Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-56405

CVE-2026-56405_CVE-2026-56405

libexpat before 2.8.2 has an integer overflow in getAttributeId.

libexpat project libexpat CVE
MEDIUM 6.9 CVE-2026-56404

CVE-2026-56404_CVE-2026-56404

libexpat before 2.8.2 has an integer overflow in addBinding.

libexpat project libexpat CVE
MEDIUM 6.9 CVE-2026-56403

CVE-2026-56403_CVE-2026-56403

libexpat before 2.8.2 has an integer overflow in storeAtts.

libexpat project libexpat CVE
CRITICAL 9.4 CVE-2026-56397

SiYuan – Remote Code Execution via Malicious Bazaar Package Metadata and README_CVE-2026-56397

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ...

SiYuan SiYuan CVE
HIGH 8.7 CVE-2026-56396

phpMyFAQ – Privilege Escalation via Missing Authorization in editUser() and updateUserRights()_CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated admini...

phpMyFAQ phpMyFAQ CVE
CRITICAL 9.4 CVE-2026-56395

SiYuan – Remote Code Execution via Malicious Bazaar Package Metadata and README_CVE-2026-56395

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ...

SiYuan SiYuan CVE
HIGH 7.1 CVE-2026-56394

Craft CMS – Authenticated Path Traversal in assets/icon Extension Parameter_CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not va...

craftcms cms 4.0.0-RC1 CVE
MEDIUM 4.6 CVE-2026-56393

Craft CMS – Multiple Stored Cross-Site Scripting in Settings Names and Field Options_CVE-2026-56393

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities w...

craftcms cms 5.0.0-RC1 CVE
MEDIUM 5.3 CVE-2026-56385

Craft CMS – Authorization Bypass in assets/preview-file Endpoint_CVE-2026-56385

Craft CMS versions >= 5.0.0-RC1, = 4.0.0-RC1,

craftcms cms 5.0.0-RC1 CVE
MEDIUM 5.3 CVE-2026-56384

Craft CMS – Missing Authorization in assets/preview-thumb Endpoint_CVE-2026-56384

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a ta...

craftcms cms 4.0.0-RC1 CVE