<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Express</title>
  <link>https://cvedaily.com/pages/tags/express.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/express.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Express</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-9618 – The PeachPay — Payments &amp; Express Checkout for WooCommerce (supports Stripe, Pay...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9618</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9618</strong></p>
  <p>The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or incorrect nonce validation on the peachpay_stripe_handle_admin_actions function. This makes it possible for unauthenticated attackers to permanentl…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8347 – Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8347</guid>
    <pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8347</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8415 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8415</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8415</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7881 – Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7881</guid>
    <pubDate>Thu, 21 May 2026 22:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7881</strong></p>
  <p>Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani f…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-37281 – An OS command injection vulnerability in the /stream-to-vlc Express route in hit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37281</guid>
    <pubDate>Tue, 19 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-37281</strong></p>
  <p>An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8723 – ### Summary



`qs.stringify` throws `TypeError` when called with `arrayFormat: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8723</guid>
    <pubDate>Sun, 17 May 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8723</strong></p>
  <p>### Summary    `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).    ### Details    In the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encod…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41893 – Signal K Server is a server application that runs on a central hub in a boat. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41893</guid>
    <pubDate>Sat, 09 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41893</strong></p>
  <p>Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path — sending {login: {username, password}} messages over an established WebSocket conn…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42353 – i18next-http-middleware is a middleware to be used with Node.js web frameworks l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42353</guid>
    <pubDate>Fri, 08 May 2026 16:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42353</strong></p>
  <p>i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languages, namespaces, …) without any sanitization. Depending on which backend is configured, the unvalida…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41690 – 18next-http-middleware is a middleware to be used with Node.js web frameworks li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41690</guid>
    <pubDate>Fri, 08 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41690</strong></p>
  <p>18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach internal object-key writes: getResourcesHandler and missingKeyHandler. This can break authorisatio…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41683 – i18next-http-middleware is a middleware to be used with Node.js web frameworks l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41683</guid>
    <pubDate>Fri, 08 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41683</strong></p>
  <p>i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled language values into the Content-Language response header after passing them through utils.escape(), which is an HTML-entity encoder that does not strip carriage return, line feed, or other control character…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41423 – Angular is a development platform for building mobile and desktop web applicatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41423</guid>
    <pubDate>Fri, 08 May 2026 14:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41423</strong></p>
  <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server due to improper handling of URLs during Server-Side Rendering (SSR). When an attacker sends a request such as GET /\ev…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42047 – Inngest is a platform for running event-driven and scheduled background function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42047</guid>
    <pubDate>Thu, 07 May 2026 21:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42047</strong></p>
  <p>Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serve() HTTP handler. The serve() handler implements GET, POST, and PUT methods. Requests using PATCH,…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33808 – Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33808</guid>
    <pubDate>Wed, 15 Apr 2026 10:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33808</strong></p>
  <p>Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-scoped authentication middleware via duplicate slashes when ignoreDuplicateSlashes is enabled, or via semicolon delimiters when useSemicolonDelimiter is enabled. In both cases, Fastify router normaliz…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33807 – @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegist...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33807</guid>
    <pubDate>Wed, 15 Apr 2026 10:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33807</strong></p>
  <p>@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This results in complete bypass of Express middleware secur…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3461 – The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authenticati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3461</guid>
    <pubDate>Wed, 15 Apr 2026 09:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3461</strong></p>
  <p>The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users in based solely on a user-supplied billing email address during guest checkout for subscription products, without verifying email ownership, requiring a password, or validating a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34899 – Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34899</guid>
    <pubDate>Tue, 07 Apr 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34899</strong></p>
  <p>Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23448 – In the Linux kernel, the following vulnerability has been resolved:

net: usb: c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23448</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23448</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check  cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset:    if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)  but the second check omits it:    if ((sizeof(stru…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23447 – In the Linux kernel, the following vulnerability has been resolved:

net: usb: c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23447</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23447</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check  The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length without accounting for ndpoffset, allowing out-of-bounds reads when the NDP32 is placed near the en…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34076 – Clerk JavaScript is the official JavaScript repository for Clerk authentication...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34076</guid>
    <pubDate>Wed, 01 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34076</strong></p>
  <p>Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express from versions 2.0.0 to before 2.0.7, @clerk/backend from versions 3.0.0 to before 3.2.3, and @clerk/fastify from versions 3.1.0 to before 3.1.5, the clerkFrontendApiProxy function in @clerk/backend is vulnerable to Server-Side Request Forgery (SSRF).…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27508 – Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27508</guid>
    <pubDate>Mon, 30 Mar 2026 17:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27508</strong></p>
  <p>Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsers when clicked through the unsanitized link.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26352 – Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26352</guid>
    <pubDate>Mon, 30 Mar 2026 17:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26352</strong></p>
  <p>Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33979 – Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user inp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33979</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33979</strong></p>
  <p>Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has been identified in versions prior to 2.0.2 where restrictive sanitization configurations are silently ignored. In version 2.0.2, the validation logic has been updated to respect explicitly pro…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25612 – Admin Express 1.2.5.485 contains a local structured exception handling buffer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25612</guid>
    <pubDate>Sun, 22 Mar 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25612</strong></p>
  <p>Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clickin…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32730 – ApostropheCMS is an open-source content management framework. Prior to version 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32730</guid>
    <pubDate>Wed, 18 Mar 2026 23:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32730</strong></p>
  <p>ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens — where the password was verified but TOTP/MFA requirements were NOT — to be used as fully authenticated bearer tokens. This completely bypasses…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4171 – A security vulnerability has been detected in CodeGenieApp serverless-express up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4171</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4171</strong></p>
  <p>A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/models/TodoList.ts of the component API Endpoint. The manipulation of the argument userId leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclos…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32594 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32594</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32594</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection control, and query complexity limits. An attacker can connect to the WebSocket endpoint and execute GraphQ…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31949 – LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Den...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31949</guid>
    <pubDate>Fri, 13 Mar 2026 19:54:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31949</strong></p>
  <p>LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to crash the Node.js server process by sending malformed requests. The DELETE /api/convos route handler attempts to destructure req.body.arg without validating that it exists. The server crashes due to an…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3992 – A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3992</guid>
    <pubDate>Thu, 12 Mar 2026 06:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3992</strong></p>
  <p>A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This manipulation of the argument filter causes injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3965 – A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3965</guid>
    <pubDate>Thu, 12 Mar 2026 00:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3965</strong></p>
  <p>A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.20.2 is able to address t…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20117 – A vulnerability in the web-based management interface of Cisco Unified Contact C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20117</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20117</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.  This vulnerability exists because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20116 – A vulnerability in the web-based management interface of&amp;nbsp; Cisco Finesse, Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20116</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20116</strong></p>
  <p>A vulnerability in the web-based management interface of&nbsp; Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the int…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30972 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30972</guid>
    <pubDate>Tue, 10 Mar 2026 21:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30972</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpoint (/batch) processes sub-requests internally by routing them directly through the Promise router, bypassing Express middleware including rate limit…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-799</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30964 – web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30964</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30964</strong></p>
  <p>web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match alone. This makes exact origin policies impossible to express: scheme and port…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30827 – express-rate-limit is a basic rate-limiting middleware for Express. In versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30827</guid>
    <pubDate>Sat, 07 Mar 2026 06:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30827</strong></p>
  <p>express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in express-rate-limit applies IPv6 subnet masking (/56 by default) to all addresses that net.isIPv6() returns true for. This includes IPv4-mapped IPv6 addresses (::ffff:x.x.x.x), which Node.js returns as request.ip on du…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3452 – Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3452</guid>
    <pubDate>Wed, 04 Mar 2026 02:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3452</strong></p>
  <p>Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express Entry List block via the columns parameter. An authenticated administrator can store attacker-controlled serialized data in block configuration fields that are later passed to unserialize() without class restrictions or integrity checks. The Concrete CMS security team gave this…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1651 – The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1651</guid>
    <pubDate>Wed, 04 Mar 2026 02:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1651</strong></p>
  <p>The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27818 – TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27818</guid>
    <pubDate>Thu, 26 Feb 2026 00:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27818</strong></p>
  <p>TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25899 – Fiber is an Express inspired web framework written in Go. In versions on the v3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25899</guid>
    <pubDate>Tue, 24 Feb 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25899</strong></p>
  <p>Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpack deserialization. No authentication is required. Every GoFiber v3 endpoint is affected regardless o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25891 – Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25891</guid>
    <pubDate>Tue, 24 Feb 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25891</strong></p>
  <p>Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25882 – Fiber is an Express inspired web framework written in Go. A denial of service vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25882</guid>
    <pubDate>Tue, 24 Feb 2026 21:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25882</strong></p>
  <p>Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vulnerability results from missing validation during route registration combined with an unbounded array write during request matching. Version 2.52.12 patches the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69326 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69326</guid>
    <pubDate>Fri, 20 Feb 2026 16:22:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69326</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69324 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69324</guid>
    <pubDate>Fri, 20 Feb 2026 16:22:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69324</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25395 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25395</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25395</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the pre…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25394 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25394</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25394</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted payloads in parameters like INIT, HANGUP, SPEAKER_ON, SPEAKER_OFF, TONE_DIAL, and PULSE_DIAL to execute arbitrary JavaScript in users' browsers when the stored da…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25393 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25393</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25393</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation. Attackers can submit POST requests to the smoothinfo.cgi endpoint with script payloads in the WRAP or SECTIONTITLE parameters to execute arbitrary JavaScript in victim browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25392 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25392</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25392</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the IP parameter. Attackers can send POST requests to the iptools.cgi endpoint with script payloads in the IP parameter to execute arbitrary JavaScript in victim browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25390 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25390</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25390</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the interfaces.cgi script that allow attackers to inject malicious scripts through multiple parameters including GREEN_ADDRESS, GREEN_NETMASK, RED_DHCP_HOSTNAME, RED_ADDRESS, DNS1_OVERRIDE, DNS2_OVERRIDE, RED_MAC, RED_NETMASK, DEFAULT_GATEWAY, DNS1, and DNS2. Attackers can craft POS…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25389 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25389</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25389</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES parameter. Attackers can craft requests to the timedaccess.cgi endpoint with script payloads in the MACHINES parameter to execute arbitrary JavaScript in users' browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25388 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25388</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25388</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the ipblock.cgi endpoint. Attackers can inject script tags through the SRC_IP and COMMENT parameters in POST requests to execute arbitrary JavaScript in users' browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25387 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25387</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25387</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the xtaccess.cgi endpoint. Attackers can inject script payloads through the EXT, DEST_PORT, or COMMENT parameters via POST requests to execute arbitrary JavaScript in victim browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25386 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25386</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25386</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dmzholes.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the SRC_IP, DEST_IP, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25385 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25385</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25385</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT parameters. Attackers can send POST requests to the outgoing.cgi endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25384 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25384</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25384</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the EXT, SRC_PORT_SEL, SRC_PORT, DEST_IP, DEST_PORT_SEL, or COMMENT parameters to execute arbitrary JavaScript in users'…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25383 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25383</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25383</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the apcupsd.cgi script that allow attackers to inject malicious scripts through multiple POST parameters. Attackers can submit crafted POST requests with script payloads in parameters like BATTLEVEL, RTMIN, BATTDELAY, TO, ANNOY, UPSIP, UPSNAME, UPSPORT, POLLTIME, UPSUSER, NISPORT, U…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25382 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25382</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25382</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the NTP_SERVER parameter. Attackers can send POST requests to the time.cgi endpoint with script payloads in the NTP_SERVER parameter to execute arbitrary JavaScript in users' browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25381 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25381</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25381</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests to the hosts.cgi endpoint with script payloads in the IP, HOSTNAME, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25380 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25380</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25380</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multiple parameters. Attackers can submit POST requests to dhcp.cgi with script payloads in parameters such as BOOT_SERVER, BOOT_FILE, BOOT_ROOT, START_ADDR, END_ADDR, DNS1, DNS2, NTP1, NTP2, WINS1, WINS2,…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25379 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25379</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25379</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST requests with script payloads in the REDIRECT_PAGE or CHILDREN parameters to execute arbitrary JavaScript in user browsers.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25378 – Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25378</guid>
    <pubDate>Mon, 16 Feb 2026 18:19:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25378</strong></p>
  <p>Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple cross-site scripting vulnerabilities in the proxy.cgi endpoint that allow attackers to inject malicious scripts through parameters including CACHE_SIZE, MAX_SIZE, MIN_SIZE, MAX_OUTGOING_SIZE, and MAX_INCOMING_SIZE. Attackers can submit POST requests with script payloads to store or reflect arbitrary JavaScript code that executes in…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66630 – Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66630</guid>
    <pubDate>Mon, 09 Feb 2026 18:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66630</strong></p>
  <p>Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. Because no error is returned by the Fiber v2 UUID functions, application code may unknowingly rely on predictable, repeated, or low-entropy identifiers in security-critical pathways. This is e…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-26385 – Johnson Controls Metasys component listed below have  Improper Neutralization of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26385</guid>
    <pubDate>Fri, 30 Jan 2026 11:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-26385</strong></p>
  <p>Johnson Controls Metasys component listed below have  Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects       *  Metasys: Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation,    *  Ext…</p>
  <p><strong>CVSS:</strong> 9.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36115 – IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36115</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36115</strong></p>
  <p>IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36113 – IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36113</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36113</strong></p>
  <p>IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36066 – IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36066</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36066</strong></p>
  <p>IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36065 – IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36065</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36065</strong></p>
  <p>IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36063 – IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36063</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36063</strong></p>
  <p>IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14978 – The PeachPay — Payments &amp; Express Checkout for WooCommerce (supports Stripe, Pay...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14978</guid>
    <pubDate>Tue, 20 Jan 2026 02:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14978</strong></p>
  <p>The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay webhook REST endpoint in all versions up to, and including, 1.119.8. This makes it possible for unauthenticated attackers to modify the status of arbitrary WooCommer…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22037 – The @fastify/express plugin adds full Express compatibility to Fastify. A securi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22037</guid>
    <pubDate>Mon, 19 Jan 2026 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22037</strong></p>
  <p>The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin` instead of `/admin`). While the middleware engine fails to match the encoded path and skips execution, the underlying Fastify router…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-177</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68919 – Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68919</guid>
    <pubDate>Wed, 24 Dec 2025 21:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68919</strong></p>
  <p>Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68038 – Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68038</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68038</strong></p>
  <p>Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Icegram Express Pro: from n/a through < 5.9.14.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12348 – The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12348</guid>
    <pubDate>Fri, 12 Dec 2025 10:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12348</strong></p>
  <p>The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `run_action_scheduler_task` function. This makes it possible for unauthenticated attackers to execute scheduled acti…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67731 – Servify Express is a Node.js package to start an Express server and log the port...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67731</guid>
    <pubDate>Fri, 12 Dec 2025 08:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67731</strong></p>
  <p>Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used express.json() without a size limit, which could allow attackers to send extremely large request bodies. This can cause excessive memory usage, degraded performance, or process crashes, resulting in a Denial of Service (DoS). Any application using the JSON parser…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-66452 – LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66452</guid>
    <pubDate>Thu, 11 Dec 2025 23:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-66452</strong></p>
  <p>LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes user input in the error message, which gets reflected in responses. User input (including HTML/JavaScript) can be exposed in error responses, creating an XSS risk if Content-Type isn't strictly enforced. This issue does not have…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9614 – An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9614</guid>
    <pubDate>Tue, 09 Dec 2025 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9614</strong></p>
  <p>An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device rebinding may allow stale write transactions from a previous security context to be processed in a new one. This can lead to unintended data access across trusted domains, compromising confidentiality and integrity.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9613 – A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9613</guid>
    <pubDate>Tue, 09 Dec 2025 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9613</strong></p>
  <p>A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completions being delivered to the wrong security context, potentially compromising data integrity and confi…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-9612 – An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9612</guid>
    <pubDate>Tue, 09 Dec 2025 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-9612</strong></p>
  <p>An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness may allow encrypted packets to be replayed or reordered without detection. This can enable local or physical attackers on the PCIe bus to violate data integrity protections.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11379 – The WebP Express plugin for WordPress is vulnerable to information exposure via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11379</guid>
    <pubDate>Thu, 04 Dec 2025 05:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11379</strong></p>
  <p>The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract configuration data.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64298 – NMIS/BioDose V22.02 and previous version installations where the embedded Micros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64298</guid>
    <pubDate>Tue, 02 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64298</strong></p>
  <p>NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share accessed by clients in networked installs. By default, this directory has insecure directory paths that allow access to the SQL Server database and configuration files, which can contain sensitive data.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-51999 – Express.js minimalist web framework for node. Prior to 5.2.0 and 4.22.0, when us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51999</guid>
    <pubDate>Mon, 01 Dec 2025 21:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-51999</strong></p>
  <p>Express.js minimalist web framework for node. Prior to 5.2.0 and 4.22.0, when using the extended query parser in express ('query parser': 'extended'), the request.query object inherits all object prototype properties, but these properties can be overwritten by query string parameter keys that match the property names. This vulnerability is fixed in 5.2.0 and 4.22.0.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12349 – The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12349</guid>
    <pubDate>Wed, 19 Nov 2025 05:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12349</strong></p>
  <p>The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the `trigger_mailing_queue_sending` function. This makes it possible for unauthenticated attackers to force immediate email send…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13204 – npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13204</guid>
    <pubDate>Fri, 14 Nov 2025 17:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13204</strong></p>
  <p>npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-20358 – A vulnerability in the Contact Center Express (CCX) Editor application of Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20358</guid>
    <pubDate>Wed, 05 Nov 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-20358</strong></p>
  <p>A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution.  This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An a…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62052 – Missing Authorization vulnerability in Horea Radu One Page Express Companion one...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62052</guid>
    <pubDate>Wed, 22 Oct 2025 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62052</strong></p>
  <p>Missing Authorization vulnerability in Horea Radu One Page Express Companion one-page-express-companion.This issue affects One Page Express Companion: from n/a through <= 1.6.43.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49917 – Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49917</guid>
    <pubDate>Wed, 22 Oct 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49917</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Server Side Request Forgery.This issue affects Icegram Express Pro: from n/a through <= 5.9.5.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61922 – PrestaShop Checkout is the PrestaShop official payment module in partnership wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61922</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61922</strong></p>
  <p>PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-11609 – A flaw has been found in code-projects Hospital Management System 1.0. Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11609</guid>
    <pubDate>Sat, 11 Oct 2025 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-11609</strong></p>
  <p>A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-320</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57205 – iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57205</guid>
    <pubDate>Mon, 22 Sep 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57205</strong></p>
  <p>iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). Due to insufficient input sanitization and output encoding, attackers can in…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36064 – IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36064</guid>
    <pubDate>Mon, 22 Sep 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36064</strong></p>
  <p>IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59364 – The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59364</guid>
    <pubDate>Sun, 14 Sep 2025 23:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59364</strong></p>
  <p>The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49399 – Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49399</guid>
    <pubDate>Wed, 20 Aug 2025 08:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49399</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Request Forgery.This issue affects NEX-Forms: from n/a through <= 9.1.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9096 – A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9096</guid>
    <pubDate>Mon, 18 Aug 2025 00:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9096</strong></p>
  <p>A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. Affected is an unknown function in the library lib/rest/routes/apps.js of the component REST Endpoint. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9095 – A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9095</guid>
    <pubDate>Sun, 17 Aug 2025 23:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9095</strong></p>
  <p>A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issue affects some unknown processing in the library lib/rest/routes/users.js of the component REST Endpoint. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8991 – A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8991</guid>
    <pubDate>Fri, 15 Aug 2025 01:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8991</strong></p>
  <p>A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_freight_min leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-840</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54801 – Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54801</guid>
    <pubDate>Wed, 06 Aug 2025 00:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54801</strong></p>
  <p>Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in the underlying schema decoder. The root cause is that the decoder attempts to allocate a slice of le…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-50067 – Vulnerability in Oracle Application Express (component: Strategic Planner Starte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50067</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-50067</strong></p>
  <p>Vulnerability in Oracle Application Express (component: Strategic Planner Starter App).  Supported versions that are affected are 24.2.4 and  24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27361 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27361</guid>
    <pubDate>Fri, 27 Jun 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27361</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Express for Google photo-express-for-google allows Reflected XSS.This issue affects Photo Express for Google: from n/a through <= 0.3.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48111 – Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48111</guid>
    <pubDate>Tue, 17 Jun 2025 15:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48111</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20275 – A vulnerability in the file opening process of Cisco Unified Contact Center Expr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20275</guid>
    <pubDate>Wed, 04 Jun 2025 17:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20275</strong></p>
  <p>A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device.&nbsp;  This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by persuading an authenticated, local user to open a cr…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48075 – Fiber is an Express-inspired web framework written in Go. Starting in version 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48075</guid>
    <pubDate>Thu, 22 May 2025 18:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48075</strong></p>
  <p>Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead of returning an error stating it cannot process the data. Since this data is user-provided, this could lead to denial of service for anyone relyi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20189 – A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20189</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20189</strong></p>
  <p>A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition.  This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-762</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20189">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
