Webreinvent

Vaahcms

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 29.07.2026 21:33:25
  • Zuletzt bearbeitet 30.07.2026 16:45:00

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders th...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 08.10.2025 00:00:00
  • Zuletzt bearbeitet 09.10.2025 16:09:36

Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php