|
461
|
2.7 |
LOW
Network
|
-
|
-
|
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-36952
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
462
|
7.2 |
HIGH
Network
|
-
|
-
|
Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. Attackers can i…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-40038
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
463
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious l…
Update
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-40039
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
464
|
8.8 |
HIGH
Network
|
-
|
-
|
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40040
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
465
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-chang…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-40041
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
466
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers…
Update
|
CWE-403
Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
|
CVE-2026-40042
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
467
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username c…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40043
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
468
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write P…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40044
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
469
|
- |
|
-
|
-
|
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users w…
Update
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-32270
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
470
|
- |
|
-
|
-
|
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allo…
Update
|
CWE-89
SQL Injection
|
CVE-2026-32271
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|