Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-75830 — grav-plugin-api before 1.0.15 Path Traversal via batchCopy

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp…

grav | Remote | Path Traversal
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.6 HIGH
CVE-2026-75829 — grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attack…

grav | Remote | Injection
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
9.3 CRITICAL
CVE-2026-75828 — Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated ed…

grav | Remote | Cross-Site Scripting
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
9.3 CRITICAL
CVE-2026-75827 — Grav before 2.0.15 Arbitrary File Write via error_log

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers wi…

grav | Remote | Injection
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
3.7 LOW
CVE-2026-75774 — karakeep-app karakeep OAuth Sign-In auth.ts improper authentication

A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation…

karakeep | Remote | Authentication
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
5.4 MEDIUM
CVE-2026-75107 — Grav Form Plugin before 9.1.19 Stored XSS via Field Properties

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form author…

grav | Remote | Cross-Site Scripting
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-74908 — Grav plugin-api before 1.0.15 Script Injection via SVG

Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and b…

grav | Remote | Injection
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.2 HIGH
CVE-2026-74907 — Grav before 2.0.15 Path Traversal via plugin-asset-map.php

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attac…

grav | Remote | Path Traversal
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-74906 — SiYuan before v3.7.4 Incorrect Authorization via Publish Access

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the visibility list instead of the disabled list. Anonym…

siyuan | Remote | Authorization
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-74905 — SiYuan before v3.7.4 SSRF via IPv6 Transition Address Bypass

SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDialer to enforce SSRF protection in SafeMode. The …

siyuan | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-74904 — SiYuan before v3.7.4 Missing Authorization via block API

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are …

siyuan | Remote | Authorization
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
5.3 MEDIUM
CVE-2026-74903 — SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM

SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBlockDOM endpoint, which is guarded only by CheckAuth middleware instead of CheckAdminRole like its sib…

siyuan | Remote | Authorization
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
9.3 CRITICAL
CVE-2026-74902 — SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers …

siyuan | Cross-Site Scripting
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
5.7 MEDIUM
CVE-2026-5224 — Sensitive Data Exposure in Kriptek Crypto's Cryptosim

Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryp…

| Information Disclosure
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
7.5 HIGH
CVE-2026-15585 — Path Traversal in AKIN Software's Wolvox9 ERP

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe al…

Remote | Path Traversal
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
3.7 LOW
CVE-2026-75773 — karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication

A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation r…

karakeep | Remote | Authentication
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-75627 — Bastillion Authentication Bypass via Path-Prefix Routing Mismatch

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path seg…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL
CVE-2026-75626 — SpiderFoot Stored Cross-Site Scripting via Correlation Titles

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into c…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-19608 — Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy…

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-ba…

single_sign-on build_of_keycloak | Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.4 MEDIUM
CVE-2026-19447 — Stored XSS in Fileorbis Informatics's FileOrbis

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOr…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
Showing 20 of 14809 Results