5.4

CVSS4.0

CVE-2026-21483 - listmonk Vulnerable to Stored XSS Leading to Admin Account Takeover

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious JavaScript into campaigns or templates. When a higher-privileged user (Super Admin) views or previews this content, the…

πŸ“… Published: Jan. 2, 2026, 8:57 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 3:20 p.m.

7.5

CVSS3.1

CVE-2026-21452 - MessagePack-Java Vulnerable to Remote Denial of Service via Malicious .msgpack Model File Triggerin…

MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later tr…

πŸ“… Published: Jan. 2, 2026, 8:47 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 7:21 p.m.

7.3

CVSS4.0

CVE-2026-21450 - Bagisto has SSTI in parameter that can lead to RCE

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

πŸ“… Published: Jan. 2, 2026, 8:38 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:20 p.m.

5.2

CVSS4.0

CVE-2026-21451 - Bagisto has HTML Filter Bypass that Enables Stored XSS

Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the filtering can be bypassed by manipulating the raw HT…

πŸ“… Published: Jan. 2, 2026, 8:37 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:20 p.m.

7.4

CVSS4.0

CVE-2026-21449 - Bagisto has SSTI via first and last name from low-privilege user (not admin)

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.

πŸ“… Published: Jan. 2, 2026, 8:35 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:21 p.m.

8.9

CVSS4.0

CVE-2026-21448 - Bagisto has Normal & Blind SSTI from low-privilege user when ordering product

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.…

πŸ“… Published: Jan. 2, 2026, 8:18 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:22 p.m.

7.1

CVSS3.1

CVE-2026-21447 - Bagisto has IDOR in Customer Order Reorder Functionality

Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order I…

πŸ“… Published: Jan. 2, 2026, 8:15 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:24 p.m.

5.3

CVSS4.0

CVE-2026-0571 - yeqifu warehouse AppFileUtils.java createResponseEntity path traversal

A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function createResponseEntity of the file warehouse\src\main\java\com\yeqifu\sys\common\AppFileUtils.java. The manipulation of the argument path results in path trav…

πŸ“… Published: Jan. 2, 2026, 8:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:11 a.m.

8.8

CVSS4.0

CVE-2026-21446 - Bagisto Missing Authentication on Installer API Endpoints

Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker …

πŸ“… Published: Jan. 2, 2026, 7:18 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:25 p.m.

8.8

CVSS4.0

CVE-2026-21445 - Langflow Missing Authentication on Critical API Endpoints

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, …

πŸ“… Published: Jan. 2, 2026, 7:11 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.
Total resulsts: 344032
Page 1787 of 34,404
Β« previous page Β» next page
Filters