CVE-2026-70556
- EPSS 0.13%
- Veröffentlicht 06.08.2026 12:10:07
- Zuletzt bearbeitet 13.08.2026 21:18:08
Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under a...
CVE-2022-27257
- EPSS 1.27%
- Veröffentlicht 15.04.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:55:30
A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
CVE-2022-27258
- EPSS 0.73%
- Veröffentlicht 15.04.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:55:30
Multiple Cross-Site Scripting (XSS) vulnerabilities in Hubzilla 7.0.3 and earlier allows remote attacker to include arbitrary web script or HTML via the rpath parameter.
CVE-2022-27256
- EPSS 1.47%
- Veröffentlicht 13.04.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:30
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.