7.3

CVSS3.1

CVE-2026-26193 - Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-script…

πŸ“… Published: Feb. 19, 2026, 7:15 p.m. πŸ”„ Last Modified: April 17, 2026, 6 p.m.

7.3

CVSS3.1

CVE-2026-26192 - Open WebUI vulnerable to Stored XSS via iFrame in citations model

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML…

πŸ“… Published: Feb. 19, 2026, 7:10 p.m. πŸ”„ Last Modified: April 17, 2026, 6 p.m.

5.9

CVSS3.1

CVE-2026-26189 - Trivy Action has a script injection via sourced env file in composite action

Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 due to improper handling of action inputs when exporting environment variables. The action writes `ex…

πŸ“… Published: Feb. 19, 2026, 7:07 p.m. πŸ”„ Last Modified: April 18, 2026, 11:45 a.m.

0.0

CVE-2026-2828 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Feb. 19, 2026, 7:01 p.m. πŸ”„ Last Modified: May 4, 2026, 6:08 p.m.

8.8

CVSS4.0

CVE-2026-26063 - CediPay Affected by Improper Input Validation in Payment Processing

CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed in version 1.2.3. If upgrading is not immediately possible, restrict API access to trusted networks…

πŸ“… Published: Feb. 19, 2026, 6:53 p.m. πŸ”„ Last Modified: April 18, 2026, noon

2.1

CVSS4.0

CVE-2026-26059 - ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php

ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. Version 6.8.2 fixes this issue.

πŸ“… Published: Feb. 19, 2026, 6:45 p.m. πŸ”„ Last Modified: April 17, 2026, 6 p.m.

6.5

CVSS3.1

CVE-2026-26057 - Skill Scanner Unsecured Network Binding Vulnerability

Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerability in the API Server of Skill Scanner could allow a unauthenticated, remote attacker to interact with the server API and either trigger a denial of ser…

πŸ“… Published: Feb. 19, 2026, 6:41 p.m. πŸ”„ Last Modified: April 17, 2026, 6 p.m.

9.2

CVSS4.0

CVE-2026-27475 - SPIP < 4.4.9 Insecure Deserialization

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can trigger arbitrary ob…

πŸ“… Published: Feb. 19, 2026, 6:39 p.m. πŸ”„ Last Modified: April 16, 2026, 5 p.m.

4.8

CVSS4.0

CVE-2026-27474 - SPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix)

SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8. The echappe_anti_xss() function was not systematically applied to input, form, button, and anchor (a) HTML tags, allowing an attacker to inject malicious scripts through these e…

πŸ“… Published: Feb. 19, 2026, 6:38 p.m. πŸ”„ Last Modified: April 16, 2026, 5 p.m.

5.1

CVSS4.0

CVE-2026-27473 - SPIP < 4.4.9 Stored Cross-Site Scripting via Syndicated Sites

SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC output is not properly sanitized on the private syndicated site page, allowing an attacker who can set a malicious syndication URL to inject persistent scripts that execute when othe…

πŸ“… Published: Feb. 19, 2026, 6:38 p.m. πŸ”„ Last Modified: April 17, 2026, 6 p.m.
Total resulsts: 349182
Page 1547 of 34,919
Β« previous page Β» next page
Filters