5.3

CVSS4.0

CVE-2026-28782 - Craft has a Permission Bypass and IDOR in Duplicate Entry Action

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "View Entries" permission (where the "Duplicate" action is res…

πŸ“… Published: March 4, 2026, 4:36 p.m. πŸ”„ Last Modified: April 16, 2026, 1:45 p.m.

7.1

CVSS4.0

CVE-2026-28781 - Craft Affected by Entries Authorship Spoofing via Mass Assignment

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) parameter into the POST request, which the backend p…

πŸ“… Published: March 4, 2026, 4:31 p.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

9.4

CVSS4.0

CVE-2026-28697 - Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.wri…

πŸ“… Published: March 4, 2026, 4:26 p.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

8.7

CVSS4.0

CVE-2026-28696 - Craft affected by IDOR via GraphQL @parseRefs

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated guests (if a Public Schema is enabled) to access sen…

πŸ“… Published: March 4, 2026, 4:21 p.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

8.7

CVSS4.0

CVE-2026-3520 - Multer vulnerable to Denial of Service via uncontrolled recursion

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No…

πŸ“… Published: March 4, 2026, 4:17 p.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

7.5

CVSS4.0

CVE-2026-28695 - Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget

Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation …

πŸ“… Published: March 4, 2026, 4:15 p.m. πŸ”„ Last Modified: April 17, 2026, 1:15 p.m.

7

CVSS4.0

CVE-2025-15558 - Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerabi…

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a vi…

πŸ“… Published: March 4, 2026, 4:14 p.m. πŸ”„ Last Modified: March 9, 2026, 5:38 p.m.

4.3

CVSS3.1

CVE-2026-23812 - Security Boundary Bypass via Routing Node Impersonation

A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for the interception or m…

πŸ“… Published: March 4, 2026, 4:13 p.m. πŸ”„ Last Modified: April 16, 2026, midnight

4.3

CVSS3.1

CVE-2026-23811 - Unauthorized Bi-Directional Traffic Interception via L2/L3 Manipulation

A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a port-stealing attack - may enab…

πŸ“… Published: March 4, 2026, 4:12 p.m. πŸ”„ Last Modified: April 16, 2026, 5:45 a.m.

4.3

CVSS3.1

CVE-2026-23810 - Cross-BSSID GTK Re-encryption and Traffic Injection

A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with the victim's BSSID.…

πŸ“… Published: March 4, 2026, 4:11 p.m. πŸ”„ Last Modified: April 16, 2026, midnight
Total resulsts: 348413
Page 1269 of 34,842
Β« previous page Β» next page
Filters