8.1

CVSS3.1

CVE-2026-39393 - Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the install route guard in ci4ms relies solely on a volatile cache check (cache('settings')) combined with .env file existence to block po…

πŸ“… Published: April 8, 2026, 2:31 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2026-39392 - CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Pages module does not apply the html_purify validation rule to content fields during create and update operations, while the Blog modu…

πŸ“… Published: April 8, 2026, 2:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

4.8

CVSS3.1

CVE-2026-39391 - CI4MS has Stored XSS via Unescaped Blacklist Note in Admin User List

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the blacklist (ban) note parameter in UserController::ajax_blackList_post() is stored in the database without sanitization and rendered in…

πŸ“… Published: April 8, 2026, 2:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2026-39390 - CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using strip_tags() with an <iframe> allowlist and regex-bas…

πŸ“… Published: April 8, 2026, 2:29 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

6.7

CVSS3.1

CVE-2026-39389 - CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Prot…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0.

πŸ“… Published: April 8, 2026, 2:28 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

5.9

CVSS3.1

CVE-2026-39865 - Axios HTTP/2 Session Cleanup State Corruption Vulnerability

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSess…

πŸ“… Published: April 8, 2026, 2:25 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.

6.4

CVSS3.1

CVE-2025-58713 - Rhpam: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

πŸ“… Published: April 8, 2026, 1:55 p.m. πŸ”„ Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-57853 - Web-terminal: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root us…

πŸ“… Published: April 8, 2026, 1:55 p.m. πŸ”„ Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-57854 - Osus-operator: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, ev…

πŸ“… Published: April 8, 2026, 1:55 p.m. πŸ”„ Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-57851 - Mce: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

πŸ“… Published: April 8, 2026, 1:55 p.m. πŸ”„ Last Modified: April 8, 2026, 7:26 p.m.
Total resulsts: 343749
Page 51 of 34,375
Β« previous page Β» next page
Filters