7.5

CVSS3.1

CVE-2026-22589 - Spree API has Unauthenticated IDOR - Guest Address

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supply…

πŸ“… Published: Jan. 10, 2026, 3:17 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:32 p.m.

6.1

CVSS3.1

CVE-2025-61674 - October CMS Vulnerable to Stored XSS via Editor and Branding Styles

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permission could inject malicious HTML/JS into the stylesh…

πŸ“… Published: Jan. 10, 2026, 3:14 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:33 p.m.

6.1

CVSS3.1

CVE-2025-61676 - October CMS Vulnerable to Stored XSS via Branding Styles

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the sty…

πŸ“… Published: Jan. 10, 2026, 3:14 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:34 p.m.

10

CVSS3.1

CVE-2025-65091 - XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been pat…

πŸ“… Published: Jan. 10, 2026, 3:06 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:35 p.m.

5.3

CVSS3.1

CVE-2025-65090 - XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has b…

πŸ“… Published: Jan. 10, 2026, 3:05 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:36 p.m.

5.1

CVSS4.0

CVE-2026-22597 - Ghost has SSRF via External Media Inliner

Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. T…

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 4:23 p.m.

6.7

CVSS3.1

CVE-2026-22596 - Ghost has SQL Injection in Members Activity Feed

Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in vers…

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:37 p.m.

8.1

CVSS3.1

CVE-2026-22595 - Ghost has Staff Token permission bypass

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External …

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:51 p.m.

8.1

CVSS3.1

CVE-2026-22594 - Ghost has Staff 2FA bypass

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.

πŸ“… Published: Jan. 10, 2026, 2:56 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:53 p.m.

6.5

CVSS3.1

CVE-2026-22030 - React Router has CSRF issue in Action/Server Action Request Processing

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when us…

πŸ“… Published: Jan. 10, 2026, 2:42 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:09 p.m.
Total resulsts: 327160
Page 21 of 32,716
Β« previous page Β» next page
Filters