CVE-2026-28225
- EPSS 0.04%
- Veröffentlicht 26.02.2026 22:40:17
- Zuletzt bearbeitet 27.02.2026 16:55:07
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.1, the `get_model` method in `ModelFilesController` (line 158-160) loads models using `Model.f...
CVE-2026-27933
- EPSS 0.03%
- Veröffentlicht 25.02.2026 23:16:01
- Zuletzt bearbeitet 27.02.2026 17:27:19
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to session hijack via cookie leakage in proxy caches. Version 0.133.0 fixes ...
CVE-2026-27635
- EPSS 0.06%
- Veröffentlicht 25.02.2026 23:10:27
- Zuletzt bearbeitet 27.02.2026 18:36:30
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.0, when model render generation is enabled, a logged-in user can achieve RCE by uploading a ZI...