|
171
|
4.3 |
MEDIUM
Network
|
-
|
-
|
e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "M…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-43936
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
8.1 |
HIGH
Network
|
-
|
-
|
e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset l…
New
|
CWE-20 CWE-807
Improper Input Validation Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-43935
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
- |
|
-
|
-
|
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.
The FlinkSessionJob jarURI is currently not validated so th…
New
|
CWE-552 CWE-918
Files or Directories Accessible to External Parties Server-Side Request Forgery (SSRF)
|
CVE-2026-40564
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
- |
|
-
|
-
|
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
New
|
CWE-22
Path Traversal
|
CVE-2026-40384
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
- |
|
-
|
-
|
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
New
|
CWE-22
Path Traversal
|
CVE-2026-40383
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
- |
|
-
|
-
|
An improper access check allows unauthorized access to com_config webservice endpoints.
New
|
CWE-284
Improper Access Control
|
CVE-2026-35223
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
- |
|
-
|
-
|
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
New
|
CWE-89
SQL Injection
|
CVE-2026-35222
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
- |
|
-
|
-
|
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
New
|
CWE-89
SQL Injection
|
CVE-2026-35221
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
- |
|
-
|
-
|
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-35220
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
- |
|
-
|
-
|
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-30895
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|