Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-31 | 2026-09-19 |
|---|---|---|
| ≥90 % | 0 | 0 |
| ≥50 % | 0 | 0 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 299 |
CVE-2026-63349: CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module
CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module Vulnerability ID: CVE-2026-63349 CVSS Score: 7.0 Published: 2026-09-18 CVE-2026-63349 is a critical privilege-dropping bypass vulnerability in the An
CVE-2026-90605 | Totolink A3002MU Hh-B20211125.1046 boa /boafrm/formFilter ip6addr buffer overflow
A vulnerability classified as very critical was found in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip
CVE-2026-90600 | itsourcecode Sales and Inventory System 1.0 /pages/inv_edit1.php ID sql injection
A vulnerability identified as critical has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. This vul
CVE-2026-90596 | embedded-graphics up to 0.8.2 on 32-bit src/image/image_raw.rs new/bytes_per_row integer overflow (Issue 820)
A vulnerability was found in embedded-graphics up to 0.8.2 on 32-bit. It has been classified as critical. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. Th
CVE-2026-90595 | wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 OnlineController.java OnlineController.getOnlineInfo authorization (Issue 65)
A vulnerability was found in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 and classified as critical. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The ma
CVE-2026-90582 | evanchiu serverless-todo 1.0.3/2.0.0 API Todo Endpoint src/index.js saveTodos event.body resource consumption (Issue 10)
A vulnerability categorized as problematic has been discovered in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.
CVE-2026-90583 | kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf Query String Rendering app/sw.py index qs cross site scripting (Issue 854)
A vulnerability identified as problematic has been detected in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Per
CVE-2026-90577 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_get_field heap-based overflow (Issue 3816)
A vulnerability has been found in GPAC up to f1219cde and classified as problematic. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulatio
CVE-2026-90601 | getzep graphiti up to 0.30.2 REST API main.py improper authentication (Issue 1716)
A vulnerability labeled as critical has been found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. Thi
CVE-2023-6710 | Apache HTTP Server mod_proxy_cluster alias cross site scripting (EUVD-2023-58930 / EDB-52010)
A vulnerability was found in Apache HTTP Server. It has been declared as problematic. Affected by this issue is some unknown functionality of the component mod_proxy_cluster. The manipulation of the argument alias results in cross site scri
CVE-2026-8354 | celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress pop_tag cross site scripting (EUVD-2026-83562)
A vulnerability was found in celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress. It has been declared as problematic. This affects an unknown function. The manipulation of the argument pop_tag results in cross site scripting
CVE-2026-18346 | TikTok Plugin up to 1.4.1 on WordPress authorization (EUVD-2026-83563)
A vulnerability was found in TikTok Plugin up to 1.4.1 on WordPress and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to authorization bypass. This vulnerability appears as CVE-2026-1
CVE-2026-5410 | davidanderson Redux Framework Plugin up to 4.5.13 on WordPress Spinner class-redux-spinner.php user_meta_save spinner cross site scripting (EUVD-2026-83561)
A vulnerability classified as problematic was found in davidanderson Redux Framework Plugin up to 4.5.13 on WordPress. This affects the function user_meta_save of the file class-redux-spinner.php of the component Spinner. The manipulation o
CVE-2026-9289 | WordLift Plugin up to 3.54.10 on WordPress JSON-LD REST API /wordlift/v1/jsonld get_post access control (EUVD-2026-83565)
A vulnerability was found in WordLift Plugin up to 3.54.10 on WordPress. It has been classified as problematic. The impacted element is the function get_post of the file /wordlift/v1/jsonld of the component JSON-LD REST API. The manipulatio
CVE-2026-9766 | Empik for Woocommerce Plugin up to 1.5.1 on WordPress authorization (EUVD-2026-83566)
A vulnerability has been found in Empik for Woocommerce Plugin up to 1.5.1 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument _empik_logistic_klass/_empik_product_state/_em
CVE-2026-1255 | YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress ysleadgen_get_captured_data information disclosure (EUVD-2026-83564)
A vulnerability, which was classified as problematic, has been found in YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress. This vulnerability affects the function ysleadgen_get_captured_data. This manipulation causes information dis
CVE-2026-1256 | ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress cross site scripting (EUVD-2026-83567)
A vulnerability was found in ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress. It has been rated as problematic. This impacts an unknown function. This manipulation causes cross site scripting. This vulnerability is handled as CVE-2
CVE-2026-76579 | LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress ESI esi cross site scripting (EUVD-2026-83568)
A vulnerability classified as problematic has been found in LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress. Affected by this issue is some unknown functionality of the component ESI. The manipulation of the argument es
CVE-2026-9613 | Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress authorization (EUVD-2026-83569)
A vulnerability, which was classified as critical, was found in Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress. This issue affects some unknown processing. Such manipulation leads to authorization bypass. This vulnerability
CVE-2026-9858 | wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress AJAX handlers woocommerce-partial-shipment.php order_id improper authorization (EUVD-2026-83570)
A vulnerability described as critical has been identified in wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress. Affected by this vulnerability is an unknown functionality of the file woocommerce-partial-shipment.ph
CVE-2026-93742 | Totolink A3002MU Hh-B20211125.1046 /boafrm/formWsc localPin command injection (EUVD-2026-83583)
A vulnerability marked as very critical has been reported in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection
CVE-2026-78030 | DBI up to 1.652 require dbm_type/dbm_mldbm code injection (EUVD-2026-83584)
A vulnerability was found in DBI up to 1.652. It has been rated as critical. This issue affects the function require. The manipulation of the argument dbm_type/dbm_mldbm leads to code injection. This vulnerability is traded as CVE-2026-7803
CVE-2026-90716 | marcobambini Gravity up to 0.9.7 Number Parser gravity_parser.c parse_number_expression out-of-bounds (Issue 446)
A vulnerability classified as problematic has been found in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulat
CVE-2026-78299 | Eclipse Embedded CDT up to 5.x/6.7 path traversal
A vulnerability has been found in Eclipse Embedded CDT up to 5.x/6.7 and classified as critical. This issue affects some unknown processing. Performing a manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-78
CVE-2026-9812 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Playbooks authorization
A vulnerability has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Playbooks. This manipulation causes authorization bypass.
CVE-2026-13417 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Boards fields.properties unusual condition
A vulnerability identified as problematic has been detected in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. This issue affects some unknown processing of the component Boards. The manipulation of the argument fields.properties leads to i
CVE-2026-10556 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Calendar Plugin unusual condition
A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. The impacted element is an unknown function of the component Calendar Plugin. Performing a manipulation results in impro
CVE-2026-90705 | D-Link DWR-M921 1.1.52 Boa Dispatch Table /boafrm/formsysCmd os command injection
A vulnerability was found in D-Link DWR-M921 1.1.52 and classified as critical. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lea
CVE-2026-90710 | taisan tarzan-cms 1.0.0 Theme Download Function ThemeService.java openConnection httpUrl server-side request forgery (IK768M)
A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Fu
CVE-2026-90695 | SourceCodester Inventory Management System 1.0 Vendor Management /api/vendors_handler.php cross site scripting
A vulnerability classified as problematic has been found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management.
CVE-2026-90700 | itsourcecode Sales and Inventory System 1.0 /pages/pro_edit1.php prodcode sql injection
A vulnerability was found in itsourcecode Sales and Inventory System 1.0 and classified as critical. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. This v
CVE-2026-90690 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection (Issue 224)
A vulnerability categorized as critical has been discovered in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Too
CVE-2026-90508 | Chengdu Qilu Technology Ludashi 6.1026.4715.714 Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorization
A vulnerability was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. It has been rated as problematic. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message
CVE-2026-90514 | SourceCodester School Registration and Fee System 1.0 save_stud.php Status sql injection
A vulnerability described as critical has been identified in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to s
CVE-2026-90503 | Chengdu Qilu Technology Ludashi 6.1026.4715.714 ComputerZ_x64.sys sub_11008 PhysicalAddress information disclosure
A vulnerability, which was classified as problematic, was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument Ph
CVE-2026-90498 | lenve vhr 1.0-SNAPSHOT vhr.sql default credentials
A vulnerability marked as critical has been reported in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. This vulnerability is referenced
CVE-2026-90496 | Fengoffice Feng Office up to 3.11.13.11 Reorder Handlers MoreController.class.php update_system_module_order/update_dimension_order modules/dims sql injection
A vulnerability identified as problematic has been detected in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php
CVE-2026-90506 | vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46 Save Account Job race condition
A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. It has been classified as problematic. This impacts an unknown function of the component Save Account Job. This manipulation causes race co
CVE-2026-90511 | GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea listSplit Interface BooksServlet.java column sql injection
A vulnerability labeled as critical has been found in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component
CVE-2026-90501 | lenve vhr 1.0-SNAPSHOT HrMapper.xml HrInfoController.updateHr Password privileges management
A vulnerability classified as critical was found in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege managemen
CVE-2021-43818 | lxml up to 4.6.4 lxml.html cross site scripting (GHSA-55x5-fj6c-h6m8 / Nessus ID 348247)
A vulnerability was found in lxml up to 4.6.4. It has been rated as problematic. This affects an unknown part of the file lxml.html. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2021-43818. It is possi
CVE-2026-81000 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Tun tun_get_user align allocation of resources (Nessus ID 348261)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. This affects the function tun_get_user of the component Tun. The manipulation of the argument align leads to allocation of resources
CVE-2026-88859 | Red Hat Enterprise Linux Trusted JavaScript cross site scripting (Nessus ID 348257)
A vulnerability identified as problematic has been detected in Red Hat Enterprise Linux. This affects an unknown part of the component Trusted JavaScript Handler. This manipulation causes cross site scripting. The identification of this vul
CVE-2026-80844 | Linux Kernel up to 7.2.2 xfrm ipv6_rearrange_rthdr out-of-bounds (Nessus ID 348261)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.2. Affected is the function ipv6_rearrange_rthdr of the component xfrm. Executing a manipulation can lead to out-of-bounds read. This vulnerability i
CVE-2026-91147 | Red Hat Enterprise Linux/OpenShift Dev Spaces cockpit-ws denial of service (Nessus ID 348262)
A vulnerability, which was classified as critical, was found in Red Hat Enterprise Linux and OpenShift Dev Spaces. This affects an unknown part of the component cockpit-ws. The manipulation results in denial of service. This vulnerability i
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE
CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor
CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user
CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s
CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in
joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0
CVE-2026-92598 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addres
CVE-2026-92597 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as [email protected](x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registr
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment
CVE-2026-92595 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key, callback)`. Because `shared.resolveContent()` normalizes the missing `options` argument to an empty object, the message-level flags copied into `mai
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using
CVE-2026-92596 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a sing
CVE-2026-92594 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding on
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are ga
CVE-2026-92593 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on a single element type can mint a token over attacker-controlled
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in
CVE-2026-92591 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action accepts a site name, serializes it through Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker who obtained
Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP
CVE-2026-92592 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie vi
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound
CVE-2026-92590 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScr
CVE-2026-92589 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding
Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) op