Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 PACKETSTORM:218760

📄 OpenSTAManager 2.9.8 Command Injection_PACKETSTORM:218760

OpenSTAManager versions 2.9.8 and below suffer from a command injection vulnerability via the P7M file processing functionality...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218769

📄 WBCE CMS Privilege Escalation / Insecure Direct Object Reference_PACKETSTORM:218769

WBCE CMS versions prior to 1.6.4 suffers from insecure direct object reference and privilege escalation vulnerabilities...

N/A N/A PACKETSTORM
CRITICAL 9.4 PACKETSTORM:218758

📄 WBCE CMS 1.6.4 SQL Injection_PACKETSTORM:218758

WBCE CMS versions 1.6.4 and below suffer from a remote time-bsed SQL injection vulnerability via the groups parameter...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218733

📄 FacturaScripts SQL Injection_PACKETSTORM:218733

FacturaScripts versions prior to 2025.81 suffer from a remote SQL injection vulnerability in the Autocomplete Actions functionality...

N/A N/A PACKETSTORM
HIGH 8.7 PACKETSTORM:218743

📄 OpenSTAManager 2.9.8 SQL Injection / Denial of Service_PACKETSTORM:218743

OpenSTAManager versions 2.9.8 and below suffer from a remote time-based SQL injection vulnerability in the search functionality that can lead to a ...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218757

📄 EGroupware SQL Injection_PACKETSTORM:218757

EGroupware versions prior to 23.1.20260113 and greater than or equal to 26.0.20251208 but less than 26.0.20260113 are affected by a remote SQL inje...

N/A N/A PACKETSTORM
HIGH 8.8 PACKETSTORM:218750

📄 OpenSTAManager 2.9.8 SQL Injection_PACKETSTORM:218750

OpenSTAManager versions 2.9.8 and below suffer from a remote SQL injection vulnerability in the Stampe module...

N/A N/A PACKETSTORM
HIGH 8.6 PACKETSTORM:218779

📄 XWiki Blog Cross Site Scripting_PACKETSTORM:218779

XWiki Blog versions prior to 9.15.7 suffer from a persistent cross site scripting vulnerability via the blog post title...

N/A N/A PACKETSTORM
HIGH 8.1 PACKETSTORM:218798

📄 WBCE CMS 1.6.4 Brute Force_PACKETSTORM:218798

WBCE CMS versions 1.6.4 suffers from a brute force protection bypass vulnerability...

N/A N/A PACKETSTORM
CRITICAL 9.3 PACKETSTORM:218759

📄 ChurchCRM SQL Injection_PACKETSTORM:218759

ChurchCRM versions prior to 6.5.3 suffer from a remote SQL injection vulnerability in ConfirmReportEmail.php...

N/A N/A PACKETSTORM