6.5

CVSS3.1

CVE-2026-39374 - Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint

Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of ANY issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches i…

πŸ“… Published: April 7, 2026, 7:37 p.m. πŸ”„ Last Modified: April 15, 2026, 5:17 p.m.

5.1

CVSS4.0

CVE-2026-39840 - CSS injection in multiple Cargo display formats

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

πŸ“… Published: April 7, 2026, 7:35 p.m. πŸ”„ Last Modified: April 15, 2026, 11:43 p.m.

5.3

CVSS3.1

CVE-2026-39373 - JWCrypto: JWE ZIP decompression bomb

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the…

πŸ“… Published: April 7, 2026, 7:35 p.m. πŸ”„ Last Modified: April 15, 2026, 5:17 p.m.

6.3

CVSS4.0

CVE-2026-39839 - Stored XSS through URLs in Cargo's map format

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

πŸ“… Published: April 7, 2026, 7:29 p.m. πŸ”„ Last Modified: April 15, 2026, 11:50 p.m.

8.1

CVSS3.1

CVE-2026-39371 - RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changin…

πŸ“… Published: April 7, 2026, 7:28 p.m. πŸ”„ Last Modified: April 24, 2026, 6:14 p.m.

7.1

CVSS3.1

CVE-2026-39370 - WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable inte…

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm to bypass SSRF validation. The server then fetch…

πŸ“… Published: April 7, 2026, 7:26 p.m. πŸ”„ Last Modified: April 22, 2026, 6:50 p.m.

7.6

CVSS3.1

CVE-2026-39369 - WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public …

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose server-local files through the GIF poster storage …

πŸ“… Published: April 7, 2026, 7:24 p.m. πŸ”„ Last Modified: April 22, 2026, 6:50 p.m.

6.5

CVSS3.1

CVE-2026-39368 - WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege us…

πŸ“… Published: April 7, 2026, 7:23 p.m. πŸ”„ Last Modified: April 22, 2026, 6:50 p.m.

5.4

CVSS3.1

CVE-2026-39367 - WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a video's epg_li…

πŸ“… Published: April 7, 2026, 7:22 p.m. πŸ”„ Last Modified: April 22, 2026, 6:51 p.m.

6.5

CVSS3.1

CVE-2026-39366 - WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Tr…

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate their wallet balance and renew subscriptions. Th…

πŸ“… Published: April 7, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 6:51 p.m.
Total resulsts: 349182
Page 623 of 34,919
Β« previous page Β» next page
Filters