing remote attackers to execute arbitrary code.
Executive Summary:
A critical PHP object injection vulnerability in Nexcess The Events Calendar allows unauthenticated attackers to achieve remote code execution.
Vulnerability Details
CVE-ID: CVE-2026-78265
Affected Software: Nexcess The Events Calendar
Affected Versions: n/a through 6.17.2
Vulnerability: This vulnerability is a deserialization of untrusted data (CWE-502) flaw within the plugin, which permits unauthenticated attackers to inject malicious PHP objects into the application.
Business Impact
Successful exploitation of this flaw allows an unauthenticated attacker to execute arbitrary code on the underlying server, leading to a full system compromise. Given the CVSS score of 9.8, this vulnerability poses an extreme risk to data confidentiality, integrity, and availability, potentially resulting in complete site takeover and unauthorized access to sensitive database information.
Remediation Plan
Immediate Action: Update the WordPress The Events Calendar plugin to version 6.17.3 or the latest available version immediately.
Proactive Monitoring: Review web server access logs for anomalous requests containing serialized PHP strings or unusual POST payloads directed at plugin endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious deserialization attempts and common PHP object injection patterns.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Aug 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous because it requires no user interaction or authentication to trigger.
Analyst Recommendation
The severity of this vulnerability cannot be overstated given its potential for unauthenticated remote code execution. Administrators must prioritize updating the affected plugin to version 6.17.3 or higher to close the deserialization vector and prevent potential compromise.
Update Nexcess The Events Calendar to the latest version. Monitor for exploitation attempts and review access logs.
The WP Project Manager plugin for WordPress contains an unauthenticated PHP object injection vulnerability that can lead to remote code execution.
The WP Project Manager plugin for WordPress contains an unauthenticated PHP object injection vulnerability that can lead to remote code execution.
---METADATA---
VENDOR: weDevs
PRODUCT: WP Project Manager
AFFECTED_VERSIONS: <= 4.0.6
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The WP Project Manager plugin for WordPress contains an unauthenticated PHP object injection vulnerability that can lead to remote code execution.
Executive Summary:
A critical unauthenticated PHP object injection vulnerability in the weDevs WP Project Manager plugin enables potential remote code execution on affected systems.
Vulnerability Details
CVE-ID: CVE-2026-78262
Affected Software: weDevs WP Project Manager
Affected Versions: <= 4.0.6
Vulnerability: The plugin fails to validate user input during deserialization processes. This allows an unauthenticated attacker to inject malicious PHP objects, which can be leveraged to execute arbitrary code.
Business Impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it permits full system compromise without requiring any prior authentication. Successful exploitation would grant an attacker complete control over the WordPress environment, leading to total data loss, malware installation, or persistent backdoors.
Remediation Plan
Immediate Action: Update the WP Project Manager plugin to version 4.0.7 or the latest available version immediately.
Proactive Monitoring: Audit the server for unexpected file modifications or the creation of new, unrecognized files within the WordPress directory, which are common indicators of post-exploitation activity.
Compensating Controls: Utilize a Web Application Firewall (WAF) configured to inspect and block serialized PHP objects in incoming HTTP requests.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of Aug 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. PHP object injection is a high-impact vulnerability class that should be addressed immediately due to its potential for remote code execution.
Analyst Recommendation
Due to the critical nature of remote code execution vulnerabilities, immediate patching is required. Organizations should treat this as a high-priority security event and ensure that all instances of the WP Project Manager plugin are updated to the secure version.
Update weDevs WP Project Manager to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
---METADATA---
VENDOR: MagePeopleTeam
PRODUCT: Booking and Rental Manager for WooCommerce
AFFECTED_VERSIONS: n/a through 2.7.5
CONFIDENCE: high
MISSING: none
CREDITS: daroo | Patchstack Bug Bounty Program (finder)
SOURCES_JSON: [{"url":"https://patchstack.com/database/wordpress/plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-booking-and-rental-manager-plugin-2-7-5-php-object-injection-vulnerability?_s_id=cve","name":null,"tags":["vdb-entry"]}]
---END_METADATA---
Description Summary:
The Booking and Rental Manager plugin for WordPress is vulnerable to PHP object injection, allowing authenticated contributors to execute arbitrary code.
Executive Summary:
A critical PHP object injection vulnerability in the Booking and Rental Manager plugin allows authenticated contributors to achieve full system compromise.
Vulnerability Details
CVE-ID: CVE-2026-78257
Affected Software: MagePeopleTeam Booking and Rental Manager for WooCommerce
Affected Versions: n/a through 2.7.5
Vulnerability: This vulnerability is a deserialization of untrusted data (CWE-502). It permits an authenticated user with contributor-level access to inject malicious PHP objects, which can lead to remote code execution.
Business Impact
The exploitation of this vulnerability poses a severe risk to organizational infrastructure, as it allows for unauthorized remote code execution on the host server. Given the CVSS score of 8.8, this flaw could result in complete data loss, unauthorized access to sensitive customer information, and potential lateral movement within the network. The ability for a contributor to escalate privileges to the server level makes this a high-priority threat to business continuity and data integrity.
Remediation Plan
Immediate Action: Update the Booking and Rental Manager for WooCommerce plugin to version 2.7.6 or later immediately.
Proactive Monitoring: Review web server logs for suspicious POST requests containing serialized PHP objects or anomalous behavior originating from contributor-level accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common PHP deserialization patterns to provide temporary protection until the patch is applied.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 28, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While exploitation requires contributor-level access, the impact is significant, and the vulnerability is inherently dangerous due to the nature of insecure deserialization.
Analyst Recommendation
Organizations utilizing the Booking and Rental Manager plugin must prioritize this update to prevent potential remote code execution. Given the high severity of this flaw, security teams should audit all user accounts with contributor privileges to ensure no unauthorized access is being leveraged while the remediation process is completed.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client
---METADATA---
VENDOR: DJI
PRODUCT: Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2
AFFECTED_VERSIONS: DJI Neo: 0-01.00.0400; DJI Neo 2: 0-01.00.0500; DJI Flip: 0-01.00.1200; DJI Air 3: 0-01.00.1600; DJI Air 3S: 0-01.00.1400; DJI Avata 2: 0-01.00.0400
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The HTTP media server in multiple DJI drone models lacks authentication, allowing unauthenticated attackers to access stored photos and videos via the /v2 endpoint.
Executive Summary:
A critical authentication bypass in the DJI drone media server allows unauthorized access to sensitive media files by unauthenticated network attackers.
Vulnerability Details
CVE-ID: CVE-2026-78255
Affected Software: DJI Neo, Neo 2, Flip, Air 3, Air 3S, and Avata 2
Affected Versions: DJI Neo: 0 through 01.00.0400; DJI Neo 2: 0 through 01.00.0500; DJI Flip: 0 through 01.00.1200; DJI Air 3: 0 through 01.00.1600; DJI Air 3S: 0 through 01.00.1400; DJI Avata 2: 0 through 01.00.0400
Vulnerability: This is a missing authentication vulnerability (CWE-306) affecting the HTTP media server. An unauthenticated attacker can query the /v2 endpoint to retrieve sensitive media content stored on the device.
Business Impact
Successful exploitation poses a significant risk to data privacy and operational security. Unauthorized access to drone media could lead to the exposure of sensitive imagery, proprietary data, or reconnaissance material, causing potential reputational damage. With a CVSS score of 8.7, this is a high-severity risk that requires immediate attention to protect captured data.
Remediation Plan
Immediate Action: Update all affected drone firmware to the latest available version provided by the manufacturer.
Proactive Monitoring: Monitor network traffic to drone devices for unusual HTTP GET requests directed at the /v2 path.
Compensating Controls: Ensure drone devices are operated within secure, private network segments where unauthorized network access is strictly restricted.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the lack of access controls on a publicly reachable service.
Analyst Recommendation
Given the high CVSS score and the sensitive nature of the data stored on these devices, organizations should prioritize firmware updates. Ensure that all drone units are patched to the latest version to close this unauthenticated access vector immediately.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
DJI drones contain an FTP service with hardcoded credentials that allows unauthorized file uploads and storage exhaustion, potentially disabling criti...
DJI drones contain an FTP service with hardcoded credentials that allows unauthorized file uploads and storage exhaustion, potentially disabling critical flight logging and firmware update capabilities.
---METADATA---
VENDOR: DJI
PRODUCT: Neo
AFFECTED_VERSIONS: DJI Neo: 0 through 01.00.0400, DJI Neo 2: 0 through 01.00.0500, DJI Flip: 0 through 01.00.1200, DJI Air 3: 0 through 01.00.1600, DJI Air 3S: 0 through 01.00.1400, DJI Avata 2: 0 through 01.00.0400
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
DJI drones contain an FTP service with hardcoded credentials that allows unauthorized file uploads and storage exhaustion, potentially disabling critical flight logging and firmware update capabilities.
Executive Summary:
Multiple DJI drone models are affected by a critical vulnerability involving hardcoded credentials in the FTP service, allowing attackers to disrupt device functionality and persistence.
Vulnerability Details
CVE-ID: CVE-2026-78251
Affected Software: DJI (various models including Neo, Air, Avata, and Mavic series)
Affected Versions: Multiple versions across several drone models (see enrichment data for specific ranges).
Vulnerability: The vulnerability stems from the use of hardcoded credentials within the drone FTP service. This allows an unauthenticated attacker, with access to the local network or USB RNDIS interface, to upload arbitrary files, overwrite system files, and cause storage exhaustion that persists across device reboots and resets.
Business Impact
Exploitation of this vulnerability poses a significant risk to the operational reliability of the drones. By exhausting storage, an attacker can prevent the recording of flight telemetry and logs, which may be required for regulatory compliance or incident investigation. With a CVSS score of 9.3, the potential for persistent system disruption is extremely high and could lead to total loss of device control or inability to perform safety-critical firmware updates.
Remediation Plan
Immediate Action: Apply the latest firmware updates provided by DJI for the specific drone model immediately.
Proactive Monitoring: Restrict access to the drone's network interfaces and monitor for any unauthorized connections to the FTP service.
Compensating Controls: If firmware updates cannot be applied immediately, ensure the drone is not exposed to untrusted networks or physical access interfaces that could allow unauthorized FTP connections.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of Aug 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The use of hardcoded credentials is a severe design flaw that simplifies potential attack vectors significantly.
Analyst Recommendation
Due to the critical nature of this vulnerability and the potential for persistent impact on device operation, users must verify their drone model firmware versions against the vendor list and apply updates without delay.
Update DJI Neo to the latest version. Monitor for exploitation attempts and review access logs.
The Xiiaozet LK100W device contains an authentication bypass vulnerability, allowing unauthenticated remote attackers to enable restricted administrat...
The Xiiaozet LK100W device contains an authentication bypass vulnerability, allowing unauthenticated remote attackers to enable restricted administrative services.
---METADATA---
VENDOR: Xiiaozet
PRODUCT: Xiiaozet LK100W
AFFECTED_VERSIONS: 0 up to (excluding) 2.1.240
CONFIDENCE: high
MISSING: none
CREDITS: Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA. (finder)
SOURCES_JSON: [{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01","name":null,"tags":[]},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json","name":null,"tags":[]}]
---END_METADATA---
Description Summary:
The Xiiaozet LK100W device contains an authentication bypass vulnerability, allowing unauthenticated remote attackers to enable restricted administrative services.
Executive Summary:
A critical authentication bypass in the Xiiaozet LK100W allows unauthorized remote attackers to enable administrative services, potentially leading to full device compromise.
Vulnerability Details
CVE-ID: CVE-2026-78239
Affected Software: Xiiaozet Xiiaozet LK100W
Affected Versions: 0 up to (excluding) 2.1.240
Vulnerability: This vulnerability, categorized as CWE-306 (Missing Authentication for Critical Function), allows an unauthenticated remote attacker to invoke management functions that should be restricted. By bypassing necessary access controls, an attacker can activate administrative services on the device.
Business Impact
The severity of this flaw is reflected in its CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation could grant an attacker full control over the affected device, potentially leading to unauthorized data access, service disruption, or the device being leveraged as a pivot point within the internal network.
Remediation Plan
Immediate Action: Update the Xiiaozet LK100W firmware to version 2.1.240 or later to remediate the authentication bypass.
Proactive Monitoring: Review system and access logs for unusual administrative service activation or unauthorized connection attempts from unknown IP addresses.
Compensating Controls: Deploy network-level access controls or a Web Application Firewall to restrict access to the device management interface to trusted management subnets only.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of Aug 27, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly dangerous due to the lack of required authentication, which lowers the barrier for entry for remote attackers significantly.
Analyst Recommendation
Given the critical nature of this vulnerability and the potential for total device compromise, immediate action is required. Organizations utilizing the Xiiaozet LK100W must prioritize the firmware update to version 2.1.240. If an immediate update is not feasible, the device should be isolated from public-facing networks until the patch is applied.
Update Xiiaozet Xiiaozet LK100W to the latest version. Monitor for exploitation attempts and review access logs.
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process C...
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process
---METADATA---
VENDOR: Admin By Request
PRODUCT: Admin By Request (ABR)
AFFECTED_VERSIONS: 5.2.2 and below
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An insecure PIN derivation mechanism in Admin By Request allows a low-privileged user to escalate privileges to administrator by masquerading as an Apple-signed process via XPC.
Executive Summary:
A high severity privilege escalation vulnerability in Admin By Request allows local users to gain administrative rights by abusing the PIN derivation process.
Vulnerability Details
CVE-ID: CVE-2026-78236
Affected Software: Admin By Request (ABR)
Affected Versions: 5.2.2 and below
Vulnerability: This vulnerability stems from an insecure PIN derivation mechanism that allows a low-privileged local user to manipulate Cross-Process Communication (XPC). By masquerading as a trusted Apple-signed process, the attacker can successfully escalate to administrative privileges.
Business Impact
The CVSS score of 8.8 highlights the critical nature of this privilege escalation flaw. An attacker who has already gained low-privileged access to a system can leverage this vulnerability to assume full administrative control, leading to complete system compromise and potential lateral movement across the network.
Remediation Plan
Immediate Action: Update the Admin By Request application to the latest version provided by the vendor to remediate the PIN derivation flaw.
Proactive Monitoring: Monitor system logs for unauthorized attempts to initiate XPC communications or unexpected privilege escalation events.
Compensating Controls: Restrict local user account permissions and enforce strict application control policies to limit the scope of potential local attacks.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 26, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. This flaw is particularly concerning because it allows a low-privileged user to bypass security boundaries on macOS systems.
Analyst Recommendation
Organizations using Admin By Request must treat this vulnerability with high urgency. Patching the software is the only definitive way to close the privilege escalation vector, and administrators should ensure all managed devices are updated immediately.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A remote OS command injection vulnerability in the Totolink A8000RU allows unauthenticated attackers to execute arbitrary commands via the `setAppFilt...
A remote OS command injection vulnerability in the Totolink A8000RU allows unauthenticated attackers to execute arbitrary commands via the `setAppFilterCfg` function.
---METADATA---
VENDOR: Totolink
PRODUCT: A8000RU
AFFECTED_VERSIONS: 7.1cu.643_b20200521
---END_METADATA---
Description Summary:
A remote OS command injection vulnerability in the Totolink A8000RU allows unauthenticated attackers to execute arbitrary commands via the setAppFilterCfg function.
Executive Summary:
A critical remote OS command injection vulnerability in Totolink A8000RU allows unauthenticated attackers to gain full control of the device.
Vulnerability Details
CVE-ID: CVE-2026-7823
Affected Software: Totolink A8000RU
Affected Versions: 7.1cu.643_b20200521
Vulnerability: The function setAppFilterCfg in /cgi-bin/cstecgi.cgi fails to sanitize the enable argument, leading to OS command injection. This allows an unauthenticated, remote attacker to execute arbitrary commands with system-level privileges.
Business Impact
A CVSS score of 9.8 highlights the extreme risk posed by this vulnerability. Total device compromise can lead to complete loss of network visibility, interception of sensitive data, and the use of the router as a foothold for further attacks against the internal network.
Remediation Plan
Immediate Action: Apply the latest firmware update provided by Totolink to patch the command injection flaw.
Proactive Monitoring: Monitor for unusual system processes or unexpected network traffic emanating from the router, which may indicate persistent command execution.
Compensating Controls: Restrict access to the router's web interface to trusted internal IP addresses only, preventing external exposure of the vulnerable CGI script.
Exploitation Status
Public Exploit Available: Yes
Analyst Notes: As of May 5, 2026, public exploits for this vulnerability are available, significantly increasing the risk of active exploitation.
Analyst Recommendation
The combination of RCE capability and public exploit availability makes this a high-priority threat. Administrators must act immediately to patch the affected devices or restrict network access to the management interface to neutralize the risk of exploitation.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Heptabase developed by Hepta Platforms, Inc
Heptabase developed by Hepta Platforms, Inc
---METADATA---
VENDOR: Hepta Platforms
PRODUCT: Heptabase
AFFECTED_VERSIONS: All versions
CONFIDENCE: high
MISSING: patch_status (specific version release date/details)
---END_METADATA---
Description Summary:
Heptabase contains a reflected cross-site scripting vulnerability that allows an authenticated user to execute malicious scripts in the context of other users.
Executive Summary:
A cross-site scripting vulnerability in Heptabase enables authenticated attackers to execute malicious scripts and potentially compromise user sessions.
Vulnerability Details
CVE-ID: CVE-2026-78213
Affected Software: Heptabase
Affected Versions: All versions
Vulnerability: This is a cross-site scripting vulnerability (CWE-79) resulting from improper neutralization of input during web page generation. The vulnerability requires the attacker to be authenticated and involves user interaction to trigger the malicious payload.
Business Impact
This vulnerability allows an attacker to inject scripts that could lead to session hijacking, unauthorized actions performed on behalf of a user, or the theft of sensitive information within the application. Given the CVSS score of 8.7, this represents a significant risk to the integrity and confidentiality of the collaborative environment.
Remediation Plan
Immediate Action: Upgrade Heptabase to version 1.93.1 or later to resolve the underlying input sanitization issues.
Proactive Monitoring: Review application logs for suspicious script injections or unusual user behavior patterns.
Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect incoming requests and filter out malicious script patterns.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability relies on successful authentication, which limits the initial attack surface.
Analyst Recommendation
Administrators must ensure that all instances of Heptabase are updated to version 1.93.1 or later. Immediate patching is recommended to prevent potential session compromise and unauthorized access within the platform.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
4MOSAn developed by 4MOSAn Security Technology Co
4MOSAn developed by 4MOSAn Security Technology Co
---METADATA---
VENDOR: 4MOSAn Security Technology Co
PRODUCT: 4MOSAn Management Center
AFFECTED_VERSIONS: 0 up to (excluding) 20260621
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The 4MOSAn Management Center is affected by a relative path traversal vulnerability, which may allow an unauthenticated attacker to access unauthorized files on the system.
Executive Summary:
A relative path traversal vulnerability in 4MOSAn Management Center versions prior to 20260621 allows unauthorized file access and poses a significant security risk.
Vulnerability Details
CVE-ID: CVE-2026-78212
Affected Software: 4MOSAn Security Technology 4MOSAn Management Center
Affected Versions: 0 up to (excluding) 20260621
Vulnerability: The product is susceptible to CWE-23 (Relative Path Traversal), which allows an unauthenticated, remote attacker to manipulate file paths and access sensitive information on the server.
Business Impact
Path traversal vulnerabilities can lead to the exposure of sensitive configuration files, source code, or internal system data. Given the CVSS score of 7.5, this vulnerability is considered high risk because it allows an unauthenticated attacker to bypass security controls and read arbitrary files from the filesystem, directly impacting the confidentiality of the affected infrastructure.
Remediation Plan
Immediate Action: Upgrade to version 20260621 or later and perform the necessary security upgrades for the FreeBSD-GCB Management Center.
Proactive Monitoring: Review server access logs for patterns indicative of directory traversal attempts, such as sequences containing dot-dot-slash.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block path traversal patterns in incoming HTTP requests.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit identified).
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the lack of required authentication for exploitation.
Analyst Recommendation
The vulnerability is urgent due to the lack of authentication required for exploitation. Administrators must apply the vendor-provided patch immediately to prevent unauthorized access to the underlying system files.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An OS command injection vulnerability in 4MOSAn GCB Doctor allows unauthenticated remote attackers to execute arbitrary system commands via a test pag...
An OS command injection vulnerability in 4MOSAn GCB Doctor allows unauthenticated remote attackers to execute arbitrary system commands via a test page parameter.
---METADATA---
VENDOR: 4MOSAn Security Technology
PRODUCT: 4MOSAn GCB Doctor
AFFECTED_VERSIONS: 0 up to (excluding) 20260621
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An OS command injection vulnerability in 4MOSAn GCB Doctor allows unauthenticated remote attackers to execute arbitrary system commands via a test page parameter.
Executive Summary:
A critical OS command injection vulnerability in 4MOSAn GCB Doctor allows unauthenticated remote attackers to achieve full system execution on the host server.
Vulnerability Details
CVE-ID: CVE-2026-78211
Affected Software: 4MOSAn Security Technology 4MOSAn GCB Doctor
Affected Versions: 0 up to (excluding) 20260621
Vulnerability: The vulnerability originates from an unremoved ADOdb test page that fails to sanitize user-supplied input. An unauthenticated attacker can inject arbitrary operating system commands into this parameter, resulting in code execution with the privileges of the web service.
Business Impact
OS command injection is a high-impact vulnerability that allows attackers to gain persistent access to the underlying server. This can result in complete data exfiltration, malware installation, or the usage of the server as a launchpad for further internal attacks. The CVSS score of 9.8 reflects the high probability of total system compromise.
Remediation Plan
Immediate Action: Upgrade to version 20260621 or later immediately, as specified by the vendor. Ensure the FreeBSD-GCB Management Center security upgrade is also applied.
Proactive Monitoring: Review server logs for unexpected process execution or shell command patterns originating from the web application user.
Compensating Controls: Remove or restrict access to the vulnerable ADOdb test page via server configuration files or a WAF rule that blocks access to known test or debug files.
Exploitation Status
Public Exploit Available: No (No confirmed weaponized exploit or public repository identified in curated data).
Analyst Notes: As of August 23, 2026, there is no public information indicating active exploitation or a confirmed public proof-of-concept for this vulnerability. Command injection remains a highly dangerous and well-understood attack vector that is easily automated if the vulnerable endpoint is exposed to the internet.
Analyst Recommendation
The availability of a vendor-provided fix makes remediation straightforward. Organizations should prioritize the update to version 20260621 to close this critical security gap. Following the update, conduct an audit to ensure no other test or debug pages remain exposed in the production environment.
Update 4MOSAn Security Technology 4MOSAn GCB Doctor to the latest version. Monitor for exploitation attempts and review access logs.
exceljs-hardened versions before 5
exceljs-hardened versions before 5
---METADATA---
VENDOR: exceljs
PRODUCT: exceljs
AFFECTED_VERSIONS: 0 through 4.4.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The exceljs library is vulnerable to CSV formula injection, which can lead to unauthorized data access or malicious actions when a user opens a generated CSV file in spreadsheet software.
Executive Summary:
The exceljs library, in versions up to 4.4.0, contains a formula injection vulnerability that could compromise user data when processed by spreadsheet applications.
Vulnerability Details
CVE-ID: CVE-2026-78209
Affected Software: exceljs
Affected Versions: 0 through 4.4.0
Vulnerability: The software is affected by CWE-1236 (Improper Neutralization of Formula Elements in a CSV File). This vulnerability allows an attacker to inject formula elements into CSV files, which are then executed when the file is opened by a victim using software like Microsoft Excel, requiring no authentication.
Business Impact
This vulnerability poses a significant risk to data confidentiality and integrity. If an attacker successfully injects malicious formulas into generated CSV files, they could potentially execute unauthorized commands or exfiltrate sensitive data from the victim's spreadsheet environment. With a CVSS score of 8.2, this issue requires prompt attention to prevent potential exploitation in business workflows.
Remediation Plan
Immediate Action: Update to the latest version of exceljs as specified by the project maintainers to ensure proper sanitization of CSV cell values.
Proactive Monitoring: Audit applications that generate CSV files using exceljs to ensure that inputs are sanitized before being processed by the library.
Compensating Controls: Advise users to exercise caution when opening CSV files from untrusted sources and configure spreadsheet software to disable automatic formula execution where possible.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit identified).
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The risk is primarily dependent on the application's implementation of user-supplied data within CSV outputs.
Analyst Recommendation
Developers should prioritize updating the exceljs dependency to the latest version to address this injection flaw. Organizations should also implement strict input validation for any data that is exported into CSV format.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
exceljs-hardened before 5
exceljs-hardened before 5
---METADATA---
VENDOR: exceljs
PRODUCT: exceljs
AFFECTED_VERSIONS: 0 through 4.4.0
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The exceljs library is vulnerable to path traversal through unvalidated filenames provided in the addImage function, potentially allowing unauthorized access to local files.
Executive Summary:
An unauthenticated remote attacker can perform path traversal attacks against applications using the exceljs library, potentially leading to unauthorized file system access.
Vulnerability Details
CVE-ID: CVE-2026-78208
Affected Software: exceljs exceljs
Affected Versions: 0 through 4.4.0
Vulnerability: This vulnerability, classified as CWE-73, arises from the lack of validation for file names passed to the addImage function. An unauthenticated attacker can exploit this to traverse directories and potentially access sensitive files on the host system.
Business Impact
The ability to access arbitrary files on the system presents a critical security risk, potentially leading to the exposure of configuration files, credentials, or sensitive application data. With a CVSS score of 7.5, this vulnerability requires immediate attention to prevent unauthorized information disclosure.
Remediation Plan
Immediate Action: Update the exceljs dependency to the latest secure version once released, or apply the specific patch provided in the vendor security advisory.
Proactive Monitoring: Review application access logs for suspicious file paths or directory traversal patterns, such as sequences containing dot-dot-slash.
Compensating Controls: Ensure that the application process runs with the least privilege necessary, isolating it from sensitive areas of the file system.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Path traversal flaws are highly targetable, and preventing this requires strict input sanitization on all user-supplied filenames.
Analyst Recommendation
Given the potential for unauthorized file access, administrators should treat this vulnerability as a high priority. Ensure that all inputs into the exceljs library are validated and that the software is updated to the latest version to eliminate the underlying path handling flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A prototype pollution vulnerability in the exceljs deepMerge helper allows attackers to inject malicious keys into object prototypes via crafted cell...
A prototype pollution vulnerability in the exceljs deepMerge helper allows attackers to inject malicious keys into object prototypes via crafted cell notes.
---METADATA---
VENDOR: exceljs
PRODUCT: exceljs
AFFECTED_VERSIONS: 0 through 4.4.0
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A prototype pollution vulnerability in the exceljs deepMerge helper allows attackers to inject malicious keys into object prototypes via crafted cell notes.
Executive Summary:
The exceljs library is susceptible to a critical prototype pollution vulnerability that could lead to unauthorized code execution or application instability.
Vulnerability Details
CVE-ID: CVE-2026-78207
Affected Software: exceljs exceljs
Affected Versions: 0 through 4.4.0
Vulnerability: This vulnerability resides in the deepMerge helper function, which fails to sanitize input keys such as proto, constructor, or prototype. An unauthenticated attacker can exploit this by providing a malicious JSON payload during note serialization, effectively polluting the global Object.prototype and influencing the behavior of all subsequent object instances within the application.
Business Impact
Successful exploitation of this flaw can lead to severe application compromise, including potential remote code execution or denial of service, depending on the surrounding application logic. Given the CVSS score of 9.4, this vulnerability represents a critical risk to data integrity and system availability, as prototype pollution often grants attackers the ability to bypass security controls or manipulate application state.
Remediation Plan
Immediate Action: Users should update to version 5.0.0 or later as soon as it becomes available from the official maintainers.
Proactive Monitoring: Security teams should monitor application logs for unexpected object property modifications or anomalous error patterns that may indicate attempts to pollute the prototype chain.
Compensating Controls: Implement strict input validation and sanitization for all user-supplied JSON data before it is processed by the exceljs library to prevent malicious keys from reaching the merge function.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of Aug 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the nature of prototype pollution in JavaScript environments.
Analyst Recommendation
The high CVSS score of 9.4 highlights the severity of this prototype pollution vulnerability. Organizations utilizing the exceljs library must prioritize upgrading to the patched version once released and verify their dependency trees to ensure all instances of this library are remediated.
Update exceljs exceljs to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
exceljs-hardened before 5
exceljs-hardened before 5
---METADATA---
VENDOR: exceljs
PRODUCT: exceljs
AFFECTED_VERSIONS: 0 through 4.4.0
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The exceljs library is vulnerable to a data amplification attack due to improper handling of highly compressed data, leading to potential denial of service.
Executive Summary:
An unauthenticated remote attacker can trigger a denial of service condition in the exceljs library by exploiting improper decompression handling of highly compressed files.
Vulnerability Details
CVE-ID: CVE-2026-78206
Affected Software: exceljs exceljs
Affected Versions: 0 through 4.4.0
Vulnerability: This vulnerability, identified as CWE-409, involves the improper handling of highly compressed data during the parsing of XLSX files. It allows an unauthenticated attacker to cause significant resource consumption, resulting in a denial of service.
Business Impact
Successful exploitation of this vulnerability can cause the application to crash or become unresponsive, leading to service disruption. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to operational availability, particularly for systems that process untrusted Excel files.
Remediation Plan
Immediate Action: Upgrade to the latest version of the library if a release is available, or consult the vendor security advisory for specific hardening configurations.
Proactive Monitoring: Monitor server CPU and memory utilization for sudden spikes during file upload or processing tasks.
Compensating Controls: Implement strict file size limits and scan all incoming documents with robust antivirus or decompression security tools before processing.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its ability to exhaust system resources via specially crafted input.
Analyst Recommendation
Organizations utilizing the exceljs library should prioritize the identification of all instances within their environment. Since this vulnerability allows for unauthenticated denial of service, applying the vendor-recommended update is essential to maintaining system stability and availability.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Ghostwriter before 7
Ghostwriter before 7
---METADATA---
VENDOR: GhostManager
PRODUCT: Ghostwriter
AFFECTED_VERSIONS: 0 up to (excluding) 7.1.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Ghostwriter contains an authorization bypass vulnerability allowing authenticated users to access or modify sensitive report templates via user controlled keys.
Executive Summary:
A critical authorization bypass vulnerability in Ghostwriter allows authenticated attackers to manipulate report templates, posing a significant risk to data integrity and reporting confidentiality.
Vulnerability Details
CVE-ID: CVE-2026-78203
Affected Software: GhostManager Ghostwriter
Affected Versions: 0 up to 7.1.2
Vulnerability: This vulnerability, categorized as CWE-639, stems from an authorization bypass flaw where a user-controlled key is not correctly validated. An authenticated attacker can exploit this to access or swap report templates that should be restricted to other users or clients.
Business Impact
The ability for an unauthorized user to access or modify sensitive report templates can lead to significant data leakage, loss of client trust, and the compromise of professional reporting integrity. Given the CVSS score of 7.1, this represents a high risk to business operations, particularly for organizations handling sensitive engagement data.
Remediation Plan
Immediate Action: Update the Ghostwriter instance to version 7.1.2 or later to apply the necessary authorization checks.
Proactive Monitoring: Review application access logs for unusual patterns of template access or unexpected modifications to report configurations by standard user accounts.
Compensating Controls: Implement strict network access controls and ensure the Principle of Least Privilege is enforced for all user accounts accessing the reporting module.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any authenticated user due to the lack of server-side validation for the template ID parameter.
Analyst Recommendation
The severity of this authorization bypass necessitates immediate attention from administrators. Organizations should prioritize patching to version 7.1.2 to eliminate the risk of report template manipulation and ensure the confidentiality of sensitive engagement data.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in itsourcecode Payroll System 1
A vulnerability was found in itsourcecode Payroll System 1
---METADATA---
VENDOR: itsourcecode
PRODUCT: Payroll System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: microwave (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394579","name":"VDB-394579 | itsourcecode Payroll System admin_class.php save_settings unrestricted upload","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394579/cti","name":"VDB-394579 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78202","name":"CVE-2026-78202 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/886159","name":"Submit #886159 | itsourcecode Payroll System 1.0 Unrestricted Upload","tags":["third-party-advisory"]},{"url":"https://github.com/microwaveabi/vul/issues/12","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://itsourcecode.com/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
The itsourcecode Payroll System is vulnerable to an unrestricted file upload flaw, which allows unauthenticated attackers to upload malicious files to the server.
Executive Summary:
An unauthenticated file upload vulnerability in the itsourcecode Payroll System permits remote attackers to upload arbitrary files, posing a critical risk of server compromise.
Vulnerability Details
CVE-ID: CVE-2026-78202
Affected Software: itsourcecode Payroll System
Affected Versions: 1.0
Vulnerability: The application features an unrestricted file upload vulnerability in the admin_class.php file, which allows an unauthenticated attacker to bypass security checks and upload files to the server.
Business Impact
This vulnerability is highly critical because it does not require authentication to exploit. With a CVSS score of 7.3, an attacker can upload web shells or malicious scripts to gain full control over the application, leading to significant data breaches or unauthorized access to sensitive payroll information.
Remediation Plan
Immediate Action: Update the Payroll System to the latest available version provided by the vendor to remediate the insecure file upload handling.
Proactive Monitoring: Audit the server for unexpected files in the web root or upload directories, and monitor for unusual web traffic patterns.
Compensating Controls: Configure the web server to disable script execution in upload directories and utilize a Web Application Firewall to block suspicious file upload requests.
Exploitation Status
Public Exploit Available: Yes — a published proof-of-concept exists via issue tracking documentation.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The lack of authentication requirements makes this a high-priority target for automated exploit attempts.
Analyst Recommendation
The ability for an unauthenticated user to upload files to a server is a severe security failure. Organizations must prioritize applying the vendor patch or implementing strict file-type and directory-level restrictions immediately to prevent remote code execution.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in itsourcecode Payroll System 1
A vulnerability has been found in itsourcecode Payroll System 1
---METADATA---
VENDOR: itsourcecode
PRODUCT: Payroll System
AFFECTED_VERSIONS: itsourcecode Payroll System: 1.0
CONFIDENCE: high
MISSING: patch
PROFILE: grounded@2cca291e317a
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-30T15:02:48.274Z
CREDITS: microwave (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394578","name":"VDB-394578 | itsourcecode Payroll System admin_class.php login sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394578/cti","name":"VDB-394578 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78201","name":"CVE-2026-78201 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/886158","name":"Submit #886158 | itsourcecode Payroll System 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/microwaveabi/vul/issues/8","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://itsourcecode.com/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the login function of itsourcecode Payroll System version 1.0 allows unauthenticated attackers to bypass authentication and execute arbitrary database queries.
Executive Summary:
An unauthenticated SQL injection vulnerability in the itsourcecode Payroll System allows remote attackers to bypass authentication and gain full administrative access.
Vulnerability Details
CVE-ID: CVE-2026-78201
Affected Software: itsourcecode Payroll System
Affected Versions: itsourcecode Payroll System: 1.0
Vulnerability: This is a SQL injection flaw (CWE-89) located in the login function of the admin_class.php file. An unauthenticated attacker can manipulate the username parameter to bypass authentication and gain full administrative control over the system.
Business Impact
Successful exploitation of this vulnerability poses a severe risk to organizational data integrity and confidentiality. With a CVSS score of 7.3, the flaw enables unauthenticated attackers to gain administrative access, potentially leading to the unauthorized exfiltration of sensitive employee PII, salary information, and attendance records.
Remediation Plan
Immediate Action: Since an official patch is currently unavailable, administrators should restrict network access to the application and implement strict input validation.
Proactive Monitoring: Review web server and application logs for anomalous POST requests to ajax.php and look for SQL syntax patterns in the username field.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection attempts targeting the login endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced GitHub research writeup.
Analyst Notes: As of August 26, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The flaw is highly exploitable due to the lack of input sanitization in the source code.
Analyst Recommendation
Given the critical nature of this vulnerability and the availability of a public proof-of-concept, immediate action is required to secure the environment. Organizations should prioritize restricting access to the affected system until the vendor provides an official patch to remediate the underlying code vulnerability.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1
---METADATA---
VENDOR: SourceCodester
PRODUCT: Simple Online Food Ordering System
AFFECTED_VERSIONS: SourceCodester Simple Online Food Ordering System: 1.0
CONFIDENCE: high
MISSING: patch
PROFILE: grounded@2cca291e317a
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-30T15:02:48.276Z
CREDITS: W5555 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394576","name":"VDB-394576 | SourceCodester Simple Online Food Ordering System view_prod.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394576/cti","name":"VDB-394576 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78199","name":"CVE-2026-78199 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/886040","name":"Submit #886040 | SourceCodester Simple Online Food Ordering System using PHP/MySQL /fos/view_prod.php 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/wsx138/cve/issues/5","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://www.sourcecodester.com/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the view_prod.php file of SourceCodester Simple Online Food Ordering System version 1.0 allows unauthenticated remote attackers to manipulate database queries.
Executive Summary:
An unauthenticated SQL injection vulnerability in the SourceCodester Simple Online Food Ordering System allows remote attackers to compromise database integrity.
Vulnerability Details
CVE-ID: CVE-2026-78199
Affected Software: SourceCodester Simple Online Food Ordering System
Affected Versions: SourceCodester Simple Online Food Ordering System: 1.0
Vulnerability: The vulnerability is a SQL injection (CWE-89) within the /fos/view_prod.php file. An unauthenticated remote attacker can inject malicious SQL code through the ID parameter, enabling unauthorized database access and data manipulation.
Business Impact
The vulnerability carries a CVSS score of 7.3, reflecting the significant risk of unauthorized database access. Exploitation can lead to the exfiltration of sensitive customer data, tampering with order information, and potential service interruption, which could cause substantial reputational and operational damage.
Remediation Plan
Immediate Action: As no patch is currently available, restrict access to the application interface and monitor all incoming traffic for malicious payloads.
Proactive Monitoring: Monitor database query logs for unusual time-based or boolean-based SQL injection patterns originating from the ID parameter.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter and block requests containing suspicious SQL syntax in the ID parameter of the view_prod.php endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced GitHub research writeup.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is straightforward to exploit via standard SQL injection techniques.
Analyst Recommendation
Due to the ease of exploitation and the availability of public proof-of-concept code, this vulnerability should be treated with high urgency. Organizations must implement compensating controls immediately and monitor the environment closely until the vendor releases a formal security update.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1
---METADATA---
VENDOR: SourceCodester
PRODUCT: Simple Online Food Ordering System
AFFECTED_VERSIONS: SourceCodester Simple Online Food Ordering System: 1.0
CONFIDENCE: high
MISSING: patch
PROFILE: grounded@2cca291e317a
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-30T15:02:48.278Z
CREDITS: W5555 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394575","name":"VDB-394575 | SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394575/cti","name":"VDB-394575 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78198","name":"CVE-2026-78198 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/886037","name":"Submit #886037 | SourceCodester sourcecodester Simple Online Food Ordering System using PHP/MySQL /fos/admin/ajax.php?ac","tags":["third-party-advisory"]},{"url":"https://github.com/wsx138/cve/issues/4","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://www.sourcecodester.com/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the add_to_cart function of SourceCodester Simple Online Food Ordering System 1.0, allowing unauthenticated attackers to execute arbitrary database commands.
Executive Summary:
An unauthenticated SQL injection vulnerability in the SourceCodester Simple Online Food Ordering System enables remote attackers to compromise the backend database.
Vulnerability Details
CVE-ID: CVE-2026-78198
Affected Software: SourceCodester Simple Online Food Ordering System
Affected Versions: SourceCodester Simple Online Food Ordering System: 1.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) in the /fos/admin/ajax.php endpoint. By manipulating the pid parameter during an add_to_cart action, an unauthenticated attacker can inject malicious SQL queries into the database.
Business Impact
With a CVSS score of 7.3, this vulnerability presents a significant security risk. Successful exploitation allows an attacker to bypass security controls to read, modify, or delete database records, which could lead to the exposure of customer PII and the disruption of critical ordering operations.
Remediation Plan
Immediate Action: In the absence of a vendor patch, restrict public access to the admin and ordering endpoints and implement strict input validation for the pid parameter.
Proactive Monitoring: Monitor application logs for suspicious POST requests to the ajax.php file, particularly those containing encoded SQL commands.
Compensating Controls: Implement WAF rules to detect and drop traffic containing SQL injection payloads directed at the add_to_cart action.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced GitHub research writeup.
Analyst Notes: As of August 27, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible to attackers due to the lack of required authentication.
Analyst Recommendation
Given that this vulnerability allows for unauthorized database interaction without authentication, it constitutes a high-priority risk. Security teams should ensure that compensating controls are active and remain vigilant for signs of exploitation while awaiting a permanent fix from the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1
---METADATA---
VENDOR: SourceCodester
PRODUCT: Simple Online Food Ordering System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: W5555 (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394574","name":"VDB-394574 | SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394574/cti","name":"VDB-394574 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78197","name":"CVE-2026-78197 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/886034","name":"Submit #886034 | SourceCodester Simple Online Food Ordering System v1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/886038","name":"Submit #886038 | SourceCodester ourcecodester Simple Online Food Ordering System using PHP/MySQL V1.0 /fos/admin/ajax.ph","tags":["third-party-advisory"]},{"url":"https://github.com/wsx138/cve/issues/3","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://www.sourcecodester.com/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in SourceCodester Simple Online Food Ordering System 1.0 via the ajax.php file, allowing unauthenticated attackers to manipulate database queries.
Executive Summary:
A critical SQL injection vulnerability in SourceCodester Simple Online Food Ordering System 1.0 allows unauthenticated attackers to compromise database integrity.
Vulnerability Details
CVE-ID: CVE-2026-78197
Affected Software: SourceCodester Simple Online Food Ordering System
Affected Versions: 1.0
Vulnerability: The application is susceptible to SQL injection via the ajax.php script. This flaw allows an unauthenticated, remote attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.
Business Impact
Successful exploitation of this vulnerability could lead to the exposure of sensitive customer data, unauthorized administrative access, or complete compromise of the backend database. Given the CVSS score of 7.3, this represents a high-risk security gap that can be leveraged by external attackers to disrupt business operations and facilitate data exfiltration.
Remediation Plan
Immediate Action: Since a specific patch is not currently available, administrators should restrict access to the affected ajax.php file at the web server level to trusted sources only.
Proactive Monitoring: Review web access logs for anomalous patterns, such as SQL keywords or unusual string lengths in requests targeting the ajax.php endpoint.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting application parameters.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical issue tracker referenced by the CVE record.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently easy to exploit due to the lack of required authentication.
Analyst Recommendation
The severity of this SQL injection vulnerability necessitates immediate attention to prevent unauthorized database access. Organizations should prioritize isolating the affected component and implementing robust input validation or WAF protections while awaiting a formal vendor patch.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager
Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager
---METADATA---
VENDOR: pgAdmin
PRODUCT: pgAdmin 4
AFFECTED_VERSIONS: 0 up to (excluding) 9.15
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A symbolic-link path traversal vulnerability in the pgAdmin 4 File Manager allows authenticated users to access or manipulate unauthorized files.
Executive Summary:
A path traversal vulnerability in pgAdmin 4 exposes the application to unauthorized file system access, potentially leading to critical data integrity issues.
Vulnerability Details
CVE-ID: CVE-2026-7819
Affected Software: pgAdmin pgAdmin 4
Affected Versions: 0 up to (excluding) 9.15
Vulnerability: This is a path traversal vulnerability (CWE-22, CWE-61) within the File Manager component. It requires the attacker to have low-level privileges (PR:L) to interact with the file management functions, where they can manipulate symbolic links to bypass directory restrictions.
Business Impact
The vulnerability carries a CVSS score of 8.1 (High), primarily due to the potential for significant impact on file integrity and availability. An attacker successfully exploiting this flaw could read or overwrite sensitive configuration or database files, leading to unauthorized data exposure or complete service disruption.
Remediation Plan
Immediate Action: Update pgAdmin 4 to version 9.15 or later immediately.
Proactive Monitoring: Review application logs for unusual file access patterns or attempts to traverse outside of designated directories.
Compensating Controls: Ensure that the service account running pgAdmin 4 follows the principle of least privilege, restricting its file system access to only the necessary directories required for operation.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of May 13, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any authenticated user with access to the File Manager interface.
Analyst Recommendation
Given the severity of this vulnerability, organizations should prioritize patching their pgAdmin 4 instances to version 9.15. Failure to address this flaw leaves the underlying database environment vulnerable to unauthorized file system manipulation by authenticated users.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300
---METADATA---
VENDOR: Shenzhen Gongji Technology
PRODUCT: XBROTHER Dynamic Environment Monitoring System
AFFECTED_VERSIONS: Up to 300R004C00B300
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the PlanController.getImmediatePlans function of the XBROTHER Dynamic Environment Monitoring System, allowing remote unauthenticated attackers to manipulate queries.
Executive Summary:
A critical SQL injection vulnerability in the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System allows unauthenticated remote attackers to execute malicious database queries.
Vulnerability Details
CVE-ID: CVE-2026-78182
Affected Software: Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System
Affected Versions: Up to 300R004C00B300
Vulnerability: This is a SQL injection vulnerability (CWE-89) located in the PlanController.getImmediatePlans function within the /xbreport/api/v1/plamange/plansImmediate file. The application fails to properly sanitize the order or sort arguments, enabling unauthenticated attackers to inject malicious SQL commands.
Business Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive data stored within the system database, potential data modification, or service disruption. Given the CVSS score of 7.3, this represents a significant risk to organizational integrity and data confidentiality, as the attack requires no user interaction or prior authentication.
Remediation Plan
Immediate Action: Review the official vendor advisory and apply the latest security patches or updates provided by Shenzhen Gongji Technology as soon as they become available.
Proactive Monitoring: Monitor database query logs for unusual patterns, such as unexpected syntax or suspicious sorting parameters, that may indicate active injection attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to filter and block malicious SQL injection patterns targeting the vulnerable API endpoint.
Exploitation Status
Public Exploit Available: Yes, as documented in the provided vulnerability references.
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation in the wild, though the availability of exploit material increases the risk. The flaw is inherently dangerous due to the lack of required authentication.
Analyst Recommendation
Organizations utilizing the XBROTHER Dynamic Environment Monitoring System must treat this vulnerability with high priority. Apply vendor-supplied patches immediately upon release and ensure that perimeter defenses are configured to inspect traffic for injection attempts until the system is fully remediated.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A weakness has been identified in ractivejs ractive up to 1
A weakness has been identified in ractivejs ractive up to 1
---METADATA---
VENDOR: ractivejs
PRODUCT: ractive
AFFECTED_VERSIONS: 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4
CONFIDENCE: high
MISSING: patch
CREDITS: wjm3 (VulDB User) (reporter); VulDB CNA Team (coordinator)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394565","name":"VDB-394565 | ractivejs ractive Keypath Ractive#set prototype pollution","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394565/cti","name":"VDB-394565 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78181","name":"CVE-2026-78181 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/884187","name":"Submit #884187 | Ractive.js ractive 1.4.4 Prototype Pollution","tags":["third-party-advisory"]},{"url":"https://github.com/ractivejs/ractive/issues/3448","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://github.com/ractivejs/ractive/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
The Ractive.js library is vulnerable to prototype pollution via the Ractive.set function, potentially allowing for remote code execution.
Executive Summary:
A high-severity prototype pollution vulnerability in the Ractive.js library allows for potential code injection and unauthorized system impact.
Vulnerability Details
CVE-ID: CVE-2026-78181
Affected Software: ractivejs ractive
Affected Versions: 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4
Vulnerability: This vulnerability involves improper control of object prototype attributes within the Ractive.set function. An unauthenticated attacker can exploit this flaw to inject malicious properties into the global object prototype, which may lead to remote code execution.
Business Impact
Prototype pollution is a dangerous class of vulnerability that can lead to complete application takeover, privilege escalation, or cross-site scripting attacks. With a CVSS score of 7.3, this flaw poses a significant threat to any web application relying on the affected versions of the Ractive.js library, potentially resulting in severe data breaches or service disruption.
Remediation Plan
Immediate Action: As no specific patch is mentioned, organizations should audit their dependencies and consider migrating to a patched version or a different framework if the library is no longer actively maintained.
Proactive Monitoring: Monitor for unexpected changes in application behavior or suspicious JavaScript execution patterns that deviate from expected functionality.
Compensating Controls: Utilize security headers and Content Security Policy (CSP) configurations to restrict the execution of unauthorized scripts and mitigate the impact of potential code injection.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists via the GitHub issue tracking repository.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The nature of prototype pollution makes this library inherently sensitive to input manipulation.
Analyst Recommendation
Given the potential for remote code execution, this vulnerability should be treated with high priority. Development teams should immediately evaluate the necessity of the Ractive.js dependency and apply necessary containment strategies until a secure version or official fix is provided by the maintainers.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in alibaba-fusion next up to 1
A security flaw has been discovered in alibaba-fusion next up to 1
---METADATA---
VENDOR: Alibaba
PRODUCT: Fusion Next
AFFECTED_VERSIONS: 1.27.0, 1.27.1, 1.27.2, 1.27.3, 1.27.4, 1.27.5, 1.27.6, 1.27.7
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A security flaw in Alibaba Fusion Next allows for improper control of object prototype attributes, potentially leading to code injection.
Executive Summary:
A critical vulnerability in Alibaba Fusion Next permits unauthorized object prototype modification, creating a risk of arbitrary code injection.
Vulnerability Details
CVE-ID: CVE-2026-78180
Affected Software: Alibaba Fusion Next
Affected Versions: 1.27.0, 1.27.1, 1.27.2, 1.27.3, 1.27.4, 1.27.5, 1.27.6, 1.27.7
Vulnerability: This vulnerability involves improper control of object prototype attributes (CWE-1321) and potential code injection (CWE-94). The attack vector is network-based and requires no authentication or user interaction.
Business Impact
The ability for an unauthenticated attacker to inject code or manipulate object prototypes can lead to full application compromise, data exfiltration, or unauthorized execution of functions. While the CVSS score of 7.3 reflects a high severity, the potential for code injection poses a significant risk to the integrity and confidentiality of the entire application environment.
Remediation Plan
Immediate Action: Review the Alibaba Fusion Next repository for security patches or updates that address object prototype pollution and code injection risks.
Proactive Monitoring: Monitor server-side logs for unusual object property assignments or unexpected code execution patterns that deviate from standard application behavior.
Compensating Controls: Implement strict input validation and sanitization for all user-supplied data to prevent the injection of malicious payloads into object structures.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its nature as a prototype pollution vulnerability, which often serves as a precursor to more severe execution attacks.
Analyst Recommendation
Given the nature of code injection vulnerabilities, organizations should prioritize updating the affected component as soon as a patch is released. Until an official fix is applied, strict input filtering and monitoring of application behavior are essential to mitigate the risk of exploitation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager
Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager
---METADATA---
VENDOR: pgAdmin
PRODUCT: pgAdmin 4
AFFECTED_VERSIONS: 0 up to 9.15
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A deserialization of untrusted data vulnerability in the FileBackedSessionManager of pgAdmin 4 allows for potential unauthorized system impact.
Executive Summary:
A deserialization vulnerability in pgAdmin 4 versions prior to 9.15 could allow an authenticated attacker to achieve total system impact.
Vulnerability Details
CVE-ID: CVE-2026-7818
Affected Software: pgAdmin pgAdmin 4
Affected Versions: 0 up to 9.15
Vulnerability: This is a deserialization of untrusted data vulnerability (CWE-502) within the FileBackedSessionManager component. The CVSS vector (PR:L) indicates that an attacker must possess low privileges (authenticated) to successfully exploit this flaw.
Business Impact
With a CVSS score of 7.0, this vulnerability poses a significant risk to the integrity and availability of the database management environment. Exploitation could lead to unauthorized code execution or system compromise, potentially exposing sensitive database credentials and administrative access.
Remediation Plan
Immediate Action: Update pgAdmin 4 to version 9.15 or later immediately.
Proactive Monitoring: Monitor application logs for suspicious session activity or unauthorized modifications to temporary session storage files.
Compensating Controls: Restrict access to the pgAdmin management interface to trusted internal networks and enforce multi-factor authentication for all users.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit in available data)
Analyst Notes: As of May 12, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While exploitation requires authenticated access, the potential for total system impact necessitates rapid patching.
Analyst Recommendation
The severity of this deserialization flaw mandates an immediate update to version 9.15. Administrators should ensure that all instances of pgAdmin 4 are patched to prevent potential privilege escalation or unauthorized command execution.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in jQWidgets up to 24
A vulnerability was determined in jQWidgets up to 24
---METADATA---
VENDOR: jQWidgets
PRODUCT: jQWidgets
AFFECTED_VERSIONS: 24.0.0, 24.0.1
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A prototype pollution and code injection vulnerability exists in jQWidgets versions 24.0.0 and 24.0.1, allowing unauthenticated attackers to modify object attributes.
Executive Summary:
A critical prototype pollution and code injection vulnerability in jQWidgets versions 24.0.0 and 24.0.1 allows unauthenticated attackers to compromise application integrity.
Vulnerability Details
CVE-ID: CVE-2026-78178
Affected Software: jQWidgets jQWidgets
Affected Versions: 24.0.0, 24.0.1
Vulnerability: The software is susceptible to improper control of object prototype attributes and code injection. This vulnerability can be triggered by unauthenticated attackers over the network.
Business Impact
Successful exploitation allows an attacker to inject malicious code or manipulate application logic by modifying object prototypes. With a CVSS score of 7.3, this high-severity flaw could lead to full application compromise, data theft, or unauthorized actions performed on behalf of legitimate users.
Remediation Plan
Immediate Action: Upgrade to a version beyond 24.0.1 if available, or apply the specific security fixes provided by the vendor.
Proactive Monitoring: Inspect application logs for suspicious input patterns, particularly those involving unexpected JSON payloads or object manipulations.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common prototype pollution attack vectors.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Prototype pollution flaws are frequently targeted for their ability to bypass security controls in modern JavaScript applications.
Analyst Recommendation
Due to the ease of exploitation for unauthenticated users, this vulnerability should be remediated immediately. Organizations using jQWidgets should verify their current version and apply the necessary updates to prevent potential code injection and application-wide compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in itsourcecode Sales and Inventory System 1
A vulnerability has been found in itsourcecode Sales and Inventory System 1
---METADATA---
VENDOR: itsourcecode
PRODUCT: Sales and Inventory System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: VivianQYW (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394560","name":"VDB-394560 | itsourcecode Sales and Inventory System processlogin.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394560/cti","name":"VDB-394560 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78171","name":"CVE-2026-78171 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/884109","name":"Submit #884109 | itsourcecode Sales and Inventory System V1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/MounT1veR/new/issues/1","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://itsourcecode.com/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
An SQL injection vulnerability in itsourcecode Sales and Inventory System 1.0 via processlogin.php allows unauthenticated attackers to compromise database integrity.
Executive Summary:
An unauthenticated SQL injection vulnerability in the itsourcecode Sales and Inventory System 1.0 creates a significant risk of database compromise.
Vulnerability Details
CVE-ID: CVE-2026-78171
Affected Software: itsourcecode Sales and Inventory System
Affected Versions: 1.0
Vulnerability: The application fails to properly sanitize user-supplied input in the processlogin.php script. This flaw allows an unauthenticated, remote attacker to perform SQL injection, facilitating unauthorized access to the application database.
Business Impact
A successful SQL injection attack against an inventory and sales system can result in the loss of sensitive business data, including customer information, financial records, and inventory logs. The CVSS score of 7.3 underscores the elevated risk, as the vulnerability is network-accessible and requires no authentication, making it an attractive target for automated exploitation.
Remediation Plan
Immediate Action: Organizations should restrict network access to the login components of the system and, if possible, implement strict input validation on the processlogin.php script.
Proactive Monitoring: Review server and application logs for signs of SQL injection attempts, such as unusual characters or SQL syntax in login requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect incoming traffic and block requests containing malicious SQL payloads directed at the login endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the project's issue tracker.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently easy to exploit due to the lack of required authentication for the affected endpoint.
Analyst Recommendation
The ability for an unauthenticated attacker to inject arbitrary SQL queries poses a severe threat to the integrity and confidentiality of the system. Immediate steps must be taken to mitigate exposure, including the implementation of WAF rules and rigorous monitoring of login processes until a permanent patch is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in UTT HiPER 1200GW up to 2
A flaw has been found in UTT HiPER 1200GW up to 2
---METADATA---
VENDOR: UTT
PRODUCT: HiPER 1200GW
AFFECTED_VERSIONS: 2.5.3-170306
CONFIDENCE: high
MISSING: patch
CREDITS: yecp (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394559","name":"VDB-394559 | UTT HiPER 1200GW formConfigFastDirectionW strcpy buffer overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394559/cti","name":"VDB-394559 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78170","name":"CVE-2026-78170 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/883902","name":"Submit #883902 | UTT HiPER 1200GW <=v2.5.3-170306 Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/7wkajk/CVE-VUL/blob/main/108.md","name":null,"tags":["exploit"]}]
---END_METADATA---
Description Summary:
The UTT HiPER 1200GW router is vulnerable to memory corruption and buffer overflow, which can be triggered by an authenticated user to achieve system compromise.
Executive Summary:
An authenticated buffer overflow vulnerability in the UTT HiPER 1200GW router poses a significant risk of total system compromise.
Vulnerability Details
CVE-ID: CVE-2026-78170
Affected Software: UTT HiPER 1200GW
Affected Versions: 2.5.3-170306
Vulnerability: This vulnerability involves a buffer overflow in the formConfigFastDirectionW function, which can be exploited by an authenticated attacker to cause memory corruption and potentially execute arbitrary code.
Business Impact
Successful exploitation of this memory corruption vulnerability could allow an attacker to gain full control over the affected router. Given the CVSS score of 8.8, this represents a high-severity threat that could lead to unauthorized network access, data interception, or the complete disruption of network services.
Remediation Plan
Immediate Action: Contact the vendor for the latest security firmware update, as no official patch version is currently identified.
Proactive Monitoring: Review system and access logs for unusual administrative activity or repeated failed attempts to access configuration interfaces.
Compensating Controls: Restrict administrative access to the router interface to trusted IP addresses only and enforce strong, multi-factor authentication for all administrative accounts.
Exploitation Status
Public Exploit Available: Yes — a published proof-of-concept exists as documented in a technical analysis on GitHub.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The flaw is inherently dangerous due to its potential for total system impact.
Analyst Recommendation
The high CVSS score of 8.8 underscores the urgency of addressing this flaw. Administrators should prioritize restricting management interfaces to prevent unauthorized access until a vendor-supplied patch is applied to resolve the buffer overflow.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW HTTP request handler, allowing remote attackers to achieve arbitrary code e...
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW HTTP request handler, allowing remote attackers to achieve arbitrary code execution via a manipulated Profile argument.
---METADATA---
VENDOR: UTT
PRODUCT: HiPER 1250GW
AFFECTED_VERSIONS: 3.2.7-210907-180535
CONFIDENCE: high
MISSING: patch
CREDITS: yecp (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394558","name":"VDB-394558 | UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394558/cti","name":"VDB-394558 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78169","name":"CVE-2026-78169 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/883900","name":"Submit #883900 | UTT HiPER 1250GW <=v3.2.7-210907-180535 Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/7wkajk/CVE-VUL/blob/main/107.md","name":null,"tags":["exploit"]}]
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the UTT HiPER 1250GW HTTP request handler allows remote, authenticated attackers to execute arbitrary code via a manipulated Profile argument.
Executive Summary:
A critical stack-based buffer overflow vulnerability in the UTT HiPER 1250GW device allows remote attackers with low-level privileges to achieve arbitrary code execution.
Vulnerability Details
CVE-ID: CVE-2026-78169
Affected Software: UTT HiPER 1250GW
Affected Versions: 3.2.7-210907-180535
Vulnerability: This vulnerability is a stack-based buffer overflow (CWE-121) triggered by improper memory management within the HTTP request handler function. An attacker with low privileges can exploit this via a crafted Profile argument to execute arbitrary code with system-level impact.
Business Impact
The potential impact of this vulnerability is critical, as it allows for full system compromise, including unauthorized code execution, data exfiltration, and potential disruption of network routing services. With a CVSS score of 9.9, this flaw represents an extreme risk to the availability and integrity of the affected network infrastructure.
Remediation Plan
Immediate Action: Contact the vendor for the latest firmware update, as no specific patch version is currently identified.
Proactive Monitoring: Monitor network traffic for anomalous HTTP requests targeting the device management interface, particularly those containing unusually large or malformed parameters.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, using an ACL or a dedicated management VLAN.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical documentation provided in the GitHub repository referenced in the CVE record.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The flaw is inherently dangerous due to the nature of stack-based overflows, which often allow for reliable remote code execution.
Analyst Recommendation
Given the critical severity and the existence of a public proof-of-concept, users should prioritize securing these devices immediately. Until a vendor-supplied patch is applied, ensure the management interface is not exposed to the public internet and restrict access to authorized personnel only.
Update UTT HiPER 1250GW to the latest version. Monitor for exploitation attempts and review access logs.
A session validation vulnerability in EFM ipTIME T24000M allows remote, unauthenticated attackers to bypass authentication controls via the httpcon_ch...
A session validation vulnerability in EFM ipTIME T24000M allows remote, unauthenticated attackers to bypass authentication controls via the httpcon_check_session_url function.
---METADATA---
VENDOR: EFM
PRODUCT: ipTIME T24000M
AFFECTED_VERSIONS: 14.0, 14.1, 14.2, 14.3, 14.4, 14.5, 14.6, 14.7
CONFIDENCE: high
MISSING: patch
CREDITS: 010hex (VulDB User) (reporter); VulDB CNA Team (coordinator)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394557","name":"VDB-394557 | EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394557/cti","name":"VDB-394557 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78168","name":"CVE-2026-78168 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/883766","name":"Submit #883766 | EFM ipTIME T24000M Version 14.20.0 and earlier Remote Code Execution (RCE)","tags":["third-party-advisory"]},{"url":"https://github.com/AdminSafe/CVE/issues/10","name":null,"tags":["exploit","issue-tracking"]}]
---END_METADATA---
Description Summary:
A session validation flaw in the EFM ipTIME T24000M allows remote, unauthenticated attackers to bypass authentication controls via the httpcon_check_session_url function.
Executive Summary:
A critical authentication bypass vulnerability in the EFM ipTIME T24000M device allows remote attackers to bypass security controls and gain unauthorized access.
Vulnerability Details
CVE-ID: CVE-2026-78168
Affected Software: EFM ipTIME T24000M
Affected Versions: 14.0, 14.1, 14.2, 14.3, 14.4, 14.5, 14.6, 14.7
Vulnerability: This is an improper authentication (CWE-287) vulnerability located in the httpcon_check_session_url function. Remote, unauthenticated attackers can exploit this flaw to bypass the session validation mechanism and gain unauthorized access to the device.
Business Impact
With a CVSS score of 9.8, this vulnerability poses a severe threat to system integrity and security. Unauthorized access to network infrastructure devices can facilitate lateral movement, data interception, and long-term persistence within the organization's network.
Remediation Plan
Immediate Action: Update the firmware of the affected EFM ipTIME T24000M devices to the latest available version provided by the manufacturer.
Proactive Monitoring: Regularly audit access and session logs to detect unauthorized administrative logins or anomalous session creation patterns.
Compensating Controls: If a patch is unavailable, isolate the device management interface from the internet using a firewall and restrict access to internal, trusted management stations only.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the issue-tracking documentation referenced in the CVE record.
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation in the wild, though the existence of a public proof-of-concept makes the risk of exploitation high. The vulnerability's ability to be triggered without authentication significantly lowers the barrier to entry for potential attackers.
Analyst Recommendation
Given the ease of exploitability and the potential for unauthorized access, this vulnerability must be addressed urgently. Administrators should verify their current firmware version and apply updates immediately upon availability to prevent unauthorized device compromise.
Update EFM ipTIME T24000M to the latest version. Monitor for exploitation attempts and review access logs.
An improper authentication vulnerability in the EFM ipTIME T16000M session validation handler allows remote attackers to bypass security controls and...
An improper authentication vulnerability in the EFM ipTIME T16000M session validation handler allows remote attackers to bypass security controls and gain unauthorized access to the device.
---METADATA---
VENDOR: EFM
PRODUCT: ipTIME T16000M
AFFECTED_VERSIONS: 14.20.2
CONFIDENCE: high
MISSING: patch
CREDITS: 010hex (VulDB User) (reporter); VulDB CNA Team (coordinator)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394556","name":"VDB-394556 | EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394556/cti","name":"VDB-394556 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78167","name":"CVE-2026-78167 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/874154","name":"Submit #874154 | EFM ipTIME T16000M 14.20.2 Remote Code Execution (RCE)","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/874302","name":"Submit #874302 | EFM ipTIME T16000M 14.20.2 Arbitrary Password Reset Due to Authentication Bypass (Duplicate)","tags":["third-party-advisory"]},{"url":"https://github.com/AdminSafe/CVE/issues/2","name":null,"tags":["issue-tracking"]},{"url":"https://github.com/AdminSafe/CVE/issues/3","name":null,"tags":["exploit","issue-tracking"]}]
---END_METADATA---
Description Summary:
An improper authentication vulnerability in the EFM ipTIME T16000M session validation handler allows remote, unauthenticated attackers to bypass security controls and gain unauthorized access.
Executive Summary:
A critical authentication bypass vulnerability in the EFM ipTIME T16000M device allows unauthenticated remote attackers to gain full unauthorized access to the system.
Vulnerability Details
CVE-ID: CVE-2026-78167
Affected Software: EFM ipTIME T16000M
Affected Versions: 14.20.2
Vulnerability: The vulnerability exists in the session validation handler, specifically the httpcon_check_session_url function, which fails to correctly verify user credentials. This allows an unauthenticated attacker to bypass authentication entirely and gain administrative control over the affected device.
Business Impact
A CVSS score of 10.0 indicates a maximum level of risk, as the vulnerability is remotely exploitable without privileges or user interaction. Successful exploitation would grant an attacker complete control over the device, leading to potential network-wide surveillance, traffic interception, or total service disruption.
Remediation Plan
Immediate Action: Seek the latest firmware release from the vendor to resolve the session validation flaw.
Proactive Monitoring: Review device access logs for suspicious administrative sessions originating from unknown or external IP addresses.
Compensating Controls: Place the device management interface behind a VPN or firewall, ensuring it is not accessible from untrusted networks.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the issue-tracking documentation referenced in the CVE record.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The flaw is highly dangerous due to the complete lack of required authentication for an attacker to gain full system access.
Analyst Recommendation
This vulnerability represents the highest possible risk level and requires immediate attention. Administrators must ensure that the device is not reachable from the public internet and should apply the vendor-provided firmware update as soon as it is released.
Update EFM ipTIME T16000M to the latest version. Monitor for exploitation attempts and review access logs.
A vulnerability was found in warmcat libwebsockets 4
A vulnerability was found in warmcat libwebsockets 4
---METADATA---
VENDOR: warmcat
PRODUCT: libwebsockets
AFFECTED_VERSIONS: 4.5.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A memory corruption vulnerability in warmcat libwebsockets allows for out-of-bounds writes, which can be triggered by a remote attacker.
Executive Summary:
An out-of-bounds write vulnerability in libwebsockets version 4.5.0 introduces a risk of memory corruption, potentially allowing remote attackers to crash the service or execute code.
Vulnerability Details
CVE-ID: CVE-2026-78161
Affected Software: warmcat libwebsockets
Affected Versions: 4.5.0
Vulnerability: The vulnerability is an out-of-bounds write (CWE-787) occurring during the parsing process, specifically within the lecp module. This memory corruption flaw is reachable by an unauthenticated attacker.
Business Impact
Memory corruption vulnerabilities often lead to service instability, denial of service, or potentially arbitrary code execution. Given the CVSS score of 7.3, this issue represents a significant threat to services relying on libwebsockets for network communication, potentially impacting both system availability and security.
Remediation Plan
Immediate Action: Update to the patched version of libwebsockets as identified in the project's commit history (commit 1d44554a1bb262db63ff4e240152a9deecd99054).
Proactive Monitoring: Monitor for unexpected service crashes or restarts that may indicate successful exploitation of memory corruption flaws.
Compensating Controls: Ensure that the application is running with memory protection features enabled, such as Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP).
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, a public proof-of-concept exists, so exploitation risk should be treated as credible. The availability of a PoC significantly lowers the barrier for attackers to develop a functional exploit.
Analyst Recommendation
The presence of a public proof-of-concept necessitates immediate action. Developers and system administrators should pull the latest version of libwebsockets or apply the specific fix commit provided by the vendor to remediate this memory corruption risk.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export
OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export
---METADATA---
VENDOR: pgAdmin
PRODUCT: pgAdmin 4
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
An OS command injection vulnerability exists within the pgAdmin 4 Import/Export query export functionality.
Executive Summary:
A critical OS command injection vulnerability in pgAdmin 4 could allow an attacker to execute arbitrary commands on the host server.
Vulnerability Details
CVE-ID: CVE-2026-7816
Affected Software: pgAdmin 4
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability, classified as CWE-78, exists in the Import/Export query export feature. It allows an authenticated user to inject malicious OS commands that will be executed by the underlying server operating system.
Business Impact
Successful exploitation allows an attacker to gain full control over the server hosting pgAdmin 4. Given that pgAdmin is often used to manage sensitive database environments, this could lead to massive data theft, database corruption, or complete host takeover. The 8.8 CVSS score signifies a high urgency.
Remediation Plan
Immediate Action: Update pgAdmin 4 to the latest version that includes the fix for this command injection vulnerability.
Proactive Monitoring: Audit database and application logs for suspicious command-line activity or unexpected process spawning from the pgAdmin user.
Compensating Controls: Restrict access to the pgAdmin web interface to trusted internal networks and enforce strict user permissions within the application.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of May 27, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
This vulnerability is highly critical due to the potential for OS-level compromise. Administrators must update their pgAdmin installations immediately and review access logs for any evidence of prior exploitation attempts.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in Open5GS 2
A vulnerability was detected in Open5GS 2
---METADATA---
VENDOR: Open5GS
PRODUCT: Open5GS
AFFECTED_VERSIONS: 2.8.0
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A memory corruption vulnerability, specifically an out-of-bounds read, exists in Open5GS 2.8.0, potentially allowing for system instability or unauthorized information disclosure.
Executive Summary:
Open5GS version 2.8.0 contains a high-severity memory corruption vulnerability that could be leveraged by an authenticated user to cause service disruption.
Vulnerability Details
CVE-ID: CVE-2026-78157
Affected Software: Open5GS
Affected Versions: 2.8.0
Vulnerability: This vulnerability involves an out-of-bounds read and general memory corruption within the Open5GS software. It requires the attacker to have low-level privileges (authenticated) to trigger the flawed function, which may result in an application crash or potentially more severe memory exploitation.
Business Impact
The vulnerability carries a CVSS score of 7.4, indicating a high risk to availability and system integrity. In a telecommunications or core network environment, an application crash could lead to a denial of service for connected users, impacting critical communication infrastructure and causing significant operational downtime.
Remediation Plan
Immediate Action: Update Open5GS to the latest stable version where the fix has been implemented, as referenced in the upstream commit.
Proactive Monitoring: Review system logs for signs of segmentation faults, unexpected application restarts, or abnormal memory usage patterns in the Open5GS processes.
Compensating Controls: Employ memory protection mechanisms, such as Address Space Layout Randomization (ASLR) or Data Execution Prevention (DEP), to reduce the likelihood of successful memory corruption exploitation.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of Aug 24, 2026, there is no public information indicating active exploitation in the wild. While CISA's SSVC assessment indicates a proof-of-concept exists, exploitation risk should be treated as credible. Memory corruption flaws are often difficult to weaponize but provide significant leverage to an attacker if successful.
Analyst Recommendation
Given the critical role of Open5GS in network infrastructure, administrators should prioritize applying the vendor-supplied security updates. The existence of a proof-of-concept increases the urgency of patching to prevent potential exploitation of this memory corruption flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in Open5GS 2
A security vulnerability has been detected in Open5GS 2
---METADATA---
VENDOR: Open5GS
PRODUCT: Open5GS
AFFECTED_VERSIONS: 2.8.0
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A heap-based buffer overflow vulnerability in Open5GS 2.8.0 allows authenticated low-privilege attackers to cause memory corruption via network-based vectors.
Executive Summary:
A heap-based buffer overflow vulnerability in Open5GS 2.8.0 poses a high risk of memory corruption and potential system instability.
Vulnerability Details
CVE-ID: CVE-2026-78156
Affected Software: Open5GS Open5GS
Affected Versions: 2.8.0
Vulnerability: This vulnerability involves a heap-based buffer overflow and memory corruption flaw. It is accessible to authenticated users with low privileges over a network connection.
Business Impact
The exploitation of this flaw could lead to a denial of service or potential remote code execution, depending on the memory layout. With a CVSS score of 7.4, this is classified as a high-severity issue that could disrupt critical telecommunications infrastructure and lead to unauthorized system behavior.
Remediation Plan
Immediate Action: Review the provided vendor references and GitHub commit history to apply the upstream fix, as a formal patch version is not explicitly listed.
Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts in the Open5GS daemon, which may indicate exploitation attempts.
Compensating Controls: Implement network segmentation to restrict access to the Open5GS service to only authorized and trusted endpoints.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its nature as a memory corruption vulnerability within a core networking component.
Analyst Recommendation
Given the high severity of this memory corruption vulnerability, administrators should prioritize the review of the linked GitHub commit to implement the necessary code changes. Testing should be performed in a staging environment before deploying the fix to production systems to ensure continued service availability.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The StackGres operator is vulnerable to privilege escalation, allowing a low-privilege tenant who owns a database to gain administrator privileges.
The StackGres operator is vulnerable to privilege escalation, allowing a low-privilege tenant who owns a database to gain administrator privileges.
---METADATA---
VENDOR: OnGres
PRODUCT: StackGres
AFFECTED_VERSIONS: 0 through 1.18.8
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The StackGres operator is vulnerable to privilege escalation, allowing a low-privilege tenant who owns a database to gain administrator privileges.
Executive Summary:
The StackGres operator contains a critical privilege escalation flaw that allows low-privileged users to gain full administrator access to the system.
Vulnerability Details
CVE-ID: CVE-2026-78155
Affected Software: OnGres StackGres
Affected Versions: 0 through 1.18.8
Vulnerability: The vulnerability is classified as an untrusted search path issue (CWE-426). It allows an authenticated user with low privileges to escalate their access level to that of an administrator within the StackGres environment.
Business Impact
This vulnerability poses a major threat to multi-tenant environments, as it allows for total system compromise by a single compromised tenant account. Given the CVSS score of 9.9, the potential for unauthorized administrative access constitutes a catastrophic security failure for affected infrastructures.
Remediation Plan
Immediate Action: Upgrade the StackGres operator to version 1.19.0 as recommended by the vendor.
Proactive Monitoring: Audit logs for administrative privilege changes and monitor for unexpected activity associated with low-privileged service accounts or tenant roles.
Compensating Controls: Restrict access to the StackGres management interface to trusted internal networks and implement strict Role-Based Access Control (RBAC) policies until the patch is applied.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Aug 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Privilege escalation flaws in operators are particularly dangerous due to the high-level permissions these tools possess within a cluster.
Analyst Recommendation
Given the extreme severity of this privilege escalation vulnerability, immediate remediation is required to maintain the integrity of the StackGres deployment. Administrators should prioritize the upgrade to version 1.19.0 to prevent unauthorized escalation and potential total system takeover.
Update OnGres StackGres to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
A vulnerability was identified in the-momentum open-wearables up to 0
A vulnerability was identified in the-momentum open-wearables up to 0
---METADATA---
VENDOR: the-momentum
PRODUCT: open-wearables
AFFECTED_VERSIONS: Up to 0.6.2
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A missing authentication vulnerability in the open-wearables Public Invitation-Code Redemption Endpoint allows remote attackers to bypass security controls via the code argument.
Executive Summary:
An authentication bypass vulnerability in the-momentum open-wearables allows unauthenticated remote attackers to redeem invitation codes, potentially compromising user registration workflows.
Vulnerability Details
CVE-ID: CVE-2026-78154
Affected Software: the-momentum open-wearables
Affected Versions: 0.6.0, 0.6.1, 0.6.2
Vulnerability: This is a missing authentication vulnerability (CWE-306) located in the redeem_invitation_code function within the backend/app/api/routes/v1/user_invitation_code.py file. The endpoint fails to perform necessary authentication checks, allowing remote attackers to manipulate the code argument to perform unauthorized actions.
Business Impact
The ability to bypass authentication for invitation code redemption can lead to unauthorized account creation or abuse of business logic within the open-wearables platform. With a CVSS score of 7.3, this vulnerability poses a risk to system integrity and could be leveraged to gain unauthorized access or manipulate user-related data.
Remediation Plan
Immediate Action: Update the open-wearables deployment to a version beyond 0.6.2 once the vendor provides a fix, or apply the specific security patches referenced in the GitHub issue tracker.
Proactive Monitoring: Review application access logs for abnormal volumes of invitation code redemption requests originating from single or suspicious IP addresses.
Compensating Controls: Implement rate limiting on the invitation code redemption endpoint to mitigate the impact of automated exploitation attempts.
Exploitation Status
Public Exploit Available: No confirmed public exploit is available in the provided data.
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation or a published proof-of-concept for this vulnerability. The flaw's exploitability is limited to the functionality of the redemption endpoint.
Analyst Recommendation
Security teams should track the official the-momentum GitHub repository for a fix and prioritize updating the affected components. Until a patch is applied, ensure that monitoring is in place to detect anomalous activity related to the invitation system.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SQL injection vulnerability in pgAdmin 4 Maintenance Tool
SQL injection vulnerability in pgAdmin 4 Maintenance Tool
---METADATA---
VENDOR: pgAdmin
PRODUCT: pgAdmin 4
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the pgAdmin 4 Maintenance Tool allows attackers to manipulate database queries.
Executive Summary:
A critical SQL injection vulnerability in the pgAdmin 4 Maintenance Tool could allow unauthorized database access and manipulation.
Vulnerability Details
CVE-ID: CVE-2026-7815
Affected Software: pgAdmin 4
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability resides in the Maintenance Tool component of pgAdmin 4. It enables an attacker to inject arbitrary SQL commands, potentially bypassing authentication or data access controls to retrieve or modify backend database content.
Business Impact
With a CVSS score of 8.8, this flaw poses a severe threat to data confidentiality and integrity. Successful exploitation could lead to the unauthorized disclosure of sensitive PII, financial records, or credentials stored within the managed databases, resulting in major regulatory and reputational damage.
Remediation Plan
Immediate Action: Update the pgAdmin 4 installation to the latest available version provided by the vendor.
Proactive Monitoring: Enable and review database query logs for anomalous syntax or unexpected access patterns originating from the pgAdmin service.
Compensating Controls: Implement strict firewall rules to ensure that only authorized administrative workstations can access the pgAdmin server interface.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of May 27, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Organizations utilizing pgAdmin 4 must prioritize this update to prevent potential data breaches. Administrators should verify their current version and apply the patch as soon as it is released to mitigate the risk of SQL injection.
Apply vendor patches immediately. Review database access controls and enable query logging.
A vulnerability was found in ggml-org llama
A vulnerability was found in ggml-org llama
---METADATA---
VENDOR: ggml-org
PRODUCT: llama.cpp
AFFECTED_VERSIONS: bec4772f6
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A critical deserialization vulnerability in the ggml-rpc component of llama.cpp at commit bec4772f6 allows remote unauthenticated attackers to execute arbitrary code.
Executive Summary:
A critical deserialization flaw in ggml-org llama.cpp allows remote unauthenticated attackers to achieve arbitrary code execution by sending malicious network input.
Vulnerability Details
CVE-ID: CVE-2026-78147
Affected Software: ggml-org llama.cpp
Affected Versions: bec4772f6
Vulnerability: This is a deserialization vulnerability (CWE-502) in the deserialize_tensor function of the ggml-rpc component. The application fails to validate operation types and parameters from network input, allowing unauthenticated remote attackers to trigger malicious payloads, potentially leading to arbitrary code execution or denial of service.
Business Impact
This vulnerability is highly severe because it allows for unauthenticated remote code execution, which can lead to complete system compromise. Given the CVSS score of 7.3, the potential for unauthorized control over the server environment, combined with the risk of service disruption, makes this a high-priority security concern.
Remediation Plan
Immediate Action: Immediately update the llama.cpp environment to a commit or version that includes the fix for this deserialization flaw.
Proactive Monitoring: Monitor network traffic for anomalous or malformed RPC requests directed at the llama.cpp component, which may indicate exploitation attempts.
Compensating Controls: Isolate the llama.cpp instance within a secure network segment and use a firewall to restrict access to the RPC service to trusted sources only.
Exploitation Status
Public Exploit Available: Yes, a proof-of-concept exists as noted in the additional context.
Analyst Notes: As of August 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment, a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly dangerous due to its potential for remote code execution.
Analyst Recommendation
Due to the availability of a proof-of-concept and the nature of the vulnerability, this issue poses a significant risk. Organizations running the affected version should prioritize updating their software and restricting network access to the RPC interface to minimize the attack surface.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1
---METADATA---
VENDOR: code-projects
PRODUCT: Barangay Resident Profiling Management System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the Barangay Resident Profiling Management System 1.0 allows remote attackers to bypass authorization via the ID parameter in /boarders.php.
Executive Summary:
A critical SQL injection vulnerability in the Barangay Resident Profiling Management System 1.0 allows unauthenticated remote attackers to bypass authorization controls.
Vulnerability Details
CVE-ID: CVE-2026-78143
Affected Software: code-projects Barangay Resident Profiling Management System
Affected Versions: 1.0
Vulnerability: The application is susceptible to a SQL injection attack due to improper sanitization of the ID argument within the /boarders.php file of the Boarder Management Module. This flaw permits unauthenticated remote attackers to manipulate database queries and bypass authorization mechanisms.
Business Impact
The vulnerability carries a CVSS score of 7.3, indicating a high risk of unauthorized access and potential data compromise. Successful exploitation could allow an attacker to extract sensitive resident information, modify database records, or manipulate system logic, leading to significant reputational damage and a loss of data integrity within the management system.
Remediation Plan
Immediate Action: There is no official patch currently available; administrators should restrict network access to the /boarders.php endpoint and implement strict input validation for the ID parameter.
Proactive Monitoring: Monitor server access logs for unusual patterns or SQL syntax fragments originating from the ID parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules specifically configured to detect and block SQL injection attempts targeting the affected application.
Exploitation Status
Public Exploit Available: Yes, a public exploit is available via the provided reference links.
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation in the wild, though the existence of a public exploit significantly increases the risk of opportunistic attacks.
Analyst Recommendation
Due to the high severity and the availability of public exploit code, this vulnerability poses a credible threat. Administrators are urged to apply rigorous input filtering immediately and limit access to the affected module to authorized personnel only until a formal vendor patch is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in Tenda CH22 1
A vulnerability has been found in Tenda CH22 1
---METADATA---
VENDOR: Tenda
PRODUCT: CH22
AFFECTED_VERSIONS: 1.0.0.1
CONFIDENCE: high
MISSING: patch
CREDITS: ysnysnysn (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/394524","name":"VDB-394524 | Tenda CH22 exeCommand formexeCommand command injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/394524/cti","name":"VDB-394524 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-78141","name":"CVE-2026-78141 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/882284","name":"Submit #882284 | Tenda CH22 V1.0.0.1 Command Injection","tags":["third-party-advisory"]},{"url":"https://candle-throne-f75.notion.site/Tenda-CH22-formexeCommand-396df0aa11858036b0cdf7a7562d4a67","name":null,"tags":["exploit"]},{"url":"https://www.tenda.com.cn/","name":null,"tags":["product"]}]
---END_METADATA---
Description Summary:
The Tenda CH22 router contains a command injection vulnerability in the web interface that allows an authenticated attacker to execute arbitrary system commands.
Executive Summary:
An authenticated command injection vulnerability in the Tenda CH22 router allows for the execution of unauthorized system commands.
Vulnerability Details
CVE-ID: CVE-2026-78141
Affected Software: Tenda CH22
Affected Versions: 1.0.0.1
Vulnerability: The device suffers from a command injection flaw within the formexeCommand function, which permits an authenticated attacker to inject and execute system-level commands through the web interface.
Business Impact
A successful exploit allows an attacker with low-level credentials to escalate their control over the device. With a CVSS score of 7.4, this vulnerability presents a high risk to network integrity, potentially enabling attackers to pivot into the internal network or manipulate traffic flowing through the router.
Remediation Plan
Immediate Action: Contact Tenda support or check the official manufacturer website for firmware updates to address this command injection flaw.
Proactive Monitoring: Monitor system logs for unexpected process execution or unauthorized configuration changes.
Compensating Controls: Implement strict network segmentation and ensure that the router administration interface is not exposed to the public internet.
Exploitation Status
Public Exploit Available: Yes — a published proof-of-concept exists as documented in a technical writeup.
Analyst Notes: As of August 24, 2026, there is no public information indicating active exploitation in the wild; however, a proof-of-concept is publicly available. The vulnerability is highly exploitable given the lack of sufficient input sanitization in the formexeCommand function.
Analyst Recommendation
This vulnerability highlights the risk of insufficient input validation on network hardware. Organizations using the Tenda CH22 should prioritize firmware updates or apply network-level access controls to mitigate the risk of command execution by unauthorized or compromised accounts.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unau...
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO off
---METADATA---
VENDOR: StoreGrowth
PRODUCT: StoreGrowth (WordPress Plugin)
AFFECTED_VERSIONS: StoreGrowth WordPress plugin before 2.1.2
CONFIDENCE: high
MISSING: none
PROFILE: grounded@2cca291e317a
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-09-02T09:35:02.173Z
CREDITS: Shikhali Jamalzade (finder); WPScan (coordinator)
SOURCES_JSON: [{"url":"https://wpscan.com/vulnerability/15d1a53b-c5f3-4509-9889-ddc48507df35/","name":null,"tags":["exploit","vdb-entry","technical-description"]}]
---END_METADATA---
Description Summary:
The StoreGrowth WordPress plugin fails to validate product prices on unauthenticated actions, allowing attackers to modify cart totals via the BOGO offer feature.
Executive Summary:
A critical vulnerability in the StoreGrowth WordPress plugin allows unauthenticated attackers to manipulate product pricing during checkout, posing a significant financial risk to e-commerce operations.
Vulnerability Details
CVE-ID: CVE-2026-78137
Affected Software: StoreGrowth WordPress plugin
Affected Versions: StoreGrowth WordPress plugin before 2.1.2
Vulnerability: The plugin suffers from improper server-side validation of browser-supplied price parameters during unauthenticated checkout actions. This flaw allows an unauthenticated attacker to inject arbitrary prices into the shopping cart, which are subsequently honored during the payment process when the BOGO offer feature is active.
Business Impact
This vulnerability carries a CVSS score of 7.5, reflecting its high impact on the integrity of financial transactions. Successful exploitation enables unauthorized price manipulation, which can lead to direct revenue loss, inventory depletion, and potential legal or compliance issues regarding transaction records. The ability for unauthenticated actors to perform this attack without specialized access makes it a high-priority risk for any organization utilizing this plugin.
Remediation Plan
Immediate Action: Update the StoreGrowth plugin to version 2.1.2 or later immediately to implement proper server-side price validation.
Proactive Monitoring: Review transaction logs for anomalous checkout totals or unusually low-priced orders that do not align with current promotional campaigns.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block suspicious POST requests directed at the plugin checkout endpoints, or temporarily disable the BOGO offer feature until the patch is applied.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 27, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its lack of authentication requirements and direct impact on the checkout flow.
Analyst Recommendation
Given the ease of exploitation and the direct financial impact, administrators must prioritize upgrading to version 2.1.2. Failure to patch allows attackers to bypass standard store pricing, directly impacting the bottom line. Security teams should verify that all instances of the StoreGrowth plugin are updated across their environment to eliminate this vector of attack.
Update Unknown StoreGrowth to the latest version. Monitor for exploitation attempts and review access logs.
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data
---METADATA---
VENDOR: chirpmyradio
PRODUCT: CHIRP
AFFECTED_VERSIONS: 0 up to (excluding) 39178dbfc4fece083ab9ed20286d6ae3a91a718e
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The chirpmyradio CHIRP software is susceptible to eval injection via specially crafted CSV data, allowing for potential arbitrary code execution.
Executive Summary:
An eval injection vulnerability in CHIRP prior to commit 39178db allows attackers to execute arbitrary code through malicious CSV files.
Vulnerability Details
CVE-ID: CVE-2026-78136
Affected Software: chirpmyradio CHIRP
Affected Versions: 0 up to (excluding) 39178dbfc4fece083ab9ed20286d6ae3a91a718e
Vulnerability: This is an Improper Neutralization of Directives in Dynamically Evaluated Code (CWE-95) vulnerability. The application fails to properly sanitize CSV input before processing it with an eval function, which can be triggered by an unauthenticated user if they are coerced into opening a malicious file.
Business Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the host system with the privileges of the user running the application. Given the CVSS score of 7.8, this poses a significant risk to system integrity and confidentiality, potentially leading to a full system compromise or the exfiltration of sensitive configuration data.
Remediation Plan
Immediate Action: Update CHIRP to the version containing the fix, which is represented by commit 39178dbfc4fece083ab9ed20286d6ae3a91a718e or later.
Proactive Monitoring: Monitor system logs for unexpected child processes spawned by the CHIRP application, particularly those occurring immediately after importing or opening CSV files.
Compensating Controls: Exercise caution when opening CSV files from untrusted sources within the application until the software can be updated.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of August 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is inherently dangerous because it leverages unsafe dynamic code evaluation, which is a common vector for remote code execution.
Analyst Recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential code execution. Administrators should prioritize updating the CHIRP software to the patched version as soon as it is available to neutralize the risk of eval injection.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An authorization flaw in pgAdmin 4 allows authenticated users to access private server data and execute arbitrary commands by manipulating object IDs...
An authorization flaw in pgAdmin 4 allows authenticated users to access private server data and execute arbitrary commands by manipulating object IDs and bypassing access controls.
---METADATA---
VENDOR: pgAdmin
PRODUCT: pgAdmin 4
AFFECTED_VERSIONS: Before 9.15
---END_METADATA---
Description Summary:
An authorization flaw in pgAdmin 4 allows authenticated users to access private server data and execute arbitrary commands by manipulating object IDs and bypassing access controls.
Executive Summary:
A critical authorization vulnerability in pgAdmin 4 allows authenticated users to escalate privileges and execute arbitrary commands, posing a severe risk to database management security.
Vulnerability Details
CVE-ID: CVE-2026-7813
Affected Software: pgAdmin pgAdmin 4
Affected Versions: Before 9.15
Vulnerability: This is an authorization bypass and privilege escalation vulnerability occurring within the server mode modules. An authenticated user can leverage insecure API endpoints to access unauthorized objects and execute arbitrary shell commands via writable configuration fields.
Business Impact
The potential for unauthorized access to sensitive database credentials, combined with the ability to execute arbitrary system commands, represents a catastrophic risk to organizational data integrity. With a CVSS score of 9.9, this vulnerability could lead to total compromise of the pgAdmin server and any connected database environments, potentially resulting in massive data exfiltration and complete system takeover.
Remediation Plan
Immediate Action: Upgrade all instances of pgAdmin 4 to version 9.15 or later immediately to implement the centralized access control framework.
Proactive Monitoring: Review application access logs for unusual patterns of object ID requests or attempts to access server configurations outside of a user's assigned scope.
Compensating Controls: Restrict access to the pgAdmin management interface to trusted internal networks and implement robust multi-factor authentication for all users.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of May 11, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the critical nature of the flaw and the ease of exploitation, the potential for malicious activity is extremely high.
Analyst Recommendation
Given the severity of this vulnerability, administrators should prioritize patching pgAdmin 4 environments immediately. The ability for non-privileged users to execute arbitrary commands makes this an urgent security priority that requires non-disruptive but immediate remediation.
Update pgAdmin Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set
---METADATA---
VENDOR: Tecnativa
PRODUCT: docker-socket-proxy
AFFECTED_VERSIONS: 0 through 0.5.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A security flaw in docker-socket-proxy fails to properly restrict read access to the Docker API /containers namespace when the CONTAINERS environment variable is configured.
Executive Summary:
An access control vulnerability in docker-socket-proxy allows unauthorized access to container information, potentially exposing sensitive filesystem metadata.
Vulnerability Details
CVE-ID: CVE-2026-78122
Affected Software: Tecnativa docker-socket-proxy
Affected Versions: 0 through 0.5.0
Vulnerability: This is an insufficient granularity of access control (CWE-1220) issue where read-only endpoints are not correctly gated. An attacker on the adjacent network can exploit this to gain unauthorized information about container state and configurations.
Business Impact
Successful exploitation allows an attacker to gather intelligence on the container environment, which can be leveraged to plan further attacks. While the CVSS score of 7.4 indicates high severity, the impact is limited to information disclosure regarding container filesystems and metadata rather than full system execution.
Remediation Plan
Immediate Action: Update docker-socket-proxy to a version beyond 0.5.0 that addresses the access control gating. Review the configuration of the CONTAINERS environment variable to ensure it is not inadvertently granting broad access.
Proactive Monitoring: Review container access logs for unexpected queries to the /containers API namespace. Monitor for unusual spikes in read requests to the Docker socket.
Compensating Controls: Ensure the docker-socket-proxy is only accessible over a restricted network segment or via a VPN, and verify that the host machine's firewall rules are strictly enforced.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of Aug 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw stems from a logic error in the haproxy configuration that fails to enforce expected security boundaries.
Analyst Recommendation
Administrators should prioritize updating to the latest version of docker-socket-proxy to ensure proper access control logic is applied. Additionally, verify that environment variables are configured with the principle of least privilege to minimize the potential impact of any access control flaws.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8
A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8
---METADATA---
VENDOR: 54yyyu
PRODUCT: code-mcp
AFFECTED_VERSIONS: 54yyyu code-mcp revisions up to 4cfc4643541a110c906d93635b391bf7e357f4a8
CONFIDENCE: high
MISSING: patch
CREDITS: CPT_Penner (VulDB User) (reporter); VulDB CNA Team (coordinator)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/361072","name":"VDB-361072 | 54yyyu code-mcp MCP Tool server.py git_operation command injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/361072/cti","name":"VDB-361072 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/807752","name":"Submit #807752 | 54yyyu code-mcp 4cfc4643541a110c906d93635b391bf7e357f4a8 Command Injection","tags":["third-party-advisory"]},{"url":"https://github.com/54yyyu/code-mcp/issues/5","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://github.com/54yyyu/code-mcp/","name":null,"tags":["product"]}]
PROFILE: daily@50ba49e8b7aa
MODEL: gemini-3.5-flash-lite
GENERATED: 2026-08-29T11:43:16.425Z
---END_METADATA---
Description Summary:
A command injection vulnerability exists in the git_operation function of 54yyyu code-mcp, allowing remote unauthenticated attackers to execute arbitrary shell commands.
Executive Summary:
An unauthenticated remote command injection vulnerability in 54yyyu code-mcp allows attackers to achieve partial system access via the git_operation function.
Vulnerability Details
CVE-ID: CVE-2026-7812
Affected Software: 54yyyu code-mcp
Affected Versions: 54yyyu code-mcp revisions up to 4cfc4643541a110c906d93635b391bf7e357f4a8
Vulnerability: This is a command injection flaw occurring in the git_operation function within src/code_mcp/server.py due to unsafe string formatting and subprocess execution with shell=True, requiring no authentication.
Business Impact
A successful exploit permits malicious actors to execute arbitrary operating system commands, threatening the confidentiality, integrity, and availability of the host system and stored data. Although the CVSS score is 7.3, the presence of a public proof-of-concept and remote attack vector elevate the operational risk for deployed instances.
Remediation Plan
Immediate Action: Restrict network access to the MCP server and disable the vulnerable git_operation tool until a vendor patch is released.
Proactive Monitoring: Monitor system logs for anomalous child processes spawned by the python interpreter and unexpected command line arguments.
Compensating Controls: Deploy a Web Application Firewall or network access control list to limit inbound connections to trusted management sources only.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists via the GitHub issue reference.
Analyst Notes: As of May 6, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible.
Analyst Recommendation
Given the availability of a public proof-of-concept and the severity of command injection, administrators must treat this flaw with high urgency. Because a formal vendor patch is currently unavailable, organizations should apply compensating network restrictions and isolate the service to prevent potential compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: ManageNinja
PRODUCT: FluentCRM Pro
AFFECTED_VERSIONS: n/a through 3.1.12
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An SQL injection vulnerability in the FluentCRM Pro plugin allows authenticated authors to execute arbitrary database queries.
Executive Summary:
An authenticated SQL injection vulnerability in the FluentCRM Pro plugin could allow authorized authors to manipulate database queries and potentially access sensitive data.
Vulnerability Details
CVE-ID: CVE-2026-78270
Affected Software: ManageNinja FluentCRM Pro
Affected Versions: n/a through 3.1.12
Vulnerability: This vulnerability is a SQL injection (CWE-89) that occurs due to insufficient input validation. It requires high-privileged (Author) access, allowing the attacker to interact with the backend database in an unauthorized manner.
Business Impact
The vulnerability allows for potential data exfiltration from the CRM database, which often contains highly sensitive customer information and marketing data. With a CVSS score of 7.6, the risk of data compromise is significant, potentially leading to regulatory non-compliance and reputational damage.
Remediation Plan
Immediate Action: Update the FluentCRM Pro plugin to version 3.1.13 or later immediately.
Proactive Monitoring: Review database logs for unusual query activity and audit the permissions of all accounts with Author-level access.
Compensating Controls: Utilize a Web Application Firewall to filter malicious SQL syntax from incoming HTTP requests.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of August 25, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the exploit requires Author-level privileges, the potential impact on customer data necessitates a rapid patching cycle.
Analyst Recommendation
Security teams must prioritize updating this plugin to the latest version. Given the high-privilege requirement, it is also recommended to review existing user roles within the WordPress environment to ensure that only trusted personnel hold Author-level access.