Security Risk Category

Web Application Security Risks — Page 5

Published vulnerability pages connected to Web Application. Each page keeps one canonical URL and focused remediation guidance.

239 published Web Application risks

Web Application risks

Showing 145–180 of 239 published risks.

mediumEPSS 0.001

CVE-2026-9597 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681

CVE-2026-9597api-securityweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9708 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

CVE-2026-9708api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6541 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

CVE-2026-6541api-securityweb-applicationauthorization-bypassidor

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-9820 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

CVE-2026-9820api-securityweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-9824 in Mattermost Server

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676

CVE-2026-9824api-securityweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48363 in Adobe ColdFusion

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48363supply-chainweb-applicationremote-code-executionprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48364 in Adobe ColdFusion

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48364supply-chainweb-applicationremote-code-executionprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.003

CVE-2024-7708 in Eclipse Jetty

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVE-2024-7708javaweb-applicationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-10051 in Eclipse Jetty

In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trailers report the union of trailers of the first request and the current request.

CVE-2026-10051javaweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-12606 in Eclipse Grizzly

Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request smuggling.

CVE-2026-12606javaweb-applicationinput-validation

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-59083 in Apache Tomcat

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

CVE-2026-59083javaweb-applicationinput-validationauthorization-bypass

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-59084 in Apache Tomcat

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

CVE-2026-59084javaweb-applicationcryptography

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6790 in Eclipse Jetty

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112). This mismatch can cause a number of problems that may be classified as vulnerabilities such as: * URI constructions (for example, for redirects -- this is typical for login pages) * Virtual host selection * Reverse proxying * Misleading logs * Etc. Given that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant.

CVE-2026-6790javaweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-8384 in Eclipse Jetty

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.

CVE-2026-8384javaweb-applicationpath-traversal

Updated Jul 15, 2026

criticalEPSS 0.003

CVE-2026-58319 in Apache Doris

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.

CVE-2026-58319javaweb-applicationauthentication-bypassdenial-of-service

Updated Jul 15, 2026

medium

CVE-2026-49488 in Apache OpenMeetings

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to upgrade to version 9.1.0, which fixes the issue.

CVE-2026-49488javaweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

medium

CVE-2026-11944 in openSIS Classic

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.

CVE-2026-11944web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-56164 in Microsoft SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56164microsoftweb-applicationauthentication-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-49091 in Kibana

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data.

CVE-2026-49091web-applicationinput-validationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58520 in MediaWiki UrlShortener Extension

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.

CVE-2026-58520phpweb-applicationopen-redirect

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58521 in MediaWiki Cargo Extension

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-58521phpweb-applicationsql-injection

Updated Jul 15, 2026

medium

CVE-2026-14358 in MediaWiki Charts Extension

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Charts Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Charts Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-14358phpweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-49119 in Gradio

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.

CVE-2026-49119pythonweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

criticalEPSS 0.006

CVE-2026-50160 in Hoppscotch

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe is configured without whitelist: true, so extra properties on the request body that are not declared in SaveOnboardingConfigRequest are not stripped and are iterated in the service layer as if they were legitimate InfraConfig entries. Because keys such as JWT_SECRET and SESSION_SECRET are valid InfraConfigEnum values and are not explicitly rejected during validation, an unauthenticated attacker who can reach a fresh instance before onboarding completes (or when no users exist) can overwrite these values in the database. Overwriting JWT_SECRET gives the attacker control of the JWT signing key, allowing them to forge tokens for any user, including administrators, and results in full server compromise. The issue is fixed in hoppscotch 2026.5.0.

CVE-2026-50160api-securityweb-applicationauthentication-bypassprivilege-escalation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58517 in MediaWiki WikiLambda Extension

Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-58517phpweb-applicationauthentication-bypass

Updated Jul 14, 2026

medium

CVE-2026-14363 in MediaWiki Cargo Extension

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-14363phpweb-applicationsql-injection

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-58593 in NodeBB

NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. In the object mock, attributedTo is used directly as a uid, and actors.assert silently ignores numeric identifiers (filtering them out without re-deriving the uid), so a federated remote actor can set attributedTo to a bare numeric value such as 1 and have the resulting post or private message created with that local uid as author, including the administrator account. This lets a remote attacker forge posts and direct messages attributed to arbitrary local users. Requires the ActivityPub/federation feature to be enabled.

CVE-2026-58593node-jsweb-applicationauthentication-bypasscryptography

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54259 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and name and URLs of documents and images in those collections. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54259pythonweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54260 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54260pythonweb-applicationdenial-of-service

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54261 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54261pythonweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54262 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54262pythonweb-applicationauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-54263 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is present for all sites, even if they do not enable the dynamic image serve view. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54263pythonweb-applicationxss

Updated Jul 14, 2026

medium

CVE-2026-14381 in Google Chrome WebAppInstalls

Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14381browserweb-applicationinput-validationauthentication-bypass

Updated Jul 14, 2026

medium

CVE-2025-71385 Netdata Vulnerability

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text element) without HTML or XML escaping, and serves the response with Content-Type image/svg+xml. An attacker can craft a URL such as /api/v2/ilove.svg?love=<script>...</script>; when a victim navigates to it the injected script executes in the victim browser in the origin of the Netdata instance (reflected cross-site scripting). These endpoints are registered with HTTP_ACL_NOCHECK and anonymous access and, because bearer-token protection is disabled by default, are reachable without authentication on a default Netdata agent. The issue was resolved by removing the ilove endpoint.

CVE-2025-71385browserapi-securityweb-applicationxss

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-59093 Weaviate Vulnerability

Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted by the assigned role. The assignRoleToUser and assignRoleToGroup handlers (POST /authz/users/{id}/assign and /authz/groups/{id}/assign) authorize only that the caller may assign roles to the target user or group, not the permissions contained in the assigned roles, unlike role creation which enforces that a user can only create roles with permissions less than or equal to its own. A user holding only the delegated assign_and_revoke_users or assign_and_revoke_groups permission can assign the built-in admin role, or any high-privilege custom role, to itself or others, escalating to full administrative control of the database.

CVE-2026-59093web-applicationauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

low

CVE-2025-13475 api manager vulnerability

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy.

CVE-2025-13475api-securityweb-applicationauthentication-bypass

Updated Jul 13, 2026