Total CVEs

131,648

Critical Severity

2,801

High Severity

10,044

Last 7 Days

1,241
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,861 - 1,880 of 28,053 CVEs
CVE-2026-46366 HIGH - 7.5

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46365 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE request with a valid sess...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46364 CRITICAL - 9.8

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/capt...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46363 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer param...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46362 MEDIUM - 6.5

phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs as authenticated user...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46361 MEDIUM - 6.9

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded payloads that bypass html_en...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46360 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG files with deeply ne...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46359 HIGH - 7.5

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break ou...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an authenticated SQL injection issue in the frontend user order history page in Vvveb CMS. A normal frontend user can log in and access /user/orders. The order_by and di...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, there is an unauthenticated reflected cross-site scripting (XSS) issue in the public product return form in Vvveb CMS. The customer_order_id POST parameter is inserted into the O...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixed in 1.0.8.3.

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2026-45010 CRITICAL - 9.1

phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts arbitrary user-id parameters without session binding or rate limiting. Unauthenticated attackers can brute-force any user's six-digit TOTP code b...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45009 MEDIUM - 4.3

phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user accounts can access sen...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45008 MEDIUM - 6.5

phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../<path> in the client URL parameter to recursively delet...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45007 MEDIUM - 4.3

phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authenticated user can enumerate system configuration metadata including permission model, cache backend, mail...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-44826 HIGH - 7.5

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-add endpoint. Submitting a negative integer is accepted by the server and treated as a normal positive ...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list, tables.metadata.list, explorations.list, and forms.list accept a database_id without verifying that the requesting user was a collaborator on that dat...

Vendor: mathesar-foundation
Product: mathesar
Published: May 15, 2026
Source: NVD

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete operate on an exploration_id without verifying that the requesting user was a collaborator on the explorat...

Vendor: mathesar-foundation
Product: mathesar
Published: May 15, 2026
Source: NVD
CVE-2026-44366 MEDIUM - 6.1

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Vvveb CMS comment submission flow. The author field is submitted by an unauthenticated user on any public post pag...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2021-47968 MEDIUM - 6.4

Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to ...

Vendor: Podcastgenerator
Product: Podcast Generator
Published: May 15, 2026
Source: NVD