<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – PHP (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/php.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/php-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – PHP (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7888 – Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize()...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7888</guid>
    <pubDate>Wed, 03 Jun 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7888</strong></p>
  <p>Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for both independ…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10704 – A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10704</guid>
    <pubDate>Wed, 03 Jun 2026 02:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10704</strong></p>
  <p>A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10694 – A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10694</guid>
    <pubDate>Wed, 03 Jun 2026 01:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10694</strong></p>
  <p>A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10620 – A flaw has been found in code-projects Student Admission System 1.0. Affected is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10620</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10620</strong></p>
  <p>A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10608 – A security flaw has been discovered in DedeCMS 5.7.88. This affects the function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10608</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10608</strong></p>
  <p>A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10607 – A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10607</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10607</strong></p>
  <p>A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10606 – A vulnerability was determined in DedeCMS 5.7.88. The affected element is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10606</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10606</strong></p>
  <p>A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33398 – NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33398</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33398</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled `post` ID and returns its content. The backend helper in `modules/Forum/classes/Forum.php` does not enforce forum or topic ACLs. In contrast, the normal topic page in `modules/Forum/pages/forum/view…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39553 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39553</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39553</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion.  This issue affects WaveRide: from n/a through 1.4.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39552 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39552</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39552</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion.  This issue affects Blueprint: from n/a before 1.1.5.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69369 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69369</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69369</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion.  This issue affects Racquet: from n/a through 1.12.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68886 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68886</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68886</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion.  This issue affects Cookiteer: from n/a through 1.4.8.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58897 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58897</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58897</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion.  This issue affects Fermentio: from n/a through 1.5.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58707 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58707</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58707</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion.  This issue affects Spin: from n/a through 1.8.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58705 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58705</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58705</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion.  This issue affects Crafti: from n/a through 1.12.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58024 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58024</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58024</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion.  This issue affects Accordion FAQ: from n/a through 2.2.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53440 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53440</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53440</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion.  This issue affects Confidant: from n/a through 1.4.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49491 – Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49491</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49491</strong></p>
  <p>Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10290 – A weakness has been identified in code-projects Hotel and Tourism Reservation Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10290</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10290</strong></p>
  <p>A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25434 – WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25434</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25434</strong></p>
  <p>WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive database information from WordPress posts and other tables.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25433 – Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25433</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25433</strong></p>
  <p>Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernam…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25430 – Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25430</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25430</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter. Attackers can send GET requests to the egeq.php endpoint with crafted SQL payloads to extract sensitive database information including version details and other data.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25429 – Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25429</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25429</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter. Attackers can send GET requests to zpro.php with crafted SQL payloads in the zProIdPro parameter to extract sensitive database information including usernames, databases, and version details.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25428 – Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25428</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25428</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10288 – A vulnerability was identified in code-projects Hotel and Tourism Reservation Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10288</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10288</strong></p>
  <p>A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10287 – A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10287</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10287</strong></p>
  <p>A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10273 – A vulnerability was found in php-censor up to 2.1.6. This affects an unknown fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10273</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10273</strong></p>
  <p>A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10263 – A vulnerability was found in SourceCodester Computer Repair Shop Management Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10263</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10263</strong></p>
  <p>A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10262 – A vulnerability has been found in code-projects Real State Services 1.0. This im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10262</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10262</strong></p>
  <p>A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10261 – A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10261</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10261</strong></p>
  <p>A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10260 – A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10260</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10260</strong></p>
  <p>A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10253 – A vulnerability was detected in itsourcecode Online House Rental System 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10253</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10253</strong></p>
  <p>A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10252 – A security vulnerability has been detected in itsourcecode Online House Rental S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10252</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10252</strong></p>
  <p>A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10251 – A weakness has been identified in itsourcecode Online House Rental System 1.0. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10251</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10251</strong></p>
  <p>A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10250 – A security flaw has been discovered in itsourcecode Online Blood Bank Management...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10250</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10250</strong></p>
  <p>A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10249 – A vulnerability was identified in itsourcecode Online Blood Bank Management Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10249</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10249</strong></p>
  <p>A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10236 – A vulnerability has been found in SourceCodester Water Billing Management System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10236</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10236</strong></p>
  <p>A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10227 – A vulnerability has been found in raisulislamg4 student_management_system_by_php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10227</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10227</strong></p>
  <p>A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The affected element is an unknown function of the file add_user_check.php of the component User Creation Handler. The manipulation of the argument role leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10226 – A flaw has been found in raisulislamg4 student_management_system_by_php up to 31...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10226</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10226</strong></p>
  <p>A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product op…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10225 – A vulnerability was detected in raisulislamg4 student_management_system_by_php u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10225</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10225</strong></p>
  <p>A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. This issue affects some unknown processing of the file login_check.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10208 – A flaw has been found in code-projects Online Hospital Management System 1.php. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10208</guid>
    <pubDate>Mon, 01 Jun 2026 02:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10208</strong></p>
  <p>A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10186 – A security vulnerability has been detected in code-projects Online Hospital Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10186</guid>
    <pubDate>Sun, 31 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10186</strong></p>
  <p>A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10185 – A weakness has been identified in SourceCodester Hospitals Patient Records Manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10185</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10185</strong></p>
  <p>A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10184 – A security flaw has been discovered in SourceCodester Hospitals Patient Records ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10184</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10184</strong></p>
  <p>A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49489 – OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49489</guid>
    <pubDate>Sun, 31 May 2026 13:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49489</strong></p>
  <p>OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection attacks and read sensitive data.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10178 – A vulnerability was detected in code-projects Online Music Site 1.0. This vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10178</guid>
    <pubDate>Sun, 31 May 2026 11:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10178</strong></p>
  <p>A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10167 – A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Manage...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10167</guid>
    <pubDate>Sun, 31 May 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10167</strong></p>
  <p>A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file application/controllers/Login.php of the component MY_Controller. Executing a manipulation of the argument role can lead to improper authentication. It is possible to launch the attack remotely. The explo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25425 – Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25425</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25425</strong></p>
  <p>Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php with crafted SQL payloads in the aid or cid parameters to extract database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25424 – Gate Pass Management System 2.1 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25424</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25424</strong></p>
  <p>Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25422 – MOGG web simulator Script contains an SQL injection vulnerability that allows un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25422</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25422</strong></p>
  <p>MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php with crafted SQL payloads in the id parameter to extract sensitive database information including usernames and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25420 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25420</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25420</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25419 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25419</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25419</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with crafted SQL payloads in the genre parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25418 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25418</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25418</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with crafted SQL payloads in the year parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25417 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25417</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25417</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25416 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25416</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25416</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25415 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25415</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25415</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25414 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25414</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25414</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25413 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25413</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25413</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25412 – Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25412</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25412</strong></p>
  <p>Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25411 – MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25411</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25411</strong></p>
  <p>MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25410 – SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25410</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25410</strong></p>
  <p>SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to /admin/media.php with module=pengurus and act=editpengurus parameters containing SQL UNION statements to extract database information including usernames, database names, and version de…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25409 – SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25409</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25409</strong></p>
  <p>SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25408 – The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25408</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25408</strong></p>
  <p>The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25407 – eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25407</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25407</strong></p>
  <p>eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database information including usernames, d…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25406 – eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25406</guid>
    <pubDate>Sat, 30 May 2026 16:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25406</strong></p>
  <p>eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database credentials, usernames, and versio…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25405 – eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25405</guid>
    <pubDate>Sat, 30 May 2026 16:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25405</strong></p>
  <p>eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10110 – A vulnerability was detected in code-projects Student Details Management System ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10110</guid>
    <pubDate>Sat, 30 May 2026 07:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10110</strong></p>
  <p>A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48557 – Spatie Laravel Media Library before version 11.23.0 contains a file upload restr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48557</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48557</strong></p>
  <p>Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .php stems in saved filenames. The blocklist also omits executable extensions including .php6, .shtml,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48555 – Spatie Laravel Media Library before version 11.23.0 contains a server-side reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48555</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48555</strong></p>
  <p>Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47123 – FreeScout is a free help desk and shared inbox built with PHP's Laravel framewor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47123</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47123</strong></p>
  <p>FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / References headers. The notification reply path (notify-{thread_id}-{user_id}-...) extracts thread_id and user_id directly from the Message-ID without HMA…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39276 – The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39276</guid>
    <pubDate>Fri, 29 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39276</strong></p>
  <p>The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25404 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25404</guid>
    <pubDate>Fri, 29 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25404</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to extract sensitive database information including version details and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25403 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25403</guid>
    <pubDate>Fri, 29 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25403</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to city_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25402 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25402</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25402</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to inc_types_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25401 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25401</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25401</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to sever_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25400 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25400</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25400</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the ajax/form_post.php endpoint with crafted SQL payloads to extract sensitive database information including schema names and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25399 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25399</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25399</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_lng parameters. Attackers can send GET requests to nearby.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25398 – The Open ISES Project 3.30A contains an SQL injection vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25398</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25398</strong></p>
  <p>The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the frm_passwd parameter. Attackers can send POST requests to main.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25395 – Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25395</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25395</strong></p>
  <p>Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to ext…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25394 – Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25394</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25394</strong></p>
  <p>Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter of boards_buttons/update_release.php. The release_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to ext…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25392 – MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25392</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25392</strong></p>
  <p>MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity function. Attackers can send POST requests to /index.php/user/log_activity with malicious SQL code in these parameters to extract sensitive database information including version and database names.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25391 – HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25391</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25391</strong></p>
  <p>HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and admin/modul/mod_update/aksi_update.php (module=update&act=hapus) endpoints process deletions without verifying…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25390 – HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25390</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25390</strong></p>
  <p>HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25389 – HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25389</guid>
    <pubDate>Fri, 29 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25389</strong></p>
  <p>HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25388 – HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25388</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25388</strong></p>
  <p>HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25386 – HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25386</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25386</strong></p>
  <p>HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus, fasilitas, and kelompok modules (for example act=print, act=editpengurus, act=editfa…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25385 – E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25385</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25385</strong></p>
  <p>E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25382 – Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25382</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25382</strong></p>
  <p>Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive data from the information_schema database.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45578 – WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45578</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45578</strong></p>
  <p>WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshellarg(). A ' in any of the three interpolated values ($users_id, $m3u8, $obj->liveTransmitionHistory_i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44239 – FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44239</guid>
    <pubDate>Fri, 29 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44239</strong></p>
  <p>FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44237 – FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44237</guid>
    <pubDate>Fri, 29 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44237</strong></p>
  <p>FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditionally returns true, allowing any party with knowledge of a valid client_id to obtain OAuth2 access tokens without providin…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48527 – HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48527</guid>
    <pubDate>Fri, 29 May 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48527</strong></p>
  <p>HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name. @haxtheweb/haxcms-…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9559 – A path traversal vulnerability exists in the campaign import feature of Mautic 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9559</guid>
    <pubDate>Fri, 29 May 2026 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9559</strong></p>
  <p>A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign:imports:create) can write arbitrary PHP files to sensitive system directories. An attacker can exp…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11993 – The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11993</guid>
    <pubDate>Fri, 29 May 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11993</strong></p>
  <p>The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via the import configuration feature without capability checks. This makes it possible for authenticated attackers, with Sub…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44657 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44657</guid>
    <pubDate>Thu, 28 May 2026 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44657</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in 2.28.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30761 – An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30761</guid>
    <pubDate>Thu, 28 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30761</strong></p>
  <p>An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24444 – SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24444</guid>
    <pubDate>Thu, 28 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24444</strong></p>
  <p>SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the recovery endpoint via HTTP. Attackers can leverage this hardcoded password to enable filtered SSH and…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35676 – phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35676</guid>
    <pubDate>Thu, 28 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35676</strong></p>
  <p>phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and inv…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37266 – An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37266</guid>
    <pubDate>Thu, 28 May 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37266</strong></p>
  <p>An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9227 – The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9227</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9227</strong></p>
  <p>The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9227">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
