7.4
CVE-2026-21449 - Bagisto has SSTI via first and last name from low-privilege user (not admin)
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.
8.9
CVE-2026-21448 - Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.β¦
7.1
CVE-2026-21447 - Bagisto has IDOR in Customer Order Reorder Functionality
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order Iβ¦
5.3
CVE-2026-0571 - yeqifu warehouse AppFileUtils.java createResponseEntity path traversal
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function createResponseEntity of the file warehouse\src\main\java\com\yeqifu\sys\common\AppFileUtils.java. The manipulation of the argument path results in path travβ¦
8.8
CVE-2026-21446 - Bagisto Missing Authentication on Installer API Endpoints
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker β¦
8.8
CVE-2026-21445 - Langflow Missing Authentication on Critical API Endpoints
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, β¦
5.5
CVE-2026-21444 - libtpms returns wrong initialization vector when certain symmetric ciphers are used
libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10.1. The commonly used integration of libtpms with OpenSSL 3.x contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were usedβ¦
9.2
CVE-2026-21440 - AdonisJS Path Traversal in Multipart File Handling
AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease versionβ¦
6.9
CVE-2026-0570 - code-projects Online Music Site Feedback.php sql injection
A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a manipulation of the argument fname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
7.7
CVE-2026-21433 - Emlog vulnerable to Server-Side Request Forgery (SSRF)
Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource references. When thβ¦