Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Caycon

#15786of 55,060
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-66600
8.8
2026-07-30
Wolfcms · Wolf Cms · CVE-2026-67206
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create file() and save() functions. Attackers with the file manager mkfile capability can write malicious PHP content into the web-accessible FILES DIR directory and trigger execution by requesting the file over HTTP.
PT-2026-66601
8.8
2026-07-30
Wolfcms · Wolf Cms · CVE-2026-67207
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without administrative privileges.