Security Risk Category

Web Application Security Risks — Page 2

Published vulnerability pages connected to Web Application. Each page keeps one canonical URL and focused remediation guidance.

239 published Web Application risks

Web Application risks

Showing 37–72 of 239 published risks.

criticalEPSS 0.003

CVE-2026-57828 Phoca Download File Upload RCE Vulnerability

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

CVE-2026-57828joomlaweb-applicationremote-code-executionfile-upload

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-44787 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with...

CVE-2026-44787web-applicationprivilege-escalation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-45780 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event...

CVE-2026-45780web-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-45788 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in...

CVE-2026-45788web-applicationinformation-disclosurefile-upload

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-46413 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2,...

CVE-2026-46413web-applicationauthorization-bypassfile-upload

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-49256 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and...

CVE-2026-49256web-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-53961 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account...

CVE-2026-53961api-securityweb-applicationcryptography

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-53962 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community...

CVE-2026-53962web-applicationxssfile-upload

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-53963 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator...

CVE-2026-53963web-applicationxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55424 in Discourse

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured link to inject JavaScript...

CVE-2026-55424web-applicationxss

Updated Jul 15, 2026

high

CVE-2026-33382 in Grafana OSS

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVE-2026-33382api-securitydevopsweb-applicationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-8595 in Grafana OSS

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVE-2026-8595browserdevopsweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-8609 in Grafana OSS

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVE-2026-8609devopsweb-applicationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-54919 in cpp-httplib

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or...

CVE-2026-54919network-securityweb-applicationcryptography

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55452 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged...

CVE-2026-55452phpweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55461 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...) when redirect_option=back is...

CVE-2026-55461phpweb-applicationopen-redirect

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55462 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only...

CVE-2026-55462phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55466 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege...

CVE-2026-55466phpweb-applicationxssfile-upload

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-55469 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary...

CVE-2026-55469phpweb-applicationpath-traversalfile-deletion

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55475 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata....

CVE-2026-55475phpapi-securityweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55479 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly...

CVE-2026-55479phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-55481 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS...

CVE-2026-55481phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55515 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,...

CVE-2026-55515phpweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-55233 in OpenResty

OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY protocol v2 implementation. When OpenResty is configured to send PROXY protocol version 2 headers to upstream servers,...

CVE-2026-55233network-securityweb-applicationdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-57213 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or...

CVE-2026-57213network-securityweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57214 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to...

CVE-2026-57214network-securityweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-52747 in ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting...

CVE-2026-52747network-securityweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-52761 in ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386...

CVE-2026-52761network-securityweb-applicationinput-validation

Updated Jul 15, 2026

criticalEPSS 0.197

CVE-2026-50522 in Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-50522windowsmicrosoftweb-applicationremote-code-execution

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-54108 in Microsoft SharePoint Server

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-54108windowsmicrosoftweb-applicationpath-traversal

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-54433 in Roundcube Webmail

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or...

CVE-2026-54433web-applicationxss

Updated Jul 15, 2026

criticalEPSS 0.013

CVE-2026-58644 in Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-58644windowsmicrosoftweb-applicationremote-code-execution

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45074 in Symfony Security HTTP

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled...

CVE-2026-45074phpweb-applicationauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-45077 in Symfony Monolog Bridge

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and...

CVE-2026-45077phpweb-applicationremote-code-executionunsafe-deserialization

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45756 in Symfony JSON Path

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match()...

CVE-2026-45756phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-55016 in Microsoft SharePoint Server

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55016windowsmicrosoftweb-applicationxss

Updated Jul 15, 2026