Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.2
CVE-2026-67595
- EPSS 0.42%
- Veröffentlicht 29.07.2026 21:33:25
- Zuletzt bearbeitet 30.07.2026 16:45:00
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders th...
6.1
CVE-2025-61183
- EPSS 0.28%
- Veröffentlicht 08.10.2025 00:00:00
- Zuletzt bearbeitet 09.10.2025 16:09:36
Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php
1