Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cyb3R

Researcher fromCHT Security
#16792of 53,622
16Total CVSS
Vulnerabilities · 2
High
2
PT-2026-36598
8.8
2026-05-02
Sunnet · Ctms · CVE-2026-7489
**Name of the Vulnerable Software and Affected Versions** CTMS (affected versions not specified) **Description** CTMS developed by Sunnet contains a SQL Injection flaw. This allows authenticated remote attackers to inject arbitrary SQL commands, enabling them to read, modify, and delete database contents. SQL Injection is a type of flaw that occurs when an attacker can interfere with the queries that an application makes to its database. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-36599
7.2
2026-05-02
Sunnet · Ctms · CVE-2026-7490
**Name of the Vulnerable Software and Affected Versions** CTMS (affected versions not specified) CPAS (affected versions not specified) **Description** CTMS and CPAS developed by Sunnet contain an arbitrary file upload flaw. This allows privileged remote attackers to upload and execute web shell backdoors, which can lead to arbitrary code execution on the server. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.