8.1

CVSS3.1

CVE-2026-25773 - Focalboard Second-Order SQL Injection in category reorder endpoint allows data exfiltration (unsupp…

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to sanitize category IDs before incorporating them into dynamic SQL statements when reordering categories. An attacker can inject a malicious SQL payload into the category id field, which is stored in the database and later executed unsan…

📅 Published: April 3, 2026, 1:24 p.m. 🔄 Last Modified: April 3, 2026, 9:16 p.m.

7.3

CVSS3.1

CVE-2026-27655 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

📅 Published: April 3, 2026, 12:23 p.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

7.3

CVSS3.1

CVE-2026-4108 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.

📅 Published: April 3, 2026, 11:47 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

5.3

CVSS4.0

CVE-2026-5467 - Casdoor OAuth Authorization Request redirect

A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The exploit is publicly …

📅 Published: April 3, 2026, 11:45 a.m. 🔄 Last Modified: April 9, 2026, 1 a.m.

7.3

CVSS3.1

CVE-2026-4107 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

📅 Published: April 3, 2026, 11:44 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

7.3

CVSS3.1

CVE-2026-3880 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.

📅 Published: April 3, 2026, 11:41 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

7.3

CVSS3.1

CVE-2026-3879 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

📅 Published: April 3, 2026, 11:33 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

7.3

CVSS3.1

CVE-2026-28703 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

📅 Published: April 3, 2026, 11:29 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

7.3

CVSS3.1

CVE-2026-28756 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.

📅 Published: April 3, 2026, 11:11 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.

7.3

CVSS3.1

CVE-2026-28754 - Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

📅 Published: April 3, 2026, 10:08 a.m. 🔄 Last Modified: April 7, 2026, 7:55 a.m.
Total resulsts: 343968
Page 188 of 34,397
« previous page » next page
Filters