Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Daniel Celis

#20548of 53,635
12.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-48668
7.1
2026-06-11
Unknown · Opensis Classic · CVE-2026-8406
**Name of the Vulnerable Software and Affected Versions** openSIS Classic version 9.3 **Description** An insecure direct object reference in the messaging module allows authenticated users with access to that module to request sent-message details. This is achieved by supplying an arbitrary `mail id` value to the 'modules/messaging/SentMail.php' endpoint. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-4914
5.3
2026-01-27
Askbot · Askbot · CVE-2026-1213
**Name of the Vulnerable Software and Affected Versions** askbot versions prior to 0.12.2 **Description** An authenticated attacker with normal user permissions can modify the profile picture of other application users. **Recommendations** Update to a version later than 0.12.2.