Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Majkelstick

#18393of 53,630
14.7Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-42215
9.3
2026-05-20
Xwiki · Xwiki Platform · CVE-2026-23734
**Name of the Vulnerable Software and Affected Versions** XWiki Platform versions prior to 18.1.0-rc-1 XWiki Platform versions prior to 17.10.3 XWiki Platform versions prior to 17.4.9 XWiki Platform versions prior to 16.10.17 **Description** Path Traversal allows unauthorized access to read configuration files. This occurs via the `resource` parameter in the 'ssx' and 'jsx' endpoints by using leading slashes, enabling an attacker to access sensitive files such as `xwiki.cfg`. **Recommendations** Update to version 18.1.0-rc-1. Update to version 17.10.3. Update to version 17.4.9. Update to version 16.10.17.
PT-2025-8690
5.4
2025-02-26
Acquia · Mautic · CVE-2022-25773
**Name of the Vulnerable Software and Affected Versions** The product name cannot be determined. **Description** A file placement issue exists, allowing assets to be uploaded to unintended server directories. This is due to improper limitation of a pathname to a restricted directory, specifically in the asset upload functionality. This enables users to upload files outside of the intended temporary directory. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.