CVE-2026-15732
- EPSS 0.16%
- Veröffentlicht 06.08.2026 22:16:48
- Zuletzt bearbeitet 07.08.2026 17:16:58
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.
CVE-2026-15733
- EPSS 13.55%
- Veröffentlicht 06.08.2026 22:16:48
- Zuletzt bearbeitet 07.08.2026 18:17:08
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.
CVE-2026-15734
- EPSS 0.28%
- Veröffentlicht 06.08.2026 22:16:48
- Zuletzt bearbeitet 07.08.2026 17:16:58
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.
CVE-2026-44343
- EPSS 0.43%
- Veröffentlicht 12.05.2026 16:39:46
- Zuletzt bearbeitet 19.05.2026 16:21:34
WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is f...