Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.1 CVE-2026-10861

MISP post-login open redirect via pre_login_requested_url_CVE-2026-10861

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session k...

misp misp CVE
MEDIUM 5.1 CVE-2026-10856

Open redirect in MISP dashboard button widget URL handling_CVE-2026-10856

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpr...

misp misp CVE
MEDIUM 5.1 CVE-2026-10855

MISP Event template importer authorization bypass_CVE-2026-10855

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the appli...

misp misp CVE
MEDIUM 5.3 CVE-2026-10854

Unauthorized exposure of private galaxies in MISP event template creation_CVE-2026-10854

A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organ...

misp misp CVE
MEDIUM 5.3 CVE-2026-10810

itsourcecode Fees Management System navbar.php cross site scripting_CVE-2026-10810

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This mani...

itsourcecode Fees Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-10809

itsourcecode Fees Management System manage_user.php sql injection_CVE-2026-10809

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The ...

itsourcecode Fees Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-10808

itsourcecode Fees Management System manage_student.php sql injection_CVE-2026-10808

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The ma...

itsourcecode Fees Management System 1.0 CVE
MEDIUM 5.3 CVE-2026-10807

mjperpinosa stumasy change_profile_image.php unrestricted upload_CVE-2026-10807

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/cha...

mjperpinosa stumasy 25d695901fbb586bf184b8ba73456d8e5311656c CVE
MEDIUM 5.3 CVE-2026-10806

mjperpinosa stumasy add_post.php unrestricted upload_CVE-2026-10806

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post....

mjperpinosa stumasy 25d695901fbb586bf184b8ba73456d8e5311656c CVE
MEDIUM 5.3 CVE-2026-47707

Strawberry GraphQL’s Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification_CVE-2026-47707

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails ...

strawberry-graphql strawberry >= 0.172.0, < 0.315.7 CVE