Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 PACKETSTORM:218781

📄 Shopware Improper Control_PACKETSTORM:218781

Shopware versions greater than or equal to 6.7.0.0 and less than 6.7.6.1 has an improper control related to Twig rendered views...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218746

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218746

OpenSTAManager versions 2.9.8 and below suffer from a remote SQL injection vulnerability in ajaxselect.php...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:218776

📄 OpenSTAManager 2.9.8 Cross Site Scripting_PACKETSTORM:218776

OpenSTAManager versions 2.9.8 and below suffer from a cross site scripting vulnerability in modificaiva.php via the righe parameter...

N/A N/A PACKETSTORM
NONE PACKETSTORM:218773

📄 Authentic 8 Insecure Direct Object Reference / Broken Access Control_PACKETSTORM:218773

Authentic 8 has an broken access control that can be leveraged via insecure direct object reference that can lead to PII information disclosure...

N/A N/A PACKETSTORM
HIGH 8.5 PACKETSTORM:218764

📄 ChurchCRM Cross Site Scripting_PACKETSTORM:218764

ChurchCRM versions 6.5.2 and below suffer from a persistent cross site scripting vulnerability in the person property assignment functionality. Not...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:218771

📄 Omega-PSIR Cross Site Scripting_PACKETSTORM:218771

Omega-PSIR suffers from a cross site scripting vulnerability via the lang parameter...

N/A N/A PACKETSTORM
CRITICAL 9.4 PACKETSTORM:218760

📄 OpenSTAManager 2.9.8 Command Injection_PACKETSTORM:218760

OpenSTAManager versions 2.9.8 and below suffer from a command injection vulnerability via the P7M file processing functionality...

N/A N/A PACKETSTORM
CRITICAL 9.4 PACKETSTORM:218758

📄 WBCE CMS 1.6.4 SQL Injection_PACKETSTORM:218758

WBCE CMS versions 1.6.4 and below suffer from a remote time-bsed SQL injection vulnerability via the groups parameter...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218769

📄 WBCE CMS Privilege Escalation / Insecure Direct Object Reference_PACKETSTORM:218769

WBCE CMS versions prior to 1.6.4 suffers from insecure direct object reference and privilege escalation vulnerabilities...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218733

📄 FacturaScripts SQL Injection_PACKETSTORM:218733

FacturaScripts versions prior to 2025.81 suffer from a remote SQL injection vulnerability in the Autocomplete Actions functionality...

N/A N/A PACKETSTORM