5.3
CVE-2025-15496 - guchengwuyue yshopmall jobs getPage sql injection
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project wโฆ
5.1
CVE-2025-15495 - BiggiDroid Simple PHP CMS editsite.php unrestricted upload
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the argument image results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. The vendor waโฆ
9.3
CVE-2020-36875 - AccessAlly < 3.3.2 Unauthenticated Arbitrary PHP Code Execution
AccessAlly WordPress plugin versions prior toย 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web serโฆ
5.3
CVE-2025-15494 - RainyGao DocSys UserMapper.xml sql injection
A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public anโฆ
5.3
CVE-2025-15493 - RainyGao DocSys ReposAuthMapper.xml sql injection
A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulation of the argument searchWord can lead to sql injection. It is possible to launch the attack remotely. The exploit hasโฆ
7.7
CVE-2026-22196 - GestSup < 3.2.60 SQL Injection in Ticket Creation
GestSup versions prior toย 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Succeโฆ
5.1
CVE-2026-22198 - GestSup < 3.2.60 Stored XSS in API Error Logs
GestSup versions prior toย 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality. By sending an API request with a crafted X-API-KEY header value (for example, to /api/v1/ticket.php), an unauthenticated attacker can cause attacker-โฆ
7.5
CVE-2026-22197 - GestSup < 3.2.60 Multiple SQL Injections in Asset List
GestSup versions prior toย 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate dโฆ
7.7
CVE-2026-22195 - GestSup < 3.2.60 SQL Injection in Search Bar
GestSup versions prior toย 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can resโฆ
8.9
CVE-2026-22194 - GestSup <= 3.2.56 CSRF Allows Privileged Actions
GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. Thisโฆ