
CVE-2025-67876
Detailed CVE-2025-67876 proof-of-concept demonstrating stored XSS in ChurchCRM group role names leading to admin session hijacking, with full…

Detailed CVE-2025-67876 proof-of-concept demonstrating stored XSS in ChurchCRM group role names leading to admin session hijacking, with full…

CVE-2026-22692 - Critical Twig Sandbox Bypass via collect()->mapInto() allowing RCE/LFI/XXE in October CMS

CVE-2026-24419 - OpenSTAManager has a SQL Injection in the Prima Nota module

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

CVE-2026-23500 - OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration in Dolibarr

CVE-2025-31337 Security Advisory - Critical Buffer Overflow in AI Chatbot Framework

XSS vulnerability on ultimatefosters

CVE-2026-22849 - Saleor lacks proper HTML sanitization in rich text fields

CVE-2026-27621 - TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

Technical analysis of CVE-2025-66628, an integer overflow in ImageMagick's TIM parser leading to out-of-bounds reads, with root cause, exploitation…

Insecure Deserialization in e107 CMS install.php


Remote Code Execution in create_conda_env function in parisneo/lollms

Detailed CVE-2025-12758 disclosure with PoC demonstrating Unicode variation selector bypass in validator.js isLength(), including root cause…

CVE-2022-33171: TypeORM SQL Injection Vulnerability