| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. |
| Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. |
| Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. |
| Private Repository Existence Disclosure via go-get Meta Endpoint |
| Private Repository Metadata Remains Accessible After Access Revocation |
| Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 |
| Cross-repository issue/comment attachment re-linking can expose private attachment content |
| Gitea Remember-Me Token Theft Not Invalidating Attacker Session |
| Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 |
| OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) |
| Email Management API Bypasses ManageCredentials Feature Restrictions |
| Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service |
| OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes |
| RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) |
| SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis
concatenates partner-controlled values directly into SQL statement text using
string concatenation, with neither parameterised queries nor escaping. The
application's own escaping helper, Dazadi.sql_txt(),
is not invoked on these code paths, so a party that sends an invoice can break
out of the string literal and alter the query logic.
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592. |
| A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command. |