Articles tagged PHP
-
Vulnerability7 SourceCodester Class and Exam Timetabling System 1.0 CVEs (CVE-2026-86220)
Seven separate CVEs (CVE-2026-86220 through 86225 and 86298) document the same unauthenticated SQL injection flaw repeated across different admin panel files in SourceCodester Class and Exam Timetabling System 1.0, with public exploit code for each.
-
VulnerabilityZ-BlogPHP Access Control Flaw (CVE-2026-8747)
CVE-2026-8747 is an improper authorization vulnerability in the comment-approval handler of Z-BlogPHP 1.7.4.3430, exploitable remotely with a public exploit.
-
VulnerabilityKirby CMS Information Disclosure (CVE-2026-69127)
CVE-2026-69127 lets Kirby CMS's REST API leak the full server filesystem path in unsanitized error messages, useful for guessing the content.salt secret, fixed in Kirby 4.9.5 and 5.5.2.
-
VulnerabilitySmarty SSRF (CVE-2026-62993)
CVE-2026-62993 lets an open redirect on a trusted host bypass Smarty's trusted_uri policy for {fetch}, enabling server-side request forgery to internal targets, fixed in 5.8.2.
-
Vulnerability5 itsourcecode Sales and Inventory System 1.0 CVEs (CVE-2026-86232)
Five separate CVEs (CVE-2026-86232 through 86236) document the same unauthenticated SQL injection flaw repeated across different pages of itsourcecode Sales and Inventory System 1.0, with public exploit code for each.