Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-48946

Joomla Extension – getk2.com – Privileged RCE vulnerability in K2 extension for Joomla < 2.26_CVE-2026-48946

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 5.3 CVE-2026-48945

Joomla Extension – getk2.com – Privileged RCE vulnerability in K2 extension for Joomla < 2.26_CVE-2026-48945

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames image files (gif/jpg/jpeg...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 6.5 CVE-2026-48944

Joomla Extension – getk2.com – Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26_CVE-2026-48944

The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 6.5 CVE-2026-48943

Joomla Extension – getk2.com – Authenticated user property mass-assignment in K2 extension for Joomla < 2.26_CVE-2026-48943

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserFor...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 6.5 CVE-2026-48941

Joomla Extension – getk2.com – Unauthenticated folder delete in K2 extension for Joomla < 2.26_CVE-2026-48941

The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()`...

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 5.3 CVE-2026-28898

CVE-2026-28898_CVE-2026-28898

swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTT...

Apple swift-nio-http2 CVE
MEDIUM 5.3 CVE-2026-57521

Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController_CVE-2026-57521

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization...

bitwarden server CVE
MEDIUM 6.3 CVE-2026-55964

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)_CVE-2026-55964

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usag...

wolfSSL wolfSSL 5.7.4 CVE
MEDIUM 4.2 CVE-2026-2299

Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint_CVE-2026-2299

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated ...

Mattermost Mattermost Google Drive Plugin CVE
MEDIUM 6.3 CVE-2026-12340

Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation_CVE-2026-12340

Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Id...

wolfSSL wolfSSL 5.6.4 CVE