|
3921
|
9.9 |
CRITICAL
Network
|
-
|
-
|
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escap…
|
CWE-22 CWE-73 CWE-98
Path Traversal External Control of File Name or Path Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-9559
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3922
|
7.1 |
HIGH
Network
|
-
|
-
|
An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or …
|
CWE-863
Incorrect Authorization
|
CVE-2026-9808
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3923
|
7.6 |
HIGH
Network
|
-
|
-
|
A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or…
|
CWE-79
Cross-site Scripting
|
CVE-2026-9809
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3924
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-9811
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3925
|
- |
|
-
|
-
|
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component …
|
CWE-23
Relative Path Traversal
|
CVE-2026-8326
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3926
|
- |
|
-
|
-
|
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path w…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-9508
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3927
|
- |
|
-
|
-
|
An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST reques…
|
CWE-248
Uncaught Exception
|
CVE-2026-9509
|
2026-05-30 00:39 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3928
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. Th…
|
CWE-862
Missing Authorization
|
CVE-2026-4290
|
2026-05-30 00:39 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3929
|
8.2 |
HIGH
Network
|
-
|
-
|
Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiri…
|
CWE-20
Improper Input Validation
|
CVE-2026-45137
|
2026-05-30 00:34 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3930
|
6.1 |
MEDIUM
Network
|
golang
|
net
|
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-25681
|
2026-05-30 00:30 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|