A flaw has been found in Tenda F456 1
Description
A flaw has been found in Tenda F456 1
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 23391 vulnerabilities with AI analyst insights
A flaw has been found in Tenda F456 1
A flaw has been found in Tenda F456 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attacker...
An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attackers to gain unauthorized elevated access.
---METADATA---
VENDOR: miniOrange
PRODUCT: miniorange otp verification
AFFECTED_VERSIONS: <= 5.5.1
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attackers to gain unauthorized elevated access.
Executive Summary:
A critical privilege escalation vulnerability in the miniOrange OTP Verification WordPress plugin allows unauthenticated attackers to gain unauthorized administrative access to the site.
Vulnerability Details
CVE-ID: CVE-2026-61967
Affected Software: miniOrange miniorange otp verification
Affected Versions: <= 5.5.1
Vulnerability: The plugin suffers from a weak password recovery mechanism (CWE-640) that permits an unauthenticated attacker to escalate privileges. This flaw bypasses standard authentication controls, granting the attacker excessive permissions.
Business Impact
An attacker successfully exploiting this vulnerability can obtain administrative control over the affected WordPress instance. This leads to total compromise, including the ability to exfiltrate sensitive data, modify site content, or install malicious backdoors. The CVSS score of 9.8 reflects the high severity of full system impact.
Remediation Plan
Immediate Action: Update the miniOrange OTP Verification plugin to version 5.5.2 or later immediately.
Proactive Monitoring: Audit WordPress user logs for unauthorized account creation or unexpected elevation of user roles.
Compensating Controls: Ensure that WordPress administrative panels are not exposed to the public internet and utilize a Web Application Firewall (WAF) to filter malicious requests.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 13, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the lack of authentication required for exploitation.
Analyst Recommendation
The severity of this privilege escalation flaw requires immediate remediation. All WordPress administrators should verify their plugin versions and ensure that the update to 5.5.2 is applied across all environments to prevent unauthorized access and potential site takeover.
Update miniOrange miniorange otp verification to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute mali...
The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute malicious code on the host server.
---METADATA---
VENDOR: Hakan Ozevin
PRODUCT: WP BASE Booking
AFFECTED_VERSIONS: n/a through 6.3.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute malicious code on the host server.
Executive Summary:
A critical unauthenticated arbitrary code execution vulnerability in the WP BASE Booking plugin poses a severe risk of total system compromise.
Vulnerability Details
CVE-ID: CVE-2026-61962
Affected Software: Hakan Ozevin WP BASE Booking
Affected Versions: n/a through 6.3.0
Vulnerability: This vulnerability is a code injection flaw, identified as CWE-94, which allows unauthenticated remote attackers to execute arbitrary code. The vulnerability exists due to improper control over the generation of code within the plugin, requiring no user interaction or elevated privileges to exploit.
Business Impact
The CVSS score of 10.0 reflects the maximum severity of this vulnerability, as it allows for complete unauthorized control over the affected server. Successful exploitation could lead to full data theft, permanent system damage, or the deployment of ransomware, resulting in significant operational downtime and potential regulatory penalties.
Remediation Plan
Immediate Action: Update the WP BASE Booking plugin to version 6.3.1 or the latest available version immediately.
Proactive Monitoring: Monitor server access logs for unusual requests directed at the plugin directory and examine system logs for unexpected process execution.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious injection attempts targeting WordPress plugin parameters.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 13, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Given the ease of exploitation and the critical nature of code injection, administrators should prioritize patching to prevent potential future abuse.
Analyst Recommendation
This vulnerability represents a critical security risk due to the lack of required authentication and the potential for total system takeover. All organizations utilizing the WP BASE Booking plugin must apply the vendor provided update immediately to mitigate the risk of remote code execution.
Update Hakan Ozevin WP BASE Booking to the latest version. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in Tenda F456 1
A vulnerability was detected in Tenda F456 1
---METADATA---
VENDOR: Tenda
PRODUCT: F456
AFFECTED_VERSIONS: 1.0.0.5
CONFIDENCE: high
MISSING: patch
CREDITS: LtzHuster (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357118","name":"VDB-357118 | Tenda F456 exeCommand fromexeCommand stack-based overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357118/cti","name":"VDB-357118 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797467","name":"Submit #797467 | Tenda F456 v1.0.0.5 Stack-based Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_113/README.md","name":null,"tags":["exploit"]},{"url":"https://www.tenda.com.cn/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.739Z
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the Tenda F456 /goform/exeCommand function allows remote attackers to execute code or cause a denial of service via the cmdinput parameter.
Executive Summary:
A critical remote code execution vulnerability in Tenda F456 routers poses a severe risk of system compromise due to a stack-based buffer overflow.
Vulnerability Details
CVE-ID: CVE-2026-6196
Affected Software: Tenda F456
Affected Versions: 1.0.0.5
Vulnerability: The device is vulnerable to a stack-based buffer overflow in the fromexeCommand function within the /goform/exeCommand endpoint. An authenticated attacker can trigger this memory corruption by sending a crafted cmdinput parameter, as the application fails to perform necessary length checks before copying the input into a fixed-size stack buffer.
Business Impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution on the affected hardware, potentially leading to a full system takeover, unauthorized network access, or permanent denial of service. With a CVSS score of 8.8, this flaw represents a High severity risk that could disrupt critical infrastructure or expose sensitive data traversing the network, necessitating immediate attention from security teams.
Remediation Plan
Immediate Action: Since no official patch is currently available, administrators should immediately restrict access to the web management interface of the Tenda F456, ensuring it is not reachable from untrusted networks or the public internet.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/exeCommand endpoint and review device logs for signs of unexpected crashes or service restarts.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) with custom rules to inspect and drop HTTP requests containing abnormally long strings in the cmdinput parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists in a security research write-up hosted on GitHub.
Analyst Notes: As of April 15, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it involves a lack of bounds checking on a user-controlled input, which is a classic vector for memory corruption attacks.
Analyst Recommendation
Given the availability of a public proof-of-concept and the high severity of the potential impact, organizations utilizing Tenda F456 devices must prioritize the isolation of these units. While a vendor patch is awaited, enforcing strict network segmentation and disabling remote management access is the most effective strategy to mitigate the risk of remote exploitation. Monitor vendor communication channels closely for the release of a firmware update that addresses the memory corruption flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms al...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection
---METADATA---
VENDOR: Hannan
PRODUCT: گرویتی فرم فارسی (Persian Gravity Forms)
AFFECTED_VERSIONS: 0 through 3.0.2
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The Persian Gravity Forms plugin for WordPress contains a blind SQL injection vulnerability that allows authenticated attackers with administrative privileges to compromise the database.
Executive Summary:
An authenticated SQL injection vulnerability in the Persian Gravity Forms plugin poses a significant risk to database confidentiality and integrity.
Vulnerability Details
CVE-ID: CVE-2026-61955
Affected Software: Hannan گرویتی فرم فارسی
Affected Versions: 0 through 3.0.2
Vulnerability: This vulnerability involves improper neutralization of special elements in SQL commands, allowing for blind SQL injection. The attack requires the attacker to hold high privileges (PR:H), such as an administrative account.
Business Impact
An attacker who successfully exploits this vulnerability can perform blind SQL injection to extract sensitive information from the WordPress database. The CVSS score of 7.6 indicates high severity, as unauthorized database access can lead to significant data breaches or the alteration of critical site configurations.
Remediation Plan
Immediate Action: Check the vendor’s repository for a security update and apply it immediately; if no patch is available, consider disabling the plugin until a fix is released.
Proactive Monitoring: Review database access logs for suspicious query activity and monitor for unauthorized changes to form data or user configurations.
Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block common SQL injection patterns targeting the plugin's endpoints.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of July 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability's impact is significant, but restricted by the requirement for administrative privileges.
Analyst Recommendation
Security teams should audit all administrative accounts to ensure no unauthorized access is being used to leverage this flaw. Update the plugin as soon as the vendor provides a remediation version to eliminate the underlying vulnerability.
Apply vendor patches immediately. Review database access controls and enable query logging.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15
---METADATA---
VENDOR: QuantumCloud
PRODUCT: Simple Link Directory Pro
AFFECTED_VERSIONS: n/a through 15.0.6
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A Server Side Request Forgery (SSRF) vulnerability exists in the Simple Link Directory Pro WordPress plugin, allowing unauthenticated attackers to perform unauthorized requests.
Executive Summary:
The Simple Link Directory Pro plugin for WordPress contains an SSRF vulnerability that could allow an unauthenticated attacker to force the server to make unauthorized network requests.
Vulnerability Details
CVE-ID: CVE-2026-61953
Affected Software: QuantumCloud Simple Link Directory Pro
Affected Versions: n/a through 15.0.6
Vulnerability: The plugin is susceptible to Server Side Request Forgery (CWE-918) via unauthenticated inputs. This allows the server to be manipulated into interacting with internal or external resources, as indicated by the CVSS scope change (S:C).
Business Impact
Successful exploitation allows an attacker to probe internal network services, bypass firewalls, or interact with external services while appearing to originate from the web server. With a CVSS score of 7.2, this vulnerability poses a significant risk to the security of the internal network infrastructure.
Remediation Plan
Immediate Action: Update the Simple Link Directory Pro plugin to version 15.0.7 or later to sanitize input and prevent unauthorized requests.
Proactive Monitoring: Monitor server egress traffic and logs for unexpected outbound connections, particularly those targeting internal IP addresses or sensitive network services.
Compensating Controls: Restrict server network access to only necessary external endpoints via egress filtering, and deploy a WAF to block malformed requests containing external URLs.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of July 28, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. SSRF flaws are often used as a stepping stone for deeper network penetration.
Analyst Recommendation
Given the potential for internal network discovery and abuse, immediate remediation is required. Administrators must ensure the plugin is updated to the latest version to prevent the server from being leveraged as a proxy for malicious activity.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.
TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.
---METADATA---
VENDOR: themetechmount
PRODUCT: TrueBooker
AFFECTED_VERSIONS: up to and including 1.2.3
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
TrueBooker for WordPress is vulnerable to an unauthenticated privilege escalation, allowing unauthorized users to gain elevated access.
Executive Summary:
The TrueBooker plugin for WordPress contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrative control over the affected site.
Vulnerability Details
CVE-ID: CVE-2026-61951
Affected Software: themetechmount TrueBooker
Affected Versions: up to and including 1.2.3
Vulnerability: This is an incorrect privilege assignment vulnerability (CWE-266) that permits an unauthenticated attacker to manipulate plugin functions to escalate their account permissions.
Business Impact
The vulnerability carries a CVSS score of 9.8, reflecting its critical nature. A successful exploit could lead to a full site takeover, unauthorized data access, and the potential for persistent backdoors to be installed by the attacker, resulting in significant reputational and operational damage.
Remediation Plan
Immediate Action: Update the TrueBooker plugin to version 1.2.4 or later immediately.
Proactive Monitoring: Review WordPress user account logs for unexpected administrative role changes or newly created administrator accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at plugin-specific API endpoints until the update is applied.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the lack of required authentication for the affected function.
Analyst Recommendation
Given the critical severity and the ease of exploitation (unauthenticated), administrators must prioritize patching this plugin immediately. Failure to update to version 1.2.4 leaves the entire WordPress environment susceptible to compromise.
Update themetechmount TrueBooker to the latest version. Monitor for exploitation attempts and review access logs.
The TrueBooker plugin for WordPress is vulnerable to an unauthenticated SQL injection, allowing remote attackers to extract sensitive data via crafted...
The TrueBooker plugin for WordPress is vulnerable to an unauthenticated SQL injection, allowing remote attackers to extract sensitive data via crafted SQL commands.
---METADATA---
VENDOR: themetechmount
PRODUCT: TrueBooker
AFFECTED_VERSIONS: <= 1.2.3
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The TrueBooker plugin for WordPress is vulnerable to an unauthenticated SQL injection, allowing remote attackers to extract sensitive data via crafted SQL commands.
Executive Summary:
An unauthenticated SQL injection vulnerability in the TrueBooker plugin for WordPress poses a critical risk of database information disclosure.
Vulnerability Details
CVE-ID: CVE-2026-61950
Affected Software: themetechmount TrueBooker
Affected Versions: <= 1.2.3
Vulnerability: This is an SQL injection vulnerability occurring due to improper neutralization of special elements in database queries. It allows an unauthenticated attacker to manipulate backend queries without requiring any user interaction or privileges.
Business Impact
Successful exploitation allows unauthorized parties to access, modify, or delete sensitive information stored in the WordPress database. Given the CVSS score of 9.3, this vulnerability represents a severe risk that could lead to full database compromise, potentially exposing customer PII or administrative credentials.
Remediation Plan
Immediate Action: Update the TrueBooker WordPress plugin to version 1.2.4 or higher immediately to apply the vendor-supplied security fix.
Proactive Monitoring: Review database query logs for anomalous patterns or unexpected syntax that may indicate automated SQL injection attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection payloads targeting WordPress plugins.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its unauthenticated nature and the high impact of SQL injection on web applications.
Analyst Recommendation
The critical nature of this vulnerability necessitates immediate patching. Organizations utilizing the TrueBooker plugin must verify their current version and upgrade to 1.2.4 or later as a priority to prevent potential data breaches.
Update themetechmount TrueBooker to the latest version. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file...
A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
---METADATA---
VENDOR: Totolink
PRODUCT: A7100RU
AFFECTED_VERSIONS: 7.4cu.2313_b20191024
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The Totolink A7100RU router contains an OS command injection vulnerability in the setPasswordCfg function, allowing remote unauthenticated attackers to execute arbitrary commands.
Executive Summary:
A critical OS command injection vulnerability in the Totolink A7100RU router enables remote unauthenticated attackers to execute arbitrary system commands, posing a severe risk of full device compromise.
Vulnerability Details
CVE-ID: CVE-2026-6195
Affected Software: Totolink A7100RU
Affected Versions: 7.4cu.2313_b20191024
Vulnerability: This vulnerability exists in the /cgi-bin/cstecgi.cgi file within the CGI handler, where the admpass argument is improperly sanitized. Unauthenticated remote attackers can leverage this flaw to inject and execute system-level commands via the setPasswordCfg function.
Business Impact
The CVSS score of 9.8 reflects the critical nature of this flaw, as it allows for full remote system compromise without authentication. Successful exploitation could lead to total loss of device integrity, unauthorized access to network traffic, and the potential use of the device as a pivot point for lateral movement within the internal network.
Remediation Plan
Immediate Action: Contact the vendor for the latest firmware release or consider isolating the affected device from the public internet immediately.
Proactive Monitoring: Review web access logs for suspicious requests directed at /cgi-bin/cstecgi.cgi, particularly those containing shell metacharacters.
Compensating Controls: Implement strict firewall rules to restrict access to the device management interface to trusted administrative IP addresses only.
Exploitation Status
Public Exploit Available: Yes
Analyst Notes: As of Apr 13, 2026, public exploit code is available for this vulnerability. Organizations should treat this as an active threat and restrict network access to the affected hardware immediately.
Analyst Recommendation
Due to the critical severity and the existence of public exploit code, this vulnerability represents an imminent threat. Administrators must prioritize updating the firmware or, if no patch is available, moving the device behind a secure VPN or firewall to prevent unauthorized remote access.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
The Bookly WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 27.7 and prior, enabling attackers to execute arbitrar...
The Bookly WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 27.7 and prior, enabling attackers to execute arbitrary SQL commands.
---METADATA---
VENDOR: Bookly
PRODUCT: Bookly
AFFECTED_VERSIONS: up to and including 27.7
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The Bookly WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 27.7 and prior, enabling attackers to execute arbitrary SQL commands.
Executive Summary:
The Bookly appointment scheduling plugin is affected by a critical unauthenticated SQL injection flaw that could allow attackers to gain unauthorized database access.
Vulnerability Details
CVE-ID: CVE-2026-61949
Affected Software: Bookly Bookly
Affected Versions: up to and including 27.7
Vulnerability: This is an SQL injection vulnerability (CWE-89) arising from insufficient input sanitization, which can be triggered by unauthenticated users to interact with the database.
Business Impact
The exploitation of this vulnerability allows for unauthorized database queries, which may lead to the disclosure of sensitive booking data, customer information, or administrative credentials. With a CVSS score of 9.3, this flaw is considered critical and requires urgent attention to prevent full database compromise.
Remediation Plan
Immediate Action: Update the Bookly plugin to version 27.8 or later immediately.
Proactive Monitoring: Monitor database query logs for suspicious or malformed SQL statements and review application logs for unauthorized access attempts.
Compensating Controls: Implement a WAF to filter malicious request parameters that match known SQL injection signatures.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The nature of the flaw makes it highly susceptible to automated exploitation efforts.
Analyst Recommendation
The severity of this issue necessitates an immediate update to the latest version of the Bookly plugin. Security teams should prioritize this remediation to ensure that the site remains protected against potential database exploitation attempts.
Update Bookly Bookly to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote data...
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.
---METADATA---
VENDOR: Shahjada
PRODUCT: WPDM – Premium Packages
AFFECTED_VERSIONS: up to and including 6.2.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.
Executive Summary:
The WPDM Premium Packages plugin is susceptible to an unauthenticated SQL injection, creating a critical path for attackers to compromise database security.
Vulnerability Details
CVE-ID: CVE-2026-61948
Affected Software: Shahjada WPDM – Premium Packages
Affected Versions: up to and including 6.2.0
Vulnerability: The plugin fails to properly neutralize special elements in SQL commands (CWE-89), enabling unauthenticated attackers to perform malicious database operations.
Business Impact
Successful exploitation allows an attacker to bypass authentication and manipulate or extract data from the database. A CVSS score of 9.3 underscores the critical severity, which could result in significant data breaches or unauthorized access to sensitive digital assets managed by the plugin.
Remediation Plan
Immediate Action: Update the WPDM – Premium Packages plugin to version 7.0.0 or higher.
Proactive Monitoring: Analyze application server logs for anomalous database interactions and monitor for unexpected administrative account activity.
Compensating Controls: Utilize a WAF to inspect incoming traffic for SQL injection payloads, which can provide an interim layer of protection if patching is delayed.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 23, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly automatable due to the lack of required authentication.
Analyst Recommendation
This vulnerability represents a significant security risk to the integrity of the WordPress site. Administrators must upgrade to version 7.0.0 immediately to remediate the flaw and prevent potential exploitation by malicious actors.
Update Shahjada WPDM – Premium Packages to the latest version. Monitor for exploitation attempts and review access logs.
A weakness has been identified in Totolink A3002MU B20211125
A weakness has been identified in Totolink A3002MU B20211125
---METADATA---
VENDOR: Totolink
PRODUCT: A3002MU Router
AFFECTED_VERSIONS: B20211125.1046
CONFIDENCE: high
MISSING: none
CREDITS: DLChen (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357116","name":"VDB-357116 | Totolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357116/cti","name":"VDB-357116 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797452","name":"Submit #797452 | TOTOLINK A3002MU A3002MU_Hh-B20211125.1046 Stack-based Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/zhuchan770/vulnerability/blob/main/A3002MU/formWlanSetup/ToToLinkA3002MU%20formWlanSetup%20339996b67c9780caafb2d351dfd8a889.md","name":null,"tags":["exploit"]},{"url":"https://www.totolink.net/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.739Z
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the Totolink A3002MU router allows remote attackers to cause memory corruption via the wan-url parameter in the formWlanSetup function.
Executive Summary:
A critical buffer overflow vulnerability in the Totolink A3002MU router allows for potential remote exploitation and memory corruption.
Vulnerability Details
CVE-ID: CVE-2026-6194
Affected Software: Totolink A3002MU Router
Affected Versions: B20211125.1046
Vulnerability: The vulnerability exists in the function sub_410188 within the /boafrm/formWlanSetup endpoint, where the wan-url parameter is processed without sufficient length validation. This results in a stack-based buffer overflow when an attacker provides an overly long string, which is then copied into a fixed-size memory buffer.
Business Impact
The successful exploitation of this vulnerability can lead to memory corruption and potential denial of service conditions, impacting the availability of network infrastructure. While the CVSS score of 8.8 reflects a high severity rating, the ability for remote attackers to trigger this flaw without complex interaction necessitates immediate attention to prevent operational disruption.
Remediation Plan
Immediate Action: Update the device firmware to the latest available version provided by the manufacturer to patch the memory handling flaw.
Proactive Monitoring: Monitor network traffic for anomalous HTTP POST requests targeting the /boafrm/formWlanSetup endpoint, particularly those containing unusually long parameters.
Compensating Controls: Deploy a Web Application Firewall or network-level access control list to restrict access to the administrative interface of the router, ensuring only trusted management IPs can interact with vulnerable endpoints.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up by the researcher.
Analyst Notes: As of April 15, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The availability of a functional exploit script significantly lowers the barrier for attackers to achieve memory corruption.
Analyst Recommendation
Given the presence of a public proof-of-concept and the potential for remote exploitation, this issue poses a significant risk to affected Totolink devices. Administrators should verify their firmware versions immediately and apply the vendor-supplied security update to mitigate the risk of memory corruption and service disruption.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1
A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1
---METADATA---
VENDOR: PHPGurukul
PRODUCT: Daily Expense Tracking System
AFFECTED_VERSIONS: 1.1
CONFIDENCE: high
MISSING: patch
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357115","name":"VDB-357115 | PHPGurukul Daily Expense Tracking System register.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357115/cti","name":"VDB-357115 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797433","name":"Submit #797433 | PHPGurukul Daily Expense Tracking System 1.1 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/f1rstb100d/CVE/issues/47","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://phpgurukul.com/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.755Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the register.php file of PHPGurukul Daily Expense Tracking System 1.1, allowing unauthenticated attackers to manipulate the email argument.
Executive Summary:
An unauthenticated SQL injection vulnerability in PHPGurukul Daily Expense Tracking System 1.1 poses a significant risk of unauthorized database interaction.
Vulnerability Details
CVE-ID: CVE-2026-6193
Affected Software: PHPGurukul Daily Expense Tracking System
Affected Versions: 1.1
Vulnerability: This vulnerability is a SQL injection (CWE-89) located in the register.php file. Unauthenticated attackers can inject malicious SQL commands via the email parameter to interact with the backend database.
Business Impact
The CVSS score of 7.3 classifies this as a high-severity vulnerability due to the ease of remote exploitation. Successful exploitation could lead to unauthorized data exposure, potential modification of application data, or disruption of database services, resulting in significant reputational and operational impact.
Remediation Plan
Immediate Action: As no official patch is currently available, users should restrict access to the registration page or implement strict input validation to sanitize the email parameter before it is processed by the database.
Proactive Monitoring: Security teams should monitor web server and database logs for anomalous queries containing SQL syntax, particularly those directed at the register.php endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules specifically configured to detect and block SQL injection patterns targeting the email parameter in registration requests.
Exploitation Status
Public Exploit Available: Yes — a published proof-of-concept exists and is documented in the referenced GitHub issue.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible as it requires no authentication to trigger.
Analyst Recommendation
Given the availability of a public proof-of-concept and the lack of an official vendor patch, this vulnerability presents a tangible risk to any organization running the affected software. Administrators must prioritize isolating the affected component and implementing robust input filtering to prevent exploitation until the vendor releases a secure update.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The jDownloads extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code ex...
The jDownloads extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code execution on the server.
---METADATA---
VENDOR: dj-extensions.com
PRODUCT: jDownloads extension for Joomla
AFFECTED_VERSIONS: 4.1.0-4.1.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The jDownloads extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code execution on the server.
Executive Summary:
The jDownloads extension for Joomla is vulnerable to unauthenticated file uploads, which can lead to complete server compromise through remote code execution.
Vulnerability Details
CVE-ID: CVE-2026-61900
Affected Software: dj-extensions.com jDownloads extension for Joomla
Affected Versions: 4.1.0-4.1.5
Vulnerability: This is an unrestricted file upload flaw (CWE-434) that allows an unauthenticated attacker to upload malicious files. By successfully executing this, the attacker gains full remote code execution (RCE) on the underlying Joomla host.
Business Impact
Exploitation of this vulnerability grants the attacker full control over the Joomla application and the underlying server environment. Given the CVSS score of 10, the impact is severe, potentially leading to the theft of site data, long-term persistence in the network, and significant reputational damage.
Remediation Plan
Immediate Action: Update the jDownloads extension for Joomla to the latest version as recommended by the vendor.
Proactive Monitoring: Monitor server logs for HTTP requests involving suspicious file uploads or access to newly created files in document directories.
Compensating Controls: Use a Web Application Firewall (WAF) to restrict file upload capabilities and block known malicious payloads targeting the jDownloads component.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit available).
Analyst Notes: As of July 20, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The combination of unauthenticated access and file upload functionality makes this a high-priority target for automated scanning.
Analyst Recommendation
The severity of this vulnerability necessitates immediate action to patch the jDownloads extension. Security teams should ensure that all instances are updated to the latest supported version to eliminate the risk of remote code execution and unauthorized system access.
Update dj-extensions.com jDownloads extension for Joomla to the latest version. Monitor for exploitation attempts and review access logs.
Vulnerability in tapestry-core in Apache Tapestry 5
Vulnerability in tapestry-core in Apache Tapestry 5
---METADATA---
VENDOR: Apache
PRODUCT: Apache Tapestry
AFFECTED_VERSIONS: 5.5.0 up to (excluding) 5.9.1
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A vulnerability in the tapestry-core component of Apache Tapestry 5 allows for the unauthorized exposure of sensitive information to unauthenticated actors.
Executive Summary:
A high-severity information disclosure vulnerability in Apache Tapestry 5 enables unauthenticated remote attackers to access sensitive system data.
Vulnerability Details
CVE-ID: CVE-2026-61899
Affected Software: Apache Tapestry
Affected Versions: 5.5.0 up to (excluding) 5.9.1
Vulnerability: This is an exposure of sensitive information to an unauthorized actor (CWE-200) within the tapestry-core module. The vulnerability permits an unauthenticated attacker to gain access to information that should be protected.
Business Impact
With a CVSS score of 7.5, this vulnerability represents a significant risk to application security. Successful exploitation could allow attackers to harvest sensitive data, potentially leading to further reconnaissance or unauthorized access to backend systems.
Remediation Plan
Immediate Action: Update Apache Tapestry to version 5.9.1 or later to resolve the information disclosure flaw.
Proactive Monitoring: Review application access logs for unusual patterns of data retrieval or requests targeting sensitive system files and configuration endpoints.
Compensating Controls: Implement strict access control lists at the network or application level to limit exposure of the tapestry-core components to untrusted networks.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of August 11, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the vulnerability is remotely exploitable, it currently lacks evidence of active weaponization.
Analyst Recommendation
Organizations utilizing Apache Tapestry should audit their environments to identify all instances within the vulnerable version range. Applying the update to version 5.9.1 is the only effective way to remediate this information disclosure risk.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges
---METADATA---
VENDOR: Weintek
PRODUCT: cMT3092X firmware
AFFECTED_VERSIONS: cMT3092X firmware: 0 up to (excluding) 20210218; EasyWeb: 0 up to (excluding) v2.1.20
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Weintek cMT3092X HMI devices are vulnerable to privilege escalation due to improper token modification by authenticated users.
Executive Summary:
A critical privilege escalation vulnerability in Weintek cMT3092X HMI firmware allows an authenticated, non-privileged user to gain unauthorized elevated access.
Vulnerability Details
CVE-ID: CVE-2026-61892
Affected Software: Weintek cMT3092X firmware
Affected Versions: cMT3092X firmware: 0 up to (excluding) 20210218; EasyWeb: 0 up to (excluding) v2.1.20
Vulnerability: The device suffers from improper restriction of operations within the bounds of a memory buffer or object (CWE-732), allowing a low-privileged authenticated user to modify tokens and perform administrative actions.
Business Impact
Successful exploitation allows an attacker to bypass standard authorization controls, potentially leading to full control over the industrial HMI system. Given the CVSS score of 8.8, this poses a high risk to operational technology environments where unauthorized configuration changes could result in safety hazards, process disruption, or permanent equipment damage.
Remediation Plan
Immediate Action: Obtain and apply the patch package cmt_typeB_20260316_007, which updates EasyWeb to version 2.3.17-typeb, by contacting Weintek support or your local distributor.
Proactive Monitoring: Audit device access logs for unusual administrative activity or unauthorized attempts to modify system tokens.
Compensating Controls: Restrict network access to the HMI device to known, trusted IP addresses using internal firewalls or VLAN segmentation to reduce the attack surface.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 25, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is fundamentally an authorization oversight that requires initial low-level access to the device.
Analyst Recommendation
This vulnerability represents a significant security risk to industrial control systems. Administrators must prioritize the acquisition and application of the provided patch from Weintek to prevent unauthorized privilege escalation and ensure the integrity of the HMI environment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1
---METADATA---
VENDOR: SourceCodester
PRODUCT: Pharmacy Sales and Inventory System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: lingzezzz (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357111","name":"VDB-357111 | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357111/cti","name":"VDB-357111 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797377","name":"Submit #797377 | sourcecodester Pharmacy Sales and Inventory System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/lingzezzz/lingze/issues/1","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://www.sourcecodester.com/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.755Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands via the Username parameter in ajax.php.
Executive Summary:
A critical SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 allows unauthenticated remote attackers to compromise the application database.
Vulnerability Details
CVE-ID: CVE-2026-6189
Affected Software: SourceCodester Pharmacy Sales and Inventory System
Affected Versions: 1.0
Vulnerability: This is a SQL injection flaw (CWE-89) located in the /ajax.php endpoint. An unauthenticated attacker can supply malicious input to the Username parameter to interact directly with the backend database.
Business Impact
Successful exploitation of this SQL injection vulnerability could lead to unauthorized data exposure, modification, or deletion of sensitive pharmacy inventory and sales records. Given the CVSS score of 7.3, this represents a high-severity risk that could facilitate complete database compromise, resulting in significant operational disruption and loss of data integrity.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict access to the affected web application or take the service offline until a secure version is released.
Proactive Monitoring: Review web server access logs for anomalous requests containing SQL syntax patterns targeted at the /ajax.php endpoint.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block common SQL injection patterns and sanitize input directed at the Username parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical write-up provided in the referenced GitHub issue.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
The presence of a public proof-of-concept combined with the unauthenticated nature of this attack makes this a high-priority concern. Organizations currently running this software must implement immediate network-level restrictions or disable the affected component to prevent unauthorized database access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The web interface of Tycon Systems TPDIN-Monitor-WEB2 fails to validate credentials, allowing unauthenticated remote attackers to bypass login and obt...
The web interface of Tycon Systems TPDIN-Monitor-WEB2 fails to validate credentials, allowing unauthenticated remote attackers to bypass login and obtain administrative access.
---METADATA---
VENDOR: Tycon Systems
PRODUCT: TPDIN-Monitor-WEB2
AFFECTED_VERSIONS: 2.3.9
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The web interface of Tycon Systems TPDIN-Monitor-WEB2 fails to validate credentials, allowing unauthenticated remote attackers to bypass login and obtain administrative access.
Executive Summary:
An unauthenticated authentication bypass vulnerability in the Tycon Systems TPDIN-Monitor-WEB2 web interface allows full administrative control over power and network settings.
Vulnerability Details
CVE-ID: CVE-2026-61884
Affected Software: Tycon Systems TPDIN-Monitor-WEB2
Affected Versions: 2.3.9
Vulnerability: This vulnerability stems from a lack of server-side credential validation (CWE-288) during the login process. By submitting empty values, an attacker can bypass authentication entirely and establish an administrative session, granting them unrestricted control over the device.
Business Impact
The CVSS score of 9.8 reflects the extreme risk posed by this vulnerability, as it allows for trivial, unauthenticated remote control of critical infrastructure. An attacker could remotely reboot equipment, modify network settings, or disable power relays, potentially causing physical damage or operational outages in the environments where these devices are deployed.
Remediation Plan
Immediate Action: Contact Tycon Systems for the latest security updates and apply them immediately. In the absence of a direct patch, consider isolating the device management interface from all external networks.
Proactive Monitoring: Review web access logs for unusual login patterns or multiple requests with empty credentials, which may indicate an attempt to exploit this flaw.
Compensating Controls: Deploy a Web Application Firewall (WAF) or place the device behind a secure VPN to prevent direct access to the management interface by unauthorized entities.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Jul 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly exploitable due to the lack of any required authentication, making it a high priority for mitigation.
Analyst Recommendation
Due to the critical severity and the ease of exploitation, this device should be removed from public-facing networks immediately. Ensure that the device management interface is only accessible via trusted internal networks until a formal firmware update is applied.
Update Tycon Systems TPDIN-Monitor-WEB2 to the latest version. Monitor for exploitation attempts and review access logs.
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1
---METADATA---
VENDOR: SourceCodester
PRODUCT: Pharmacy Sales and Inventory System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: lingzezzz (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357110","name":"VDB-357110 | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357110/cti","name":"VDB-357110 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797376","name":"Submit #797376 | sourcecodester Pharmacy Sales and Inventory System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/lingzezzz/lingze/issues/2","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://www.sourcecodester.com/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.755Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the Pharmacy Sales and Inventory System 1.0 via the ajax.php file, allowing remote unauthenticated attackers to manipulate database queries.
Executive Summary:
An unauthenticated SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 poses a significant risk of unauthorized database manipulation.
Vulnerability Details
CVE-ID: CVE-2026-6188
Affected Software: SourceCodester Pharmacy Sales and Inventory System
Affected Versions: 1.0
Vulnerability: The application is vulnerable to SQL injection within the /ajax.php endpoint via the ID parameter. This flaw allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database.
Business Impact
The vulnerability carries a CVSS score of 7.3, indicating a high level of risk. Successful exploitation could lead to unauthorized access to sensitive pharmacy data, potential data exfiltration, or modification of inventory and sales records. Such compromises may result in significant operational disruption and loss of data integrity.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict network access to the application and monitor the /ajax.php endpoint for suspicious activity.
Proactive Monitoring: Review web server access logs for requests to /ajax.php containing SQL syntax patterns or unusual ID parameter values.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block requests containing SQL injection payloads targeting the ID parameter in the pharmacy system.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept is available via the referenced GitHub issue.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication.
Analyst Recommendation
Given the availability of a public proof-of-concept and the ease of exploitation, this vulnerability requires immediate attention. Organizations utilizing this system must implement strict network segmentation and WAF filtering to prevent unauthorized database access until a formal vendor update is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML mar...
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup
---METADATA---
VENDOR: OpenWrt
PRODUCT: LuCI
AFFECTED_VERSIONS: LuCI to 3.0.0 (exclusive)
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A stored XSS vulnerability in OpenWrt LuCI allows adjacent network attackers to inject malicious HTML via DHCPv6 lease hostnames.
Executive Summary:
A stored cross-site scripting vulnerability in OpenWrt LuCI allows adjacent network attackers to execute malicious scripts in the browser of an administrator.
Vulnerability Details
CVE-ID: CVE-2026-61876
Affected Software: OpenWrt LuCI
Affected Versions: LuCI to 3.0.0 (exclusive)
Vulnerability: This is a stored cross-site scripting (XSS) vulnerability caused by the failure to properly encode DHCPv6 lease hostnames. An attacker on the local network can inject malicious HTML/JavaScript tags into the hostname, which will be executed in the administrator's browser when the status table is viewed.
Business Impact
This vulnerability carries a CVSS score of 8.8, representing a High severity risk. By exploiting this, an adjacent attacker can perform malicious actions in the context of the administrator’s session, such as stealing session cookies, redirecting the user to malicious sites, or performing unauthorized administrative actions, which could ultimately lead to full network compromise.
Remediation Plan
Immediate Action: Update the LuCI web interface to version 3.0.0 or later as indicated in the vendor advisory at https://github.com/openwrt/luci/security/advisories/GHSA-686p-p8p9-x6fh.
Proactive Monitoring: Review DHCPv6 lease tables and web access logs for any evidence of malformed hostnames or unusual administrative activity.
Compensating Controls: Restrict access to the administrative web interface by limiting the networks or specific IP addresses allowed to reach the management console.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly exploitable by any device capable of communicating on the local network segment.
Analyst Recommendation
Administrators should update the LuCI interface immediately to version 3.0.0 or newer to remediate this flaw. Given the ease with which adjacent attackers can inject malicious payloads, ensuring that the management interface is not exposed to untrusted clients is a critical defensive measure.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMa...
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests
---METADATA---
VENDOR: OpenWrt
PRODUCT: LuCI
AFFECTED_VERSIONS: All versions of luci-app-upnp are affected.
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A stored cross-site scripting (XSS) vulnerability in the OpenWrt luci-app-upnp package allows unauthenticated LAN attackers to execute malicious JavaScript via UPnP IGD AddPortMapping requests.
Executive Summary:
A critical stored XSS vulnerability in OpenWrt's luci-app-upnp component allows unauthenticated attackers to execute arbitrary code in the context of an administrator session.
Vulnerability Details
CVE-ID: CVE-2026-61875
Affected Software: OpenWrt LuCI
Affected Versions: All versions of luci-app-upnp are affected.
Vulnerability: This is a stored cross-site scripting (XSS) flaw occurring when the application fails to sanitize input within the NewPortMappingDescription field. An unauthenticated attacker on the local network can inject malicious payloads that execute when an administrator views the affected UPnP or Status pages.
Business Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of an authenticated administrator. This can lead to unauthorized configuration changes, session hijacking, or further compromise of the network gateway. With a CVSS score of 8.8, this vulnerability poses a significant risk to the integrity and security of the administrative interface.
Remediation Plan
Immediate Action: Update your OpenWrt firmware to the latest available version, which includes a patched luci-app-upnp package.
Proactive Monitoring: Review web interface access logs for unusual activity or requests containing unexpected script tags in UPnP-related parameters.
Compensating Controls: If immediate patching is not feasible, restrict network access to the LuCI administrative interface and disable the UPnP service if it is not required for network operations.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists.
Analyst Notes: As of July 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous because it requires no authentication to trigger the payload storage.
Analyst Recommendation
Given the ease of exploitation and the potential for full administrative compromise, organizations should prioritize updating their OpenWrt instances. Administrators must ensure that the luci-app-upnp package is patched to the latest version to prevent potential session hijacking and unauthorized gateway manipulation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1
---METADATA---
VENDOR: SourceCodester
PRODUCT: Pharmacy Sales and Inventory System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: lingzezzz (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357109","name":"VDB-357109 | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357109/cti","name":"VDB-357109 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797375","name":"Submit #797375 | sourcecodester Pharmacy Sales and Inventory System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/lingzezzz/lingze/issues/3","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://www.sourcecodester.com/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.755Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the Pharmacy Sales and Inventory System 1.0 via the ajax.php file, allowing remote unauthenticated attackers to manipulate database queries.
Executive Summary:
A remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 exposes the application to unauthorized database manipulation by unauthenticated attackers.
Vulnerability Details
CVE-ID: CVE-2026-6187
Affected Software: SourceCodester Pharmacy Sales and Inventory System
Affected Versions: 1.0
Vulnerability: This is a SQL injection flaw (CWE-89) triggered by improper sanitization of the ID argument within the /ajax.php?action=chk_prod_availability endpoint. The vulnerability is exploitable by unauthenticated remote attackers.
Business Impact
Successful exploitation allows an attacker to interact directly with the backend database, potentially leading to unauthorized data disclosure or modification. With a CVSS score of 7.3, this high-severity flaw poses a significant risk to the integrity and confidentiality of sensitive pharmacy inventory and sales data.
Remediation Plan
Immediate Action: Since no official patch is currently available, administrators should restrict access to the affected /ajax.php endpoint or disable the vulnerable module entirely until a vendor-supplied update is released.
Proactive Monitoring: Review web server access logs for suspicious requests containing SQL syntax patterns or unexpected input in the ID parameter of the ajax.php file.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection payloads targeting the identified vulnerable endpoint.
Exploitation Status
Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the research write-up at https://github.com/lingzezzz/lingze/issues/3.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The simplicity of the attack vector makes this vulnerability highly susceptible to automated exploitation attempts.
Analyst Recommendation
Given the availability of a public proof-of-concept and the ease of remote exploitation, immediate action is required to secure the environment. Organizations currently utilizing this software must implement the recommended compensating controls immediately and monitor for unauthorized access attempts while awaiting a vendor-provided resolution.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in UTT HiPER 1200GW up to 2
A security vulnerability has been detected in UTT HiPER 1200GW up to 2
---METADATA---
VENDOR: UTT
PRODUCT: HiPER 1200GW
AFFECTED_VERSIONS: <= 2.5.3-170306
CONFIDENCE: high
MISSING: patch
CREDITS: QMSSDXN (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357108","name":"VDB-357108 | UTT HiPER 1200GW formNatStaticMap strcpy buffer overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357108/cti","name":"VDB-357108 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797304","name":"Submit #797304 | UTT HiPER 1200GW <=v2.5.3-170306 Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/lin-3-start/lin-cve/blob/main/Amao/1.md","name":null,"tags":["exploit"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.739Z
---END_METADATA---
Description Summary:
A buffer overflow vulnerability exists in the UTT HiPER 1200GW router due to improper handling of the NatBind argument in the /goform/formNatStaticMap endpoint.
Executive Summary:
A critical buffer overflow vulnerability in UTT HiPER 1200GW routers allows authenticated attackers to trigger memory corruption and potential denial of service conditions.
Vulnerability Details
CVE-ID: CVE-2026-6186
Affected Software: UTT HiPER 1200GW
Affected Versions: <= 2.5.3-170306
Vulnerability: The vulnerability resides in the strcpy function within the /goform/formNatStaticMap file. An authenticated attacker can supply an overly long NatBind parameter during a POST request, resulting in a buffer overflow that can lead to system instability or denial of service.
Business Impact
The exploitation of this vulnerability can result in significant operational disruption, as the device becomes susceptible to denial of service attacks. Given the CVSS score of 8.8, this flaw represents a high risk to business continuity, particularly if the router serves as a critical gateway for network traffic. Unauthorized control over network infrastructure components can further facilitate lateral movement or reconnaissance by malicious actors.
Remediation Plan
Immediate Action: Since a specific patch is not yet confirmed, administrators should restrict access to the management interface to trusted internal segments only and disable remote administration features until the vendor releases a firmware update.
Proactive Monitoring: Security teams should review firewall and access logs for anomalous POST requests directed at the /goform/formNatStaticMap endpoint, particularly those containing unusually large strings in the NatBind parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to inspect and block HTTP traffic containing oversized payloads destined for the vulnerable /goform/ formNatStaticMap URI.
Exploitation Status
Public Exploit Available: Yes, a published proof of concept exists, as evidenced by the technical write up provided in the associated research documentation.
Analyst Notes: As of April 15, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof of concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently exploitable via a standard POST request, making it a viable target for attackers with legitimate credentials.
Analyst Recommendation
Given the confirmed public availability of a proof of concept and the high severity of the buffer overflow, immediate action is required to harden the affected devices. IT teams must verify if their firmware version is 2.5.3-170306 or older and prioritize the implementation of the suggested compensating controls to prevent potential service disruption while awaiting official vendor remediation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Directus is a real-time API and App dashboard for managing SQL database content
Directus is a real-time API and App dashboard for managing SQL database content
---METADATA---
VENDOR: Directus
PRODUCT: Directus
AFFECTED_VERSIONS: < 12.0.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Directus is vulnerable to unauthorized information disclosure and authorization bypass due to improper handling of sensitive cached data and user-controlled keys.
Executive Summary:
Directus versions prior to 12.0.0 contain a critical vulnerability that allows unauthenticated attackers to bypass authorization controls and access sensitive cached information.
Vulnerability Details
CVE-ID: CVE-2026-61836
Affected Software: Directus
Affected Versions: < 12.0.0
Vulnerability: This vulnerability involves the use of a cache containing sensitive information and an authorization bypass through user-controlled keys. The flaw is exploitable by unauthenticated remote attackers.
Business Impact
The ability for an unauthenticated attacker to bypass authorization and access sensitive data poses a severe risk to organizational confidentiality. Because Directus manages SQL database content, this vulnerability could lead to the unauthorized exposure of proprietary business data, customer information, or administrative credentials. The CVSS score of 8.6 reflects the high potential for significant data compromise.
Remediation Plan
Immediate Action: Upgrade to Directus version 12.0.0 or later immediately.
Proactive Monitoring: Review application logs for unusual access patterns or unauthorized API requests that deviate from established user behavior.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block suspicious requests targeting the API dashboard.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of July 17, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is considered highly dangerous due to its automatable nature and lack of required authentication.
Analyst Recommendation
Given the high severity of this vulnerability and the potential for unauthorized access to sensitive database content, administrators should prioritize patching immediately. Upgrading to version 12.0.0 is the only effective way to remediate the underlying authorization and cache-handling flaws.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in code-projects Simple Content Management System 1
A security flaw has been discovered in code-projects Simple Content Management System 1
---METADATA---
VENDOR: code-projects
PRODUCT: Simple Content Management System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: imad alvi (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357106","name":"VDB-357106 | code-projects Simple Content Management System index.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357106/cti","name":"VDB-357106 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797264","name":"Submit #797264 | code-projects.org Simple Content Management System in php 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/Xmyronn/simple-cms-sqli-id-parameter","name":null,"tags":["exploit"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.755Z
---END_METADATA---
Description Summary:
An unauthenticated SQL injection vulnerability exists in the index.php file of Simple Content Management System 1.0, allowing remote attackers to extract sensitive database information.
Executive Summary:
An unauthenticated SQL injection vulnerability in Simple Content Management System 1.0 allows remote attackers to perform unauthorized database queries and extract sensitive information.
Vulnerability Details
CVE-ID: CVE-2026-6183
Affected Software: code-projects Simple Content Management System
Affected Versions: 1.0
Vulnerability: This vulnerability is a SQL injection (CWE-89) flaw located in the id parameter of the /web/index.php file. The application fails to properly sanitize user input, allowing an unauthenticated remote attacker to manipulate SQL queries and exfiltrate data from the underlying database.
Business Impact
The exploitation of this flaw poses a severe risk to data confidentiality and integrity. An attacker can leverage this injection to extract administrative credentials, user records, and the entire database content, leading to a full compromise of the application data. While the CVSS score is 7.3, the ability for an unauthenticated attacker to remotely dump the database makes this a high-priority risk for any organization hosting this software.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should restrict public access to the /web/index.php endpoint or disable the affected installation until a secure version is released.
Proactive Monitoring: Review web server access logs for anomalous GET requests containing SQL syntax, such as UNION, SELECT, or database-specific keywords, directed at the index.php file.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting the id parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the GitHub repository referenced in the vulnerability details.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, a public proof-of-concept exploit is available, which significantly lowers the barrier for attackers. The vulnerability is inherently easy to exploit because it requires no authentication and targets a common parameter in a publicly accessible script.
Analyst Recommendation
Given the availability of a functional proof-of-concept and the lack of a vendor-provided patch, this vulnerability presents a credible and immediate threat to the confidentiality of your data. Organizations should prioritize isolating the affected system from the public internet and implementing strict input validation via a WAF to mitigate the risk of unauthorized database access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Nixpkgs is a collection of software packages that can be installed with the Nix package manager
Nixpkgs is a collection of software packages that can be installed with the Nix package manager
---METADATA---
VENDOR: NixOS
PRODUCT: nixpkgs
AFFECTED_VERSIONS: < 25.11, >= 26.05-beta, < 26.05
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Nixpkgs contains an incorrect default permissions vulnerability that may expose sensitive files or system components to unauthorized access.
Executive Summary:
Nixpkgs versions within the specified ranges suffer from incorrect default permissions, which could lead to unauthorized access to sensitive system information.
Vulnerability Details
CVE-ID: CVE-2026-61828
Affected Software: NixOS nixpkgs
Affected Versions: < 25.11, >= 26.05-beta, < 26.05
Vulnerability: The vulnerability stems from incorrect default permissions assigned to software packages. This issue can be exploited by an authenticated local user to gain unauthorized access to system files or escalate privileges.
Business Impact
Successful exploitation could result in a total compromise of the affected system's security posture. With a CVSS score of 8.5, this vulnerability represents a severe risk to environments relying on Nixpkgs for software deployment, as local users could potentially bypass system restrictions.
Remediation Plan
Immediate Action: Update the Nixpkgs collection to a secure version as directed by the official NixOS security advisory.
Proactive Monitoring: Regularly audit file system permissions for critical packages and monitor for unauthorized attempts to access restricted directories by non-privileged users.
Compensating Controls: Employ system-level hardening and the principle of least privilege to ensure that local users have restricted access to sensitive software environments.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 17, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its potential for privilege escalation on the host system.
Analyst Recommendation
Given the potential for system-wide impact, it is imperative that administrators using Nixpkgs apply the relevant security updates immediately. Ensure all package channels are synchronized with the latest secure versions to prevent exploitation of these permission flaws.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Defuddle cleans up HTML pages
Defuddle cleans up HTML pages
---METADATA---
VENDOR: kepano
PRODUCT: defuddle
AFFECTED_VERSIONS: < 0.19.1
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Defuddle is vulnerable to Cross-site Scripting (XSS) due to improper neutralization of input during web page generation.
Executive Summary:
A high severity Cross-site Scripting vulnerability in kepano defuddle allows unauthenticated attackers to execute malicious scripts in a user's browser.
Vulnerability Details
CVE-ID: CVE-2026-61824
Affected Software: kepano defuddle
Affected Versions: < 0.19.1
Vulnerability: This is a Cross-site Scripting (XSS) vulnerability caused by improper input sanitization and output encoding. The vulnerability is exploitable by unauthenticated remote attackers who can craft malicious HTML inputs that are improperly processed by the application.
Business Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or the theft of sensitive information displayed on the page. Given the CVSS score of 8.2, this represents a significant risk to user data integrity and privacy.
Remediation Plan
Immediate Action: Update the kepano defuddle package to version 0.19.1 or later to implement the necessary input sanitization fixes.
Proactive Monitoring: Review application logs for unusual HTML tags or script-like patterns being submitted to the application.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common XSS attack vectors.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit identified in available data).
Analyst Notes: As of August 22, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable via standard web injection techniques if proper encoding is missing.
Analyst Recommendation
The vulnerability poses a high risk to users of the defuddle software. Organizations should prioritize updating to version 0.19.1 immediately to eliminate the XSS vector and protect end users from potential account compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was identified in code-projects Simple Content Management System 1
A vulnerability was identified in code-projects Simple Content Management System 1
---METADATA---
VENDOR: code-projects
PRODUCT: Simple Content Management System PHP
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: imad alvi (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357105","name":"VDB-357105 | code-projects Simple Content Management System login.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357105/cti","name":"VDB-357105 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797263","name":"Submit #797263 | code-projects.org Simple Content Management System In PHP 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/Xmyronn/simple-cms-sqli-login-bypass-CVE-HUNT-","name":null,"tags":["exploit"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.847Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the admin login page of Simple Content Management System PHP 1.0 allows unauthenticated remote attackers to bypass authentication and gain administrative access.
Executive Summary:
An unauthenticated SQL injection vulnerability in Simple Content Management System PHP 1.0 allows remote attackers to bypass authentication and gain full administrative control.
Vulnerability Details
CVE-ID: CVE-2026-6182
Affected Software: code-projects Simple Content Management System PHP
Affected Versions: 1.0
Vulnerability: This vulnerability is a SQL injection (CWE-89) flaw located in the /web/admin/login.php file. An unauthenticated attacker can manipulate the user parameter in a POST request to bypass authentication mechanisms and achieve full administrative access.
Business Impact
The ability for an unauthenticated attacker to bypass authentication poses a critical risk to the confidentiality, integrity, and availability of the system. Successful exploitation grants full administrative control, which may lead to unauthorized data modification, content injection, or complete system takeover. While the CVSS score is 7.3, the potential for unauthorized administrative access necessitates immediate attention to prevent compromise.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should immediately restrict access to the /web/admin/ directory using network-level controls or IP allowlisting to prevent public exposure.
Proactive Monitoring: Review web server access logs for suspicious POST requests to /web/admin/login.php containing SQL injection patterns, such as the use of single quotes or tautological expressions like "or 1=1".
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection attempts targeting the user parameter on the login endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the researcher's GitHub repository.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is trivial to exploit as it requires no prior authentication and uses standard SQL injection techniques.
Analyst Recommendation
Given that this vulnerability allows for complete authentication bypass and administrative takeover, it represents a significant security risk. Administrators must prioritize isolating the affected management interface from public access until a secure update is provided by the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and...
LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and consume LLM resources.
---METADATA---
VENDOR: HKUDS
PRODUCT: LightRAG
AFFECTED_VERSIONS: < 1.5.5rc1
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and consume LLM resources.
Executive Summary:
The LightRAG API server is vulnerable to unauthenticated access, allowing remote attackers to read, modify, or delete sensitive data and consume infrastructure resources.
Vulnerability Details
CVE-ID: CVE-2026-61808
Affected Software: HKUDS LightRAG
Affected Versions: < 1.5.5rc1
Vulnerability: The application binds its API server to all network interfaces with authentication disabled by default. This missing authentication vulnerability allows any unauthenticated network attacker to perform administrative actions, including data manipulation and resource exhaustion.
Business Impact
With a CVSS score of 9.8, this vulnerability represents a critical threat to data confidentiality and availability. Unauthorized access to RAG-based systems can lead to the exposure of sensitive indexed documents, corruption of the underlying knowledge base, and significant financial loss due to the unauthorized consumption of LLM API resources.
Remediation Plan
Immediate Action: Update HKUDS LightRAG to version 1.5.5rc1 or later to enforce mandatory authentication on the API server.
Proactive Monitoring: Audit network configurations to ensure the API server is not exposed to untrusted networks and monitor logs for unauthorized API calls.
Compensating Controls: Implement strict network-level access controls or VPN requirements to restrict access to the LightRAG API to authorized internal entities only.
Exploitation Status
Public Exploit Available: Unknown — there is no confirmed public exploit in the available data.
Analyst Notes: As of August 7, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the default configuration of disabling authentication on a critical network service.
Analyst Recommendation
Organizations utilizing LightRAG must treat this as a high-priority remediation task. Ensure that the software is updated to the fixed version and verify that the API is not exposed to the public internet until authentication controls are properly implemented and validated.
Update HKUDS LightRAG to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a...
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every peer under its CA (and internal services on the mesh) for up to 30d (agent) / 365d (mobile). An attacker who exfiltrates host.key+host.crt can run stock slackhq/nebula directly, ignore the agent's 403/410 poll responses, and stay connected after the operator revokes the host. Operator-visible state (UI shows blocked, audit log records it) is misleading. This issue has been patched in version 0.7.1.
---METADATA---
VENDOR: Forgekeep
PRODUCT: nebula-mesh
AFFECTED_VERSIONS: < 0.7.1
CONFIDENCE: high
MISSING: none
PROFILE: daily@7c4e524780a4
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-09-05T09:04:42.339Z
SOURCES_JSON: [{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8","name":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8","tags":["x_refsource_CONFIRM"]},{"url":"https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb","name":"https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb","tags":["x_refsource_MISC"]},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1","name":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1","tags":["x_refsource_MISC"]}]
---END_METADATA---
Description Summary:
A failure in the nebula-mesh certificate revocation mechanism allows revoked or offboarded hosts to maintain unauthorized network access for extended periods despite being marked as blocked.
Executive Summary:
A high-severity authentication bypass vulnerability in nebula-mesh allows compromised hosts to retain unauthorized access to the VPN overlay network after revocation.
Vulnerability Details
CVE-ID: CVE-2026-61699
Affected Software: Forgekeep nebula-mesh
Affected Versions: < 0.7.1
Vulnerability: This flaw involves improper certificate revocation and operations on resources after expiration (CWE-299, CWE-672). An attacker with stolen credentials can bypass revocation status by ignoring agent poll responses, maintaining full reachability to internal mesh services despite administrator action.
Business Impact
The vulnerability presents a significant risk to organizational confidentiality and integrity. Because the control plane fails to propagate blocklist updates to peers, an attacker who has exfiltrated host keys can maintain persistent, unauthorized access to sensitive internal network resources. With a CVSS score of 8.1, this flaw indicates a high risk of lateral movement and data exfiltration, rendering traditional offboarding procedures ineffective.
Remediation Plan
Immediate Action: Upgrade the nebula-mesh control plane to version 0.7.1 or later immediately to ensure revocation commands are correctly enforced across all mesh peers.
Proactive Monitoring: Review audit logs for unexpected or anomalous traffic from hosts that have been previously marked as revoked or offboarded within the mesh.
Compensating Controls: Until patches are applied, consider rotating all existing host keys and manually updating peer configurations to exclude revoked identifiers, as the UI-based revocation is currently unreliable.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of September 5, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous because it creates a false sense of security, where administrators believe a host is blocked while the attacker retains full network connectivity.
Analyst Recommendation
The reliance on a misleading revocation state makes this vulnerability a critical concern for any organization managing access via nebula-mesh. Security teams must prioritize updating to version 0.7.1 to rectify the revocation logic. Failure to patch will leave the network exposed to persistent access by unauthorized or offboarded entities, undermining the entire zero-trust architecture of the VPN mesh.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FastGPT is a knowledge-based AI application platform
FastGPT is a knowledge-based AI application platform
---METADATA---
VENDOR: Labring
PRODUCT: FastGPT
AFFECTED_VERSIONS: 4.15.0-beta4
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
FastGPT contains hard-coded credentials, which may allow an unauthenticated attacker to gain unauthorized access to sensitive information.
Executive Summary:
Hard-coded credentials within FastGPT expose the platform to potential unauthorized access by unauthenticated attackers.
Vulnerability Details
CVE-ID: CVE-2026-61684
Affected Software: Labring FastGPT
Affected Versions: 4.15.0-beta4
Vulnerability: The application utilizes hard-coded credentials (CWE-798), which can be leveraged by an unauthenticated attacker to gain unauthorized access. This vulnerability simplifies the attack path, as no complex exploitation is required to bypass authentication.
Business Impact
With a CVSS score of 8.8, this vulnerability poses a significant risk to the confidentiality of knowledge-based AI platforms. Unauthorized access to the platform could lead to the theft of proprietary data, sensitive AI training sets, or the manipulation of application logic, causing substantial business disruption.
Remediation Plan
Immediate Action: Update FastGPT to version 4.15.0-beta5 or later to eliminate the hard-coded credentials.
Proactive Monitoring: Monitor authentication logs for suspicious login attempts and inspect configuration files for signs of credential tampering.
Compensating Controls: Ensure the instance is not exposed to the public internet and use a Web Application Firewall to filter out requests that attempt to exploit known credential patterns.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 16, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The presence of hard-coded credentials makes the system inherently easy to compromise if reachable.
Analyst Recommendation
The reliance on hard-coded credentials represents a fundamental security flaw that must be addressed immediately. Organizations currently running FastGPT version 4.15.0-beta4 must upgrade to version 4.15.0-beta5 to secure the platform against unauthorized access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in TOTOLINK A7000R up to 9
A flaw has been found in TOTOLINK A7000R up to 9
---METADATA---
VENDOR: TOTOLINK
PRODUCT: A7000R
AFFECTED_VERSIONS: A7000R 9.1.0u.6115 and earlier
CONFIDENCE: high
MISSING: patch
CREDITS: DLChen (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357056","name":"VDB-357056 | TOTOLINK A7000R cstecgi.cgi setWiFiEasyGuestCfg stack-based overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357056/cti","name":"VDB-357056 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797193","name":"Submit #797193 | TOTOLINK A7000R <=V9.1.0u.6115 Stack-based Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/zhuchan770/vulnerability/blob/main/A7000R/setWiFiEasyGuestCfg/ToToLink%20A7000R%20setWiFiEasyGuestCfg%20338996b67c9780b89829d0ea70058788.md","name":null,"tags":["exploit"]},{"url":"https://www.totolink.net/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the TOTOLINK A7000R router allows remote code execution via the ssid5g parameter in the setWiFiEasyGuestCfg function.
Executive Summary:
A critical stack-based buffer overflow vulnerability in TOTOLINK A7000R routers allows remote attackers to compromise device integrity and potentially execute arbitrary code.
Vulnerability Details
CVE-ID: CVE-2026-6168
Affected Software: TOTOLINK A7000R
Affected Versions: A7000R 9.1.0u.6115 and earlier
Vulnerability: The vulnerability exists within the setWiFiEasyGuestCfg function of the cstecgi.cgi script, where the ssid5g parameter is processed without proper length validation before being copied into a fixed-size stack buffer. This memory corruption flaw allows a low-privileged authenticated attacker to trigger a stack-based buffer overflow.
Business Impact
The exploitation of this flaw allows an attacker to achieve remote code execution on the affected router. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full device takeover, unauthorized access to internal network traffic, and potential lateral movement into the local environment. Compromise of networking equipment often serves as a primary vector for persistent internal threats and data exfiltration.
Remediation Plan
Immediate Action: Since a specific patch version is currently unknown, administrators should restrict access to the web management interface to trusted internal segments only. If possible, disable the guest wireless configuration features until the vendor releases a firmware update.
Proactive Monitoring: Monitor device logs for unusual crash events or unexpected reboots of the cstecgi.cgi process. Review network traffic for anomalous POST requests directed at the /cgi-bin/cstecgi.cgi endpoint containing oversized ssid5g parameters.
Compensating Controls: Implement an ingress Web Application Firewall (WAF) rule or an Intrusion Prevention System (IPS) signature to inspect and block HTTP requests to the management interface that contain excessively long strings within the ssid5g field.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the researcher.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, because a functional proof-of-concept has been published, the risk of exploitation is elevated and should be considered credible. The vulnerability is highly exploitable due to the lack of input sanitization on the ssid5g parameter.
Analyst Recommendation
Due to the severity of this remote code execution vulnerability, immediate mitigation is required. Organizations utilizing TOTOLINK A7000R devices should prioritize isolating these systems from the public internet and monitoring vendor communication channels for forthcoming firmware updates. Failure to secure these devices may result in total loss of control over the affected network infrastructure.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in code-projects Faculty Management System 1
A vulnerability was detected in code-projects Faculty Management System 1
---METADATA---
VENDOR: code-projects
PRODUCT: Faculty Management System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: wfcht-sy (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357055","name":"VDB-357055 | code-projects Faculty Management System subject-print.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357055/cti","name":"VDB-357055 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797098","name":"Submit #797098 | code-projects Faculty Management System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/wfcht-sy/src/issues/1","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in code-projects Faculty Management System 1.0 allows remote attackers to manipulate the ID argument in subject-print.php.
Executive Summary:
The Faculty Management System 1.0 is vulnerable to unauthenticated SQL injection, posing a risk of unauthorized database interaction.
Vulnerability Details
CVE-ID: CVE-2026-6167
Affected Software: code-projects Faculty Management System
Affected Versions: 1.0
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) located in the subject-print.php file, which fails to properly sanitize the ID parameter. The flaw is exploitable by unauthenticated remote attackers.
Business Impact
The ability to perform SQL injection allows an attacker to interact directly with the backend database, potentially leading to unauthorized data disclosure or modification. With a CVSS score of 7.3, this high-severity vulnerability could compromise the integrity and confidentiality of student or faculty information, resulting in significant reputational and regulatory consequences for the institution.
Remediation Plan
Immediate Action: As no official patch is currently identified, administrators should restrict access to the affected web interface or disable the vulnerable subject-print.php functionality until a vendor update is released.
Proactive Monitoring: Security teams should monitor database logs for suspicious query patterns, such as unusual syntax or unexpected data access requests originating from the web server.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection payloads targeting URL parameters.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up at https://github.com/wfcht-sy/src/issues/1.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently easy to exploit due to the lack of required authentication.
Analyst Recommendation
Given the availability of a public proof-of-concept and the unauthenticated nature of the attack, this vulnerability represents a significant risk. Organizations utilizing the Faculty Management System 1.0 must prioritize the implementation of WAF protections or network-level access controls immediately to prevent potential exploitation while awaiting a permanent vendor-supplied security update.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
websocket-driver is a WebSocket protocol handler with pluggable I/O
websocket-driver is a WebSocket protocol handler with pluggable I/O
---METADATA---
VENDOR: faye
PRODUCT: websocket-driver-ruby
AFFECTED_VERSIONS: faye websocket-driver-ruby < 0.8.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A vulnerability in faye websocket-driver-ruby allows an unauthenticated attacker to cause a denial of service via an uncaught exception.
Executive Summary:
A high-severity denial of service vulnerability in the faye websocket-driver-ruby library could allow an unauthenticated attacker to crash the application.
Vulnerability Details
CVE-ID: CVE-2026-61666
Affected Software: faye websocket-driver-ruby
Affected Versions: faye websocket-driver-ruby < 0.8.2
Vulnerability: The library is susceptible to an uncaught exception (CWE-248) during WebSocket protocol handling. This flaw is remotely exploitable without authentication, potentially causing the application to hang or terminate unexpectedly.
Business Impact
The primary impact of this vulnerability is service availability. With a CVSS score of 8.9, the ability for an unauthenticated attacker to remotely trigger a crash presents a significant threat to business continuity, particularly for services heavily dependent on WebSocket communication.
Remediation Plan
Immediate Action: Update the faye websocket-driver-ruby dependency to version 0.8.2 or later in your project's Gemfile.
Proactive Monitoring: Monitor application logs for recurring stack traces or sudden service restarts that may indicate attempted exploitation of this exception-based vulnerability.
Compensating Controls: Utilize a robust load balancer or ingress controller to manage traffic and potentially mitigate the impact of service-level disruptions.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 18, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While it is remotely exploitable, the technical impact is focused on service availability.
Analyst Recommendation
Due to the high CVSS score and the ease of remote exploitation, developers should prioritize upgrading the websocket-driver-ruby library to version 0.8.2 immediately to prevent potential service-disruption attacks.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1
A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1
---METADATA---
VENDOR: code-projects
PRODUCT: Vehicle Showroom Management System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: wfcht-sy (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357054","name":"VDB-357054 | code-projects Vehicle Showroom Management System UpdateVehicleFunction.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357054/cti","name":"VDB-357054 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797097","name":"Submit #797097 | code-projects Vehicle Showroom Management System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/wfcht-sy/src/issues/2","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the Vehicle Showroom Management System 1.0 allows remote attackers to manipulate the VEHICLE_ID parameter in /util/UpdateVehicleFunction.php.
Executive Summary:
The code-projects Vehicle Showroom Management System 1.0 contains a critical SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary database commands.
Vulnerability Details
CVE-ID: CVE-2026-6166
Affected Software: code-projects Vehicle Showroom Management System
Affected Versions: 1.0
Vulnerability: The application is vulnerable to SQL injection (CWE-89) within the /util/UpdateVehicleFunction.php file. Attackers can exploit this by injecting malicious input into the VEHICLE_ID argument, which is processed without sufficient sanitization.
Business Impact
Successful exploitation allows an attacker to interact directly with the backend database, potentially leading to unauthorized data access, modification, or deletion. Given the CVSS score of 7.3, this high-severity flaw poses a significant risk to the confidentiality and integrity of information stored within the showroom management database.
Remediation Plan
Immediate Action: Since no official patch is currently available, administrators should restrict access to the affected script or disable the module entirely until a secure update is released by the vendor.
Proactive Monitoring: Review web server access logs for anomalous requests containing SQL syntax or unusual parameters targeting the /util/UpdateVehicleFunction.php endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) rule to filter and block malicious SQL injection payloads targeting the VEHICLE_ID parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the GitHub issue tracker referenced by the vulnerability record.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently dangerous due to its remote, unauthenticated attack vector.
Analyst Recommendation
Due to the availability of a public proof-of-concept and the lack of an official patch, organizations using this software are at elevated risk. Immediate isolation of the vulnerable component is required to prevent potential database compromise until the vendor provides a remediation update.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A weakness has been identified in code-projects Vehicle Showroom Management System 1
A weakness has been identified in code-projects Vehicle Showroom Management System 1
---METADATA---
VENDOR: code-projects
PRODUCT: Vehicle Showroom Management System
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: Minji (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357053","name":"VDB-357053 | code-projects Vehicle Showroom Management System Login_check.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357053/cti","name":"VDB-357053 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797090","name":"Submit #797090 | code-projects Vehicle Showroom Management System V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/realnotjoking/cve/issues/2","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the Vehicle Showroom Management System 1.0, specifically within the /util/Login_check.php file, allowing remote attackers to manipulate the ID argument.
Executive Summary:
A critical SQL injection vulnerability in the code-projects Vehicle Showroom Management System allows unauthenticated remote attackers to compromise the application database.
Vulnerability Details
CVE-ID: CVE-2026-6165
Affected Software: code-projects Vehicle Showroom Management System
Affected Versions: 1.0
Vulnerability: This is a SQL injection flaw (CWE-89) triggered by improper input validation of the ID parameter within the /util/Login_check.php file. The vulnerability is exploitable by unauthenticated remote attackers.
Business Impact
The ability to perform remote SQL injection poses a significant risk to the confidentiality, integrity, and availability of the application. An attacker could potentially extract sensitive user data, bypass authentication mechanisms, or modify database records, leading to unauthorized access and potential system compromise. With a CVSS score of 7.3, this high-severity flaw requires immediate attention to prevent unauthorized data exfiltration.
Remediation Plan
Immediate Action: Since no official patch is currently available, administrators should restrict access to the affected web directory or disable the vulnerable Vehicle Showroom Management System until a secure update is released.
Proactive Monitoring: Review web server access logs for anomalous requests containing SQL syntax patterns targeted at the /util/Login_check.php endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection payloads targeting the identified parameter.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced GitHub issue.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The presence of a published proof-of-concept significantly lowers the barrier to entry for potential attackers.
Analyst Recommendation
Given the availability of a public proof-of-concept and the ease of remote exploitation, this vulnerability presents a clear and present danger to affected environments. Organizations must prioritize the implementation of compensating controls, such as WAF filtering, to mitigate the risk while awaiting a vendor-supplied patch. Failure to address this flaw could lead to a full database compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incomi...
Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverified email (multi-tenant IdPs, IdPs with open self-registration, or any IdP the attacker partly controls), an attacker with no Wallos account can authenticate with the admin's email and be logged in as the admin — full account takeover, no password needed. This issue has been patched in version 4.9.6.
---METADATA---
VENDOR: ellite
PRODUCT: Wallos
AFFECTED_VERSIONS: >= 4.0.0, < 4.9.6
CONFIDENCE: high
MISSING: none
PROFILE: daily@7c4e524780a4
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-09-01T09:11:33.332Z
SOURCES_JSON: [{"url":"https://github.com/ellite/Wallos/security/advisories/GHSA-qwgp-m2f3-6j3r","name":"https://github.com/ellite/Wallos/security/advisories/GHSA-qwgp-m2f3-6j3r","tags":["x_refsource_CONFIRM"]},{"url":"https://github.com/ellite/Wallos/pull/1092","name":"https://github.com/ellite/Wallos/pull/1092","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","name":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","name":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","tags":["x_refsource_MISC"]}]
---END_METADATA---
Description Summary:
Wallos versions 4.0.0 through 4.9.5 contain an authentication bypass vulnerability in the OIDC login flow, allowing unauthenticated attackers to hijack accounts by spoofing email claims.
Executive Summary:
A critical authentication vulnerability in Wallos allows unauthenticated attackers to perform full account takeovers by exploiting improper OIDC email verification.
Vulnerability Details
CVE-ID: CVE-2026-61641
Affected Software: ellite Wallos
Affected Versions: >= 4.0.0, < 4.9.6
Vulnerability: The application fails to verify the email_verified claim during the OpenID Connect (OIDC) login process. This allows an unauthenticated attacker to associate an arbitrary email address with their session, effectively bypassing authentication and gaining unauthorized access to any user account, including administrative accounts.
Business Impact
The exploitation of this flaw grants an attacker full administrative control over the Wallos instance. Given the CVSS score of 8.1, the high severity reflects the potential for complete data compromise, unauthorized access to sensitive financial subscription tracking information, and full system takeover without requiring prior authentication.
Remediation Plan
Immediate Action: Update the Wallos instance to version 4.9.6 or later immediately to enforce proper OIDC email verification.
Proactive Monitoring: Review authentication and access logs for suspicious logins, particularly those originating from unexpected OIDC providers or anomalous patterns involving administrative accounts.
Compensating Controls: If immediate patching is not possible, consider disabling OIDC authentication and reverting to local credential-based authentication until the update can be applied.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of September 1, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the flaw is theoretically simple to execute if the IdP configuration allows for arbitrary email claims, there is no evidence of widespread automated scanning or weaponized exploit code at this time.
Analyst Recommendation
The severity of this vulnerability necessitates an immediate response, as it permits unauthenticated account takeover of the application. Administrators must prioritize upgrading to version 4.9.6 to remediate the logic flaw in the authentication service. Failure to patch leaves the system vulnerable to unauthorized access and potential data exfiltration.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in in...
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs which have validate_webhook_url_for_ssrf(), OIDC URLs bypass all protections. Admin sets URL to http://169.254.169.254/latest/meta-data/ for cloud metadata access or internal network pivoting. This issue has been patched in version 4.9.6.
---METADATA---
VENDOR: ellite
PRODUCT: Wallos
AFFECTED_VERSIONS: < 4.9.6
CONFIDENCE: high
MISSING: none
PROFILE: daily@7c4e524780a4
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-09-01T09:08:06.197Z
SOURCES_JSON: [{"url":"https://github.com/ellite/Wallos/security/advisories/GHSA-x9x5-gh69-q7cm","name":"https://github.com/ellite/Wallos/security/advisories/GHSA-x9x5-gh69-q7cm","tags":["x_refsource_CONFIRM"]},{"url":"https://github.com/ellite/Wallos/pull/1092","name":"https://github.com/ellite/Wallos/pull/1092","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","name":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","name":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","tags":["x_refsource_MISC"]}]
---END_METADATA---
Description Summary:
A Server-Side Request Forgery (SSRF) vulnerability in Wallos allows an authenticated administrator to perform unauthorized internal network requests via unvalidated OIDC configuration URLs.
Executive Summary:
An authenticated administrator can exploit a Server-Side Request Forgery vulnerability in Wallos version 4.9.5 and earlier to access cloud metadata or pivot into internal networks.
Vulnerability Details
CVE-ID: CVE-2026-61640
Affected Software: ellite Wallos
Affected Versions: < 4.9.6
Vulnerability: The application fails to perform input validation on OIDC token and user info URLs, allowing an administrator to inject malicious targets into the curl_init function. This bypasses the protections applied to other URL fields and enables arbitrary requests from the host server.
Business Impact
Successful exploitation of this flaw could allow an attacker with administrative access to reach internal-only services or extract sensitive cloud environment metadata. With a CVSS score of 8.5, this high-severity vulnerability poses a significant risk to the confidentiality and integrity of the hosting infrastructure.
Remediation Plan
Immediate Action: Update Wallos to version 4.9.6 or later immediately to incorporate the necessary input validation for OIDC configuration URLs.
Proactive Monitoring: Review application logs for unusual outbound requests initiated by the Wallos service and monitor for access attempts targeting internal IP ranges.
Compensating Controls: Ensure the Wallos instance is deployed with strict network egress filtering to prevent the application from making unauthorized requests to internal network segments or metadata services.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of September 1, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its potential to facilitate cloud-based infrastructure compromise.
Analyst Recommendation
The risk presented by this SSRF vulnerability is substantial, particularly for cloud-hosted deployments where metadata services are accessible. Administrators should prioritize updating the Wallos installation to version 4.9.6 to remediate this flaw and prevent potential internal network pivoting.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in code-projects Lost and Found Thing Management 1
A security flaw has been discovered in code-projects Lost and Found Thing Management 1
---METADATA---
VENDOR: code-projects
PRODUCT: Lost and Found Thing Management
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: lanPwa (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357052","name":"VDB-357052 | code-projects Lost and Found Thing Management addcat.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357052/cti","name":"VDB-357052 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797089","name":"Submit #797089 | code-projects Lost and Found Thing Management V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/lanPwa/CVE/issues/1","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the addcat.php file of code-projects Lost and Found Thing Management 1.0, allowing remote attackers to manipulate the cata argument.
Executive Summary:
A critical SQL injection vulnerability in the Lost and Found Thing Management application allows unauthenticated remote attackers to compromise database integrity.
Vulnerability Details
CVE-ID: CVE-2026-6164
Affected Software: code-projects Lost and Found Thing Management
Affected Versions: 1.0
Vulnerability: This is a SQL injection vulnerability (CWE-89) located in the addcat.php file. An unauthenticated attacker can exploit this flaw by manipulating the cata argument to execute arbitrary SQL commands.
Business Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive data stored in the underlying database, potentially resulting in data exfiltration or modification. Given the CVSS score of 7.3, this represents a high-severity risk that could lead to significant operational disruption and compromise of user information.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should immediately restrict access to the affected web application or take it offline until the vendor provides a security update.
Proactive Monitoring: Monitor database query logs for suspicious patterns, such as unexpected syntax or unauthorized access attempts originating from the addcat.php endpoint.
Compensating Controls: Deploy a Web Application Firewall (WAF) with specific rules designed to detect and block SQL injection payloads targeting the cata parameter.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub issue referenced by the vulnerability record.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of required authentication.
Analyst Recommendation
The presence of a public proof-of-concept combined with the ease of remote, unauthenticated exploitation necessitates immediate attention. Organizations utilizing this software must prioritize isolating the application from external networks and implementing strict input validation or WAF rules to prevent SQL injection attempts until an official vendor patch is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extrac...
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to write webshell to webroot. Extension filter only applies to post-extraction logo copy step. This issue has been patched in version 4.9.6.
---METADATA---
VENDOR: ellite
PRODUCT: Wallos
AFFECTED_VERSIONS: < 4.9.6
CONFIDENCE: high
MISSING: none
PROFILE: daily@7c4e524780a4
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-09-01T09:08:13.586Z
SOURCES_JSON: [{"url":"https://github.com/ellite/Wallos/security/advisories/GHSA-3vg2-cxpg-m43g","name":"https://github.com/ellite/Wallos/security/advisories/GHSA-3vg2-cxpg-m43g","tags":["x_refsource_CONFIRM"]},{"url":"https://github.com/ellite/Wallos/pull/1092","name":"https://github.com/ellite/Wallos/pull/1092","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","name":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","name":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","tags":["x_refsource_MISC"]}]
---END_METADATA---
Description Summary:
A path traversal vulnerability in Wallos allows an authenticated administrator to upload a malicious ZIP file, leading to arbitrary file write and potential remote code execution.
Executive Summary:
A path traversal vulnerability in the Wallos subscription tracker allows an authenticated administrator to achieve arbitrary file write, posing a severe risk of system compromise.
Vulnerability Details
CVE-ID: CVE-2026-61639
Affected Software: ellite Wallos
Affected Versions: < 4.9.6
Vulnerability: The application fails to validate ZIP entry names for directory traversal sequences within the restore functionality. By crafting a ZIP file containing path traversal sequences, an attacker with administrative privileges can bypass extension filters and write a webshell to the webroot.
Business Impact
A successful exploitation of this vulnerability allows an attacker to gain full control over the application server. Given the CVSS score of 8.5, this is classified as a high-severity issue that could lead to complete data compromise, unauthorized access to underlying system files, and potential persistence for the attacker. The ability to write arbitrary files essentially grants the attacker the same level of access as the web server user.
Remediation Plan
Immediate Action: Update the Wallos installation to version 4.9.6 or later immediately to patch the path traversal vulnerability in the restore endpoint.
Proactive Monitoring: Review web server access logs for anomalous POST requests to /endpoints/db/restore.php and monitor the file system for unexpected files created in the web directory.
Compensating Controls: Ensure that the web server process runs with the least privilege necessary, and use a Web Application Firewall (WAF) to inspect incoming ZIP archives for suspicious naming patterns.
Exploitation Status
Public Exploit Available: No (Exploit status is unknown).
Analyst Notes: As of September 1, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the vulnerability requires administrative access, the impact is significant, and the lack of path validation in the restoration process makes it a high-risk vector if an administrator account is compromised.
Analyst Recommendation
This vulnerability represents a critical security flaw in the Wallos restoration process that could lead to full system compromise. Organizations utilizing Wallos must prioritize upgrading to version 4.9.6 to eliminate this risk. Given the high severity of path traversal vulnerabilities when used for file writes, immediate remediation is strongly advised to prevent unauthorized access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.ph...
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses ssrf_helper.php but email was missed. Any authenticated user can probe internal network, cloud metadata. This issue has been patched in version 4.9.6.
---METADATA---
VENDOR: ellite
PRODUCT: Wallos
AFFECTED_VERSIONS: < 4.9.6
CONFIDENCE: high
MISSING: none
PROFILE: daily@7c4e524780a4
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-09-01T09:08:20.986Z
SOURCES_JSON: [{"url":"https://github.com/ellite/Wallos/security/advisories/GHSA-f8r5-v75m-385h","name":"https://github.com/ellite/Wallos/security/advisories/GHSA-f8r5-v75m-385h","tags":["x_refsource_CONFIRM"]},{"url":"https://github.com/ellite/Wallos/pull/1092","name":"https://github.com/ellite/Wallos/pull/1092","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","name":"https://github.com/ellite/Wallos/commit/b75f13d0ffa3ed7e77e8e79e4b9fd3fc528c98d3","tags":["x_refsource_MISC"]},{"url":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","name":"https://github.com/ellite/Wallos/releases/tag/v4.9.6","tags":["x_refsource_MISC"]}]
---END_METADATA---
Description Summary:
A Server-Side Request Forgery vulnerability in the testemailnotifications.php endpoint of Wallos allows authenticated users to probe internal network resources and cloud metadata services.
Executive Summary:
Wallos versions prior to 4.9.6 contain a Server-Side Request Forgery vulnerability that allows authenticated attackers to perform unauthorized internal network reconnaissance.
Vulnerability Details
CVE-ID: CVE-2026-61638
Affected Software: ellite Wallos
Affected Versions: < 4.9.6
Vulnerability: This Server-Side Request Forgery (CWE-918) flaw exists within the testemailnotifications.php script, which fails to properly validate the smtpaddress and smtpport parameters provided in POST requests. An authenticated user can leverage this oversight to force the application to connect to arbitrary internal hosts and cloud metadata endpoints.
Business Impact
The ability to perform Server-Side Request Forgery poses a significant risk to internal infrastructure by bypassing network segmentation and security perimeters. An attacker could potentially access sensitive cloud metadata, internal services, or private APIs not exposed to the public internet, leading to unauthorized information disclosure. With a CVSS score of 8.2, this vulnerability is classified as High, reflecting the potential for severe impact on confidentiality despite the requirement for authenticated access.
Remediation Plan
Immediate Action: Update the Wallos installation to version 4.9.6 or later, which implements the necessary validation logic to prevent unauthorized requests.
Proactive Monitoring: Review application access logs for unusual POST requests directed at the testemailnotifications.php endpoint, specifically looking for internal IP addresses or cloud metadata service endpoints in the request body.
Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect and block POST requests containing suspicious hostnames or internal IP addresses in the smtpaddress field.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of September 1, 2026, there is no public information indicating active exploitation or a published proof-of-concept for this vulnerability. The flaw is inherently exploitable by any user with valid application credentials, making it a critical concern for environments where user access is not strictly limited to trusted personnel.
Analyst Recommendation
Given the ease with which this vulnerability can be leveraged to map internal network topology, administrators should prioritize patching to version 4.9.6. Even in restricted environments, the risk of credential compromise leading to lateral movement via this SSRF vector remains high. Immediate application of the vendor-provided update is the only effective way to fully neutralize this security risk.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was identified in code-projects Lost and Found Thing Management 1
A vulnerability was identified in code-projects Lost and Found Thing Management 1
---METADATA---
VENDOR: code-projects
PRODUCT: Lost and Found Thing Management
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: lanPwa (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357051","name":"VDB-357051 | code-projects Lost and Found Thing Management catageory.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357051/cti","name":"VDB-357051 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797088","name":"Submit #797088 | code-projects Lost and Found Thing Management V1.0 SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/lanPwa/CVE/issues/2","name":null,"tags":["exploit","issue-tracking"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
A SQL injection vulnerability exists in the Lost and Found Thing Management application, specifically within the catageory.php file, which allows remote attackers to manipulate the cat argument.
Executive Summary:
The Lost and Found Thing Management application contains a critical SQL injection vulnerability that allows remote, unauthenticated attackers to potentially compromise database information.
Vulnerability Details
CVE-ID: CVE-2026-6163
Affected Software: code-projects Lost and Found Thing Management
Affected Versions: 1.0
Vulnerability: This is a SQL injection flaw (CWE-89) triggered via the cat parameter in the catageory.php script. The vulnerability allows an unauthenticated remote attacker to inject malicious SQL commands into the application database.
Business Impact
Successful exploitation of this SQL injection vulnerability could lead to unauthorized access to sensitive data stored within the application database. Given the CVSS score of 7.3, this represents a high-severity risk that could result in data exfiltration or potential manipulation of application records. Such an incident poses a significant threat to data confidentiality and the overall integrity of the business environment.
Remediation Plan
Immediate Action: Since no official patch is currently available, administrators should restrict access to the affected catageory.php file or disable the application until a security update is released by the vendor.
Proactive Monitoring: Security teams should monitor web access logs for anomalous patterns, such as SQL syntax characters (e.g., single quotes, double dashes, or UNION keywords) being passed to the cat parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting the catageory.php endpoint.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up at https://github.com/lanPwa/CVE/issues/2.
Analyst Notes: As of April 14, 2026, there is no public information indicating active exploitation in the wild. However, because a functional proof-of-concept is publicly available, the risk of exploitation is elevated and immediate defensive measures are required.
Analyst Recommendation
The presence of a public proof-of-concept makes this SQL injection vulnerability a high-priority risk. Organizations using the Lost and Found Thing Management application should prioritize isolating the affected component immediately. Until the vendor provides a remediation update, strict input validation and access control via a WAF are essential to prevent unauthorized database access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in code-projects Simple ChatBox up to 1
A vulnerability was determined in code-projects Simple ChatBox up to 1
---METADATA---
VENDOR: Code-Projects
PRODUCT: Simple ChatBox
AFFECTED_VERSIONS: 1.0
CONFIDENCE: high
MISSING: patch
CREDITS: AhmadMarzook (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357041","name":"VDB-357041 | code-projects Simple ChatBox Endpoint insert.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357041/cti","name":"VDB-357041 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/796697","name":"Submit #796697 | code-projects Simple ChatBox In PHP 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20in%20Simple%20Chatbox%20PHP%20msg%20Parameter.md","name":null,"tags":["exploit"]},{"url":"https://code-projects.org/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.855Z
---END_METADATA---
Description Summary:
Code-Projects Simple ChatBox version 1.0 is vulnerable to unauthenticated SQL injection via the msg parameter in /chatbox/insert.php.
Executive Summary:
An unauthenticated SQL injection vulnerability in Code-Projects Simple ChatBox 1.0 allows remote attackers to execute arbitrary database queries and potentially compromise backend data.
Vulnerability Details
CVE-ID: CVE-2026-6161
Affected Software: Code-Projects Simple ChatBox
Affected Versions: 1.0
Vulnerability: The application fails to sanitize the msg parameter within the /chatbox/insert.php endpoint before passing it to backend SQL queries. This allows an unauthenticated attacker to inject malicious SQL commands, enabling time-based blind SQL injection.
Business Impact
Successful exploitation grants an attacker the ability to interact directly with the underlying database. This can lead to unauthorized data exfiltration, modification or deletion of chat records, and potential full compromise of the database management system. Given the CVSS score of 7.3, this represents a high-severity risk to confidentiality and integrity that should be addressed immediately.
Remediation Plan
Immediate Action: As no official patch is currently available, administrators should immediately restrict access to the /chatbox/insert.php endpoint or disable the affected chat functionality until a secure update is released by the vendor.
Proactive Monitoring: Review database and web server access logs for anomalous POST requests to the chatbox directory, specifically searching for SQL syntax characters such as single quotes, sleep commands, or union select statements.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection patterns targeting the msg parameter.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists and is documented in a security research write-up on GitHub.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of input validation and the use of direct string concatenation in SQL queries.
Analyst Recommendation
The presence of a functional proof-of-concept for this SQL injection vulnerability creates a significant risk of unauthorized data access. Users are strongly advised to limit exposure by restricting network access to the application and implementing strict WAF filtering. If the software cannot be secured through these compensating controls, it should be removed from production environments until the vendor provides a patched version that utilizes prepared statements.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in Totolink N300RH 6
A flaw has been found in Totolink N300RH 6
---METADATA---
VENDOR: Totolink
PRODUCT: N300RH
AFFECTED_VERSIONS: 6.1c.1353_B20190305, 6.1c.1390_B20191101
CONFIDENCE: high
MISSING: none
CREDITS: xuanyu (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357038","name":"VDB-357038 | Totolink N300RH upgrade.so setUpgradeUboot os command injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357038/cti","name":"VDB-357038 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/796426","name":"Submit #796426 | TOTOLINK N300RH_V4 V6.1c.1353_B20190305 OS Command Injection","tags":["third-party-advisory"]},{"url":"https://github.com/xyh4ck/iot_poc/tree/main/TOTOLINK/N300RHv4/02_setUpgradeUboot_RCE","name":null,"tags":["exploit","patch"]},{"url":"https://www.totolink.net/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.859Z
---END_METADATA---
Description Summary:
Totolink N300RH routers are vulnerable to unauthenticated OS command injection in the setUpgradeUboot function, allowing remote attackers to execute arbitrary commands with root privileges.
Executive Summary:
A critical, unauthenticated remote code execution vulnerability in Totolink N300RH routers allows attackers to gain full system control via the web management interface.
Vulnerability Details
CVE-ID: CVE-2026-6158
Affected Software: Totolink N300RH
Affected Versions: 6.1c.1353_B20190305, 6.1c.1390_B20191101
Vulnerability: This is an OS command injection vulnerability (CWE-78) located in the setUpgradeUboot handler within the upgrade.so file. An unauthenticated remote attacker can inject shell metacharacters into the FileName parameter during a POST request to /cgi-bin/cstecgi.cgi, which are then executed by the system as root.
Business Impact
Successful exploitation of this vulnerability grants an attacker full root access to the affected router, which can lead to complete device compromise, unauthorized network access, and the potential for the device to be leveraged as a pivot point for further attacks on the internal network. Given the CVSS score of 7.3, this represents a significant risk to organizational infrastructure, particularly where these devices are used to provide edge connectivity.
Remediation Plan
Immediate Action: Update the device firmware to a version beyond V6.1c.1390_B20191101 or apply the latest security patch provided by Totolink. If no patch is available for a specific deployment, isolate the management interface from the public internet immediately.
Proactive Monitoring: Review web server access logs for anomalous POST requests directed at /cgi-bin/cstecgi.cgi, particularly those containing shell metacharacters like backticks or semicolons in the FileName parameter.
Compensating Controls: Implement a Web Application Firewall (WAF) or an Access Control List (ACL) to restrict access to the router's management interface to known, trusted management IP addresses only.
Exploitation Status
Public Exploit Available: Yes, a functional proof of concept is available via the referenced GitHub repository.
Analyst Notes: As of April 16, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof of concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of required authentication and the use of system-level privileges during the command execution.
Analyst Recommendation
The presence of a public proof of concept and the ability for an unauthenticated attacker to gain root access makes this a high priority for remediation. Administrators should prioritize firmware updates or network-level isolation of the management interface to prevent unauthorized remote execution.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
authentik is an open-source identity provider
authentik is an open-source identity provider
---METADATA---
VENDOR: goauthentik
PRODUCT: authentik
AFFECTED_VERSIONS: < 2026.2.6, >= 2026.5.0, < 2026.5.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
The goauthentik identity provider contains authorization bypass vulnerabilities, allowing authenticated users to perform unauthorized actions due to improper key handling.
Executive Summary:
An authorization bypass vulnerability in goauthentik allows authenticated users to perform unauthorized actions by manipulating user-controlled keys.
Vulnerability Details
CVE-ID: CVE-2026-61574
Affected Software: goauthentik authentik
Affected Versions: < 2026.2.6, >= 2026.5.0, < 2026.5.5
Vulnerability: The application suffers from authorization bypass (CWE-639) and incorrect authorization (CWE-863) flaws, where user-controlled keys are not correctly validated during authorization checks.
Business Impact
As an identity provider, a compromise of authentik is critical, potentially allowing attackers to escalate privileges or access resources they are not entitled to. The CVSS score of 8.8 underscores the severity of this access control failure, which could lead to widespread unauthorized access across integrated services.
Remediation Plan
Immediate Action: Update goauthentik to version 2026.2.6 or 2026.5.5, depending on the current branch in use, to resolve the authorization logic errors.
Proactive Monitoring: Review audit logs for anomalous authorization decisions or users accessing resources outside of their expected scope.
Compensating Controls: Implement strict Network Access Control (NAC) and monitor for unusual API request patterns that might indicate an attempt to exploit authorization keys.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 19, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability stems from flaws in the authorization layer, which is a high-value target for attackers.
Analyst Recommendation
Given the central role of authentik in identity management, this patch should be applied with high urgency. Failure to remediate could allow authenticated users to circumvent security controls and gain unauthorized access to protected enterprise resources.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in Totolink A800R 4
A vulnerability was detected in Totolink A800R 4
---METADATA---
VENDOR: Totolink
PRODUCT: A800R
AFFECTED_VERSIONS: 4.1.2cu.5137_B20200730
CONFIDENCE: high
MISSING: patch
CREDITS: xuanyu (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357037","name":"VDB-357037 | Totolink A800R app.so setAppEasyWizardConfig buffer overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357037/cti","name":"VDB-357037 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/793114","name":"Submit #793114 | TOTOLINK A800R V4.1.2cu.5137_B20200730 Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/xyh4ck/iot_poc/blob/main/TOTOLINK/A800R/01_Buffer_Overflow_setAppEasyWizardConfig.md","name":null,"tags":["exploit"]},{"url":"https://www.totolink.net/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:41.859Z
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the setAppEasyWizardConfig function of Totolink A800R firmware allows remote attackers to trigger memory corruption via the apcliSsid parameter.
Executive Summary:
A critical stack-based buffer overflow in the Totolink A800R router allows remote attackers to cause system crashes or potentially execute arbitrary code.
Vulnerability Details
CVE-ID: CVE-2026-6157
Affected Software: Totolink A800R
Affected Versions: 4.1.2cu.5137_B20200730
Vulnerability: The vulnerability exists within the setAppEasyWizardConfig function of the /lib/cste_modules/app.so library. An attacker with low privileges can supply an overly long string to the apcliSsid parameter, which is then copied into a fixed-size stack buffer without bounds checking, resulting in memory corruption.
Business Impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of severity. Successful exploitation could lead to a complete denial of service of the networking device or unauthorized arbitrary code execution, potentially granting an attacker a foothold within the local network. This poses a significant risk to organizational infrastructure, as compromised routers can be used to facilitate man-in-the-middle attacks or provide persistent access to internal resources.
Remediation Plan
Immediate Action: Contact the vendor or consult the official Totolink support portal to determine if a firmware patch is available for the A800R series, as no specific patch version was provided in the current data.
Proactive Monitoring: Review system logs for unexpected reboots, service crashes, or anomalous traffic patterns targeting the /cgi-bin/cstecgi.cgi endpoint.
Compensating Controls: Implement strict access control lists on the management interface to restrict access to trusted administrative IP addresses and employ a Web Application Firewall to inspect and block excessively long input strings in POST requests.
Exploitation Status
Public Exploit Available: Yes, a functional proof-of-concept is available via the researcher write-up published on GitHub.
Analyst Notes: As of April 14, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of length validation when processing user-supplied data in the affected interface.
Analyst Recommendation
Given the availability of a public proof-of-concept and the high CVSS severity, this vulnerability presents a credible threat to the integrity and availability of the affected Totolink routers. Administrators should prioritize identifying vulnerable units and applying official vendor firmware updates as soon as they are released. If an update is not immediately available, restrict management access to the device to prevent remote exploitation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.
Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.
---METADATA---
VENDOR: Totolink
PRODUCT: A7100RU
AFFECTED_VERSIONS: 7.4cu.2313_b20191024
---END_METADATA---
Description Summary:
Totolink A7100RU allows remote OS command injection via the setIpQosRules function in the CGI handler.
Executive Summary:
A critical OS command injection vulnerability in the Totolink A7100RU permits remote, unauthenticated attackers to execute arbitrary system commands.
Vulnerability Details
CVE-ID: CVE-2026-6156
Affected Software: Totolink A7100RU
Affected Versions: 7.4cu.2313_b20191024
Vulnerability: The setIpQosRules function in /cgi-bin/cstecgi.cgi fails to sanitize the Comment argument, allowing an unauthenticated attacker to inject and execute OS commands.
Business Impact
The CVSS score of 9.8 highlights the critical threat of this vulnerability. Successful exploitation provides the attacker with full control over the device, facilitating further network penetration and data interception.
Remediation Plan
Immediate Action: Apply the vendor-provided firmware update immediately to patch the vulnerable CGI function.
Proactive Monitoring: Monitor system logs for unusual behavior or unauthorized command execution.
Compensating Controls: Ensure the router's management interface is not accessible from the public internet by configuring appropriate firewall rules.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of Apr 13, 2026, public exploit code is available. The risk of exploitation is extremely high given the remote nature of the flaw.
Analyst Recommendation
Immediate firmware updates are required to mitigate this critical risk. Restricting access to the device management interface is a necessary secondary measure to prevent unauthorized exploitation.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript
---METADATA---
VENDOR: Harttle
PRODUCT: LiquidJS
AFFECTED_VERSIONS: >= 10.26.0, < 10.27.1
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
LiquidJS is vulnerable to an infinite loop via a template processing flaw, which can lead to a denial of service.
Executive Summary:
A vulnerability in the LiquidJS template engine allows unauthenticated attackers to cause a denial of service through an infinite loop condition.
Vulnerability Details
CVE-ID: CVE-2026-61556
Affected Software: Harttle LiquidJS
Affected Versions: >= 10.26.0, < 10.27.1
Vulnerability: This is an infinite loop vulnerability (CWE-835) occurring within the template processing logic. An unauthenticated attacker can supply specifically crafted input that prevents the engine from reaching a termination condition, exhausting system resources.
Business Impact
The vulnerability carries a CVSS score of 8.7, reflecting its high impact on system availability. Successful exploitation results in a denial of service, rendering the affected application unresponsive to legitimate users and potentially causing significant operational downtime for services relying on this template engine.
Remediation Plan
Immediate Action: Update the LiquidJS package to version 10.27.1 or later to incorporate the necessary fix for the infinite loop condition.
Proactive Monitoring: Monitor application logs for spikes in CPU usage or unusually long response times associated with template rendering functions.
Compensating Controls: Implement request rate limiting or timeouts on services that process user-supplied templates to mitigate the impact of potential resource exhaustion attacks.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently exploitable by any actor capable of submitting templates to the engine.
Analyst Recommendation
Given the high severity of this denial of service vulnerability, organizations using LiquidJS should prioritize updating their dependencies immediately. Ensuring the engine is patched to version 10.27.1 will eliminate the underlying logic flaw and restore service stability.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Totolink A7100RU is vulnerable to remote OS command injection via the setWanCfg function in the CGI handler.
Totolink A7100RU is vulnerable to remote OS command injection via the setWanCfg function in the CGI handler.
---METADATA---
VENDOR: Totolink
PRODUCT: A7100RU
AFFECTED_VERSIONS: 7.4cu.2313
---END_METADATA---
Description Summary:
Totolink A7100RU is vulnerable to remote OS command injection via the setWanCfg function in the CGI handler.
Executive Summary:
A critical OS command injection vulnerability in the Totolink A7100RU allows remote attackers to execute arbitrary commands with full system privileges.
Vulnerability Details
CVE-ID: CVE-2026-6155
Affected Software: Totolink A7100RU
Affected Versions: 7.4cu.2313
Vulnerability: The setWanCfg function in /cgi-bin/cstecgi.cgi does not properly sanitize the pppoeServiceName argument, allowing for remote OS command injection by an unauthenticated attacker.
Business Impact
A CVSS score of 9.8 signifies a critical risk of full system compromise. Attackers can gain control over network configuration and traffic, potentially leading to man-in-the-middle attacks or full internal network access.
Remediation Plan
Immediate Action: Update to the latest firmware version as provided by Totolink to address the identified command injection vulnerability.
Proactive Monitoring: Monitor for suspicious network configuration changes or unusual outbound traffic from the router.
Compensating Controls: Use firewall rules to block internet-facing access to the device's web management interface.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of Apr 13, 2026, public exploits are available. The severity and ease of exploitation necessitate immediate action.
Analyst Recommendation
This is a high-priority issue. Administrators should update affected devices immediately and ensure that management interfaces are not exposed to the public internet.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Totolink A7100RU allows remote OS command injection via the setWizardCfg function within the CGI handler.
Totolink A7100RU allows remote OS command injection via the setWizardCfg function within the CGI handler.
---METADATA---
VENDOR: Totolink
PRODUCT: A7100RU
AFFECTED_VERSIONS: 7.4cu.2313_b20191024
---END_METADATA---
Description Summary:
Totolink A7100RU allows remote OS command injection via the setWizardCfg function within the CGI handler.
Executive Summary:
A critical OS command injection vulnerability in the Totolink A7100RU allows remote, unauthenticated attackers to execute arbitrary system commands.
Vulnerability Details
CVE-ID: CVE-2026-6154
Affected Software: Totolink A7100RU
Affected Versions: 7.4cu.2313_b20191024
Vulnerability: The setWizardCfg function in /cgi-bin/cstecgi.cgi fails to sanitize the wizard argument, enabling an unauthenticated attacker to inject and execute OS commands.
Business Impact
The CVSS score of 9.8 indicates a critical risk. Successful exploitation grants the attacker full control over the router, which can be used to compromise all traffic passing through the device and potentially infiltrate internal resources.
Remediation Plan
Immediate Action: Install the latest firmware update provided by the vendor to remediate the command injection flaw.
Proactive Monitoring: Review system and audit logs for signs of arbitrary command execution or unauthorized configuration changes.
Compensating Controls: Implement strict firewall rules to prevent external access to the device's CGI management endpoints.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of Apr 13, 2026, public exploits have been identified. The potential for malicious use is high, and immediate patching is required.
Analyst Recommendation
Administrators must prioritize the firmware update for all affected devices. Until an update is applied, ensure that access to the device is limited to trusted, internal-only networks.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Tenda
PRODUCT: F456
AFFECTED_VERSIONS: 1.0.0.5
CONFIDENCE: high
MISSING: patch
CREDITS: LtzHuster (VulDB User) (reporter)
SOURCES_JSON: [{"url":"https://vuldb.com/vuln/357119","name":"VDB-357119 | Tenda F456 AdvSetWrlsafeset formWrlsafeset stack-based overflow","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/357119/cti","name":"VDB-357119 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/797468","name":"Submit #797468 | Tenda F456 v1.0.0.5 Stack-based Buffer Overflow","tags":["third-party-advisory"]},{"url":"https://github.com/Litengzheng/vuldb_new/blob/main/F456/vul_114/README.md","name":null,"tags":["exploit"]},{"url":"https://www.tenda.com.cn/","name":null,"tags":["product"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T13:56:40.739Z
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the Tenda F456 web interface allows remote attackers to trigger memory corruption and potential code execution via a crafted mit_ssid parameter.
Executive Summary:
A critical stack-based buffer overflow vulnerability in Tenda F456 routers poses a significant risk of remote code execution for authenticated users.
Vulnerability Details
CVE-ID: CVE-2026-6197
Affected Software: Tenda F456
Affected Versions: 1.0.0.5
Vulnerability: This vulnerability occurs in the formWrlsafeset function within the /goform/AdvSetWrlsafeset endpoint, where the mit_ssid parameter is processed without adequate length validation. This memory corruption flaw can be triggered by an authenticated user to overwrite the stack, potentially leading to denial of service or remote code execution.
Business Impact
Successful exploitation allows an attacker to gain unauthorized control over the affected network device, which may lead to complete compromise of local network traffic or permanent denial of service. Given the high CVSS score of 8.8, this flaw represents a severe threat to infrastructure integrity and data confidentiality.
Remediation Plan
Immediate Action: Contact the vendor for firmware updates, as no official patch is currently identified for this specific version. If no update is available, restrict management interface access to trusted administrative networks only.
Proactive Monitoring: Monitor device logs for unusual POST requests directed at the /goform/AdvSetWrlsafeset endpoint and watch for abnormal system reboots or service crashes.
Compensating Controls: Implement strict network access control lists to prevent unauthorized users from reaching the administrative web interface of the router.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up by Li Tengzheng.
Analyst Notes: As of April 15, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the lack of bounds checking in the target function.
Analyst Recommendation
The presence of a publicly available proof-of-concept significantly lowers the barrier for exploitation. Organizations utilizing Tenda F456 hardware must treat this vulnerability with high urgency, isolating vulnerable devices from the public internet until a vendor-supplied patch is applied.