Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Prav33N-Sec

#18879de 53,638
14.2CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2026-7327
8.8
2026-02-10
Worklenz · Worklenz · CVE-2026-25947
**Name of the Vulnerable Software and Affected Versions** Worklenz versions prior to 2.1.7 **Description** Worklenz, a project management tool, contains multiple SQL injection flaws in its backend SQL query construction. These flaws affect project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation and scheduling features. The issue allows for potential unauthorized access and manipulation of data through crafted SQL queries. **Recommendations** Update to version 2.1.7 or later.
PT-2026-7943
5.4
2026-01-22
WordPress · Freeforum · CVE-2026-26188
**Name of the Vulnerable Software and Affected Versions** Solspace Freeform plugin for Craft CMS versions 5.0 through 5.14.6 **Description** A low-privilege authenticated user with form creation/editing permissions can inject arbitrary HTML and JavaScript code into the Craft Control Panel builder and integrations views. Form labels and integration metadata, controlled by the user, are rendered using `dangerouslySetInnerHTML` without proper sanitization, resulting in stored cross-site scripting (XSS). This allows for the execution of malicious scripts when any administrator views the builder or integration screens. **Recommendations** Update to version 5.14.7 or later.