CVE-2026-66601
- EPSS -
- Veröffentlicht 20.08.2026 12:16:33
- Zuletzt bearbeitet 20.08.2026 16:17:43
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66600
- EPSS -
- Veröffentlicht 20.08.2026 12:16:33
- Zuletzt bearbeitet 20.08.2026 17:19:26
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66591
- EPSS 0.16%
- Veröffentlicht 18.08.2026 22:15:08
- Zuletzt bearbeitet 20.08.2026 12:48:31
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
CVE-2026-61963
- EPSS 0.18%
- Veröffentlicht 06.08.2026 14:27:20
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-56012
- EPSS 0.36%
- Veröffentlicht 18.06.2026 14:02:38
- Zuletzt bearbeitet 18.06.2026 14:02:38
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.
CVE-2026-54198
- EPSS 0.2%
- Veröffentlicht 16.06.2026 09:00:38
- Zuletzt bearbeitet 16.06.2026 14:52:36
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
CVE-2026-34897
- EPSS 0.18%
- Veröffentlicht 06.04.2026 14:50:48
- Zuletzt bearbeitet 24.04.2026 18:08:35
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.
CVE-2026-34885
- EPSS 1.67%
- Veröffentlicht 06.04.2026 14:47:31
- Zuletzt bearbeitet 24.04.2026 18:08:35
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.
CVE-2026-32399
- EPSS 0.23%
- Veröffentlicht 13.03.2026 11:42:12
- Zuletzt bearbeitet 22.04.2026 21:30:26
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a throug...
CVE-2025-63065
- EPSS 0.36%
- Veröffentlicht 09.12.2025 14:52:34
- Zuletzt bearbeitet 27.04.2026 19:16:20
Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n...