5.3

CVSS4.0

CVE-2026-1897 - WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization

A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from remote. Upgrading to vers…

πŸ“… Published: Feb. 5, 2026, 12:02 a.m. πŸ”„ Last Modified: April 18, 2026, 6:30 p.m.

9

CVSS3.1

CVE-2025-68723 -

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) th…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 3:15 p.m.

8.8

CVSS3.1

CVE-2025-69906 -

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to up…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:07 p.m.

7.2

CVSS3.1

CVE-2025-70073 -

An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 12, 2026, 5:30 p.m.

5.5

CVSS3.1

CVE-2025-69619 -

A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 7:53 p.m.

8.8

CVSS3.1

CVE-2025-68722 -

Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and automatically processes…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 24, 2026, 6:14 p.m.

5.4

CVSS3.1

CVE-2025-68643 -

Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payload is injected into the timeFormat preference by e…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 9:16 p.m.

6.1

CVSS3.1

CVE-2025-70791 -

Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipulate the "orderDirection" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 6:56 p.m.

8.1

CVSS3.1

CVE-2025-68721 -

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the a…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 3:15 p.m.

6.1

CVSS3.1

CVE-2025-70792 -

Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipulate the "rel_id" parameter in a crafted URL and lure a user with admin privileges into visiting it, achieving JavaScript code execution in the victim's browser. The issue was rep…

πŸ“… Published: Feb. 5, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 6:54 p.m.
Total resulsts: 349182
Page 1792 of 34,919
Β« previous page Β» next page
Filters