|
1821
|
6.5 |
MEDIUM
Network
|
-
|
-
|
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches the content of option values server-side via `file_get_…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49359
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1822
|
3.0 |
LOW
Local
|
-
|
-
|
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invok…
|
CWE-73
External Control of File Name or Path
|
CVE-2026-49358
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1823
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's ide…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-11551
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1824
|
7.5 |
HIGH
Network
|
-
|
-
|
Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the cust…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2023-54357
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1825
|
7.1 |
HIGH
Network
|
-
|
-
|
Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid param…
|
CWE-89
SQL Injection
|
CVE-2019-25757
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1826
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST par…
|
CWE-89
SQL Injection
|
CVE-2019-25751
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1827
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attack…
|
CWE-89
SQL Injection
|
CVE-2017-20280
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1828
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. At…
|
CWE-89
SQL Injection
|
CVE-2017-20274
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1829
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' …
|
CWE-89
SQL Injection
|
CVE-2017-20268
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1830
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. A…
|
CWE-89
SQL Injection
|
CVE-2017-20262
|
2026-06-23 12:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|