4.3

CVSS3.1

CVE-2026-26304 - Permission Bypass in Playbook Run Creation

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which allows team members to create unauthorized runs via the playbook run API. Mattermost Advisory ID: MMSA-2025-00542

📅 Published: March 16, 2026, 7:53 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

6.1

CVSS3.1

CVE-2026-30882 - Chamilo LMS: Reflected XSS in the session category listing page

Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in the session category listing page. The keyword parameter from $_REQUEST is echoed directly into an HTML href attribute without any encoding or sanitiza…

📅 Published: March 16, 2026, 7:21 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

8.8

CVSS3.1

CVE-2026-30881 - Chamilo LMS: SQL Injection in the statistics AJAX endpoint

Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST are embedded directly into a raw SQL string without proper sanitization. Although Database::escape_str…

📅 Published: March 16, 2026, 7:19 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

6.3

CVSS4.0

CVE-2026-30876 - Chamilo LMS: User enumeration vulnerability via response

Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.

📅 Published: March 16, 2026, 7:18 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

8.8

CVSS3.1

CVE-2026-30875 - Chamilo LMS: Authenticated RCE via H5P Import

Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't block .h…

📅 Published: March 16, 2026, 7:16 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

9.3

CVSS4.0

CVE-2026-28430 - Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.php

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a predictable legacy password reset mechanism, an atta…

📅 Published: March 16, 2026, 7:13 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

6.9

CVSS4.0

CVE-2026-29516 - Buffalo TeraStation TS5400R Excessive File Permissions Information Disclosure

Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on …

📅 Published: March 16, 2026, 7:07 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

7.7

CVSS4.0

CVE-2026-32267 - Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithT…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->ac…

📅 Published: March 16, 2026, 7:04 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

8.6

CVSS4.0

CVE-2026-32264 - Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and al…

📅 Published: March 16, 2026, 7:02 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.

8.6

CVSS4.0

CVE-2026-32263 - Craft CMS vulnerable to behavior injection RCE via EntryTypesController

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handler…

📅 Published: March 16, 2026, 6:57 p.m. 🔄 Last Modified: March 24, 2026, 10:49 a.m.
Total resulsts: 349182
Page 1091 of 34,919
« previous page » next page
Filters