CVE-2026-40044
- EPSS 0.48%
- Veröffentlicht 13.04.2026 18:11:01
- Zuletzt bearbeitet 17.04.2026 15:28:29
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files wi...
CVE-2026-40042
- EPSS 0.37%
- Veröffentlicht 13.04.2026 18:10:59
- Zuletzt bearbeitet 17.04.2026 15:28:29
Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki tab...
CVE-2026-40041
- EPSS 0.11%
- Veröffentlicht 13.04.2026 18:10:57
- Zuletzt bearbeitet 17.04.2026 15:28:29
Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protections on state-changing endpoints. Attackers can craft malicious reques...
CVE-2026-40040
- EPSS 0.47%
- Veröffentlicht 13.04.2026 18:10:56
- Zuletzt bearbeitet 17.04.2026 15:28:29
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scrip...
CVE-2026-40039
- EPSS 0.34%
- Veröffentlicht 13.04.2026 18:10:55
- Zuletzt bearbeitet 17.04.2026 15:28:29
Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to cond...
CVE-2026-40038
- EPSS 0.16%
- Veröffentlicht 13.04.2026 18:10:54
- Zuletzt bearbeitet 17.04.2026 15:28:29
Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. Attackers can inject scripts through the value, comment_body, arti...
CVE-2023-47437
- EPSS 0.48%
- Veröffentlicht 28.11.2023 00:15:07
- Zuletzt bearbeitet 21.11.2024 08:30:16
A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables ...