8.2

CVSS3.1

CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a resu…

πŸ“… Published: April 10, 2026, 7:20 p.m. πŸ”„ Last Modified: April 10, 2026, 8:16 p.m.

7.7

CVSS3.1

CVE-2026-32252 - Chartbrew Cross-Tenant Template Export and Secret Disclosure in `GET /team/:team_id/template/genera…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew in GET /team/:team_id/template/generate/:project_id. The GET handler calls checkAccess(req, "updateA…

πŸ“… Published: April 10, 2026, 7:17 p.m. πŸ”„ Last Modified: April 10, 2026, 8:16 p.m.

7.8

CVSS4.0

CVE-2026-30232 - Chartbrew has SSRF in API Data Connection - No IP Validation on User-Provided URLs

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using request-promise without any IP …

πŸ“… Published: April 10, 2026, 7:15 p.m. πŸ”„ Last Modified: April 10, 2026, 8:16 p.m.

6.5

CVSS3.1

CVE-2026-27460 - Tandoor Recipes Affected by Denial of Service via Recipe Import

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly d…

πŸ“… Published: April 10, 2026, 7:09 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

5.3

CVSS3.1

CVE-2026-33737 - Chamilo LMS has an XML External Entity (XXE) Injection

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

πŸ“… Published: April 10, 2026, 7:05 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2026-33736 - Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles) via GET /api/users, including administrator accounts. This vulnerability is fixed in 2.0.0-RC.3.

πŸ“… Published: April 10, 2026, 7:03 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-33710 - Chamilo LMS has Weak REST API Key Generation (Predictable)

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000 (min == max), making the formula effectively md5(timestamp + user_id*5 - 10000).…

πŸ“… Published: April 10, 2026, 6:59 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2026-33708 - Chamilo LMS has REST API PII Exposure via get_user_info_from_username

Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including students. There is no authorization check. This vulne…

πŸ“… Published: April 10, 2026, 6:54 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

9.4

CVSS3.1

CVE-2026-33707 - Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victi…

πŸ“… Published: April 10, 2026, 6:52 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2026-33706 - Chamilo LMS has a REST API Self-Privilege Escalation (Student β†’ Teacher)

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the update_user_from_username endpoint. A student (status=5) can change their status to Teacher/CourseManager (status=1), gaining course creation and manag…

πŸ“… Published: April 10, 2026, 6:51 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.
Total resulsts: 343947
Page 9 of 34,395
Β« previous page Β» next page
Filters