9.8

CVSS3.1

CVE-2025-66434 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (body_text) using frappe.render_template() with a user-supplied context (doc). Although Frappe uses a cust…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 5:57 p.m.

8.2

CVSS3.1

CVE-2025-65781 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS …

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:35 a.m.

8.1

CVSS3.1

CVE-2025-65778 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-controlled Content-Type (text/html), allowing execution of attacker-supplied HTML/JS in the application's origin and enabling session/token thef…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 1:44 a.m.

9.8

CVSS3.1

CVE-2025-66438 -

A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frappe.www.printview.get_html_and_style() triggers the rendering of the html field inside a Print Format document using frappe.render_template(t…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:20 p.m.

8.8

CVSS3.1

CVE-2025-66437 -

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a str…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:19 p.m.

8.8

CVSS3.1

CVE-2025-60786 -

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:05 p.m.

5.4

CVSS3.1

CVE-2025-65431 -

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may be mutable and should therefore be avoided for authorization decisions. The providers are now using sub instead.

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:08 p.m.

6.5

CVSS3.1

CVE-2025-65782 -

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling allows board members (and potentially other authenticated users) to add/remove arbitrary user IDs in vote.positive / vote.negative arrays, enabling vo…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:08 p.m.

9.8

CVSS3.1

CVE-2025-66440 -

An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_entry.py is vulnerable to SQL Injection. It allows an attacker to extract arbitrary data from the database by injecting SQL payloads via the to…

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 6:23 p.m.

9.1

CVSS3.1

CVE-2025-66844 -

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

πŸ“… Published: Dec. 15, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 3:38 p.m.
Total resulsts: 349182
Page 2611 of 34,919
Β« previous page Β» next page
Filters