No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised. | |
| Title | pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference | |
| First Time appeared |
Pkp
Pkp pkp-lib |
|
| Weaknesses | CWE-610 CWE-611 |
|
| CPEs | cpe:2.3:a:pkp:pkp-lib:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pkp
Pkp pkp-lib |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-19T19:30:10.341Z
Reserved: 2026-08-19T13:45:40.432Z
Link: CVE-2026-76572
No data.
Status : Received
Published: 2026-08-19T20:17:23.627
Modified: 2026-08-19T20:17:23.627
Link: CVE-2026-76572
No data.
OpenCVE Enrichment
No data.