Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Moworn

#48401of 55,135
5.4Total CVSS
Vulnerabilities · 1
PT-2026-44039
5.4
2026-05-27
Undefined · Undefined · CVE-2026-38931
**Name of the Vulnerable Software and Affected Versions** creatorsofcode simplephp versions prior to GitHub commit 5184cff **Description** A stored cross-site scripting (XSS) issue exists in the '/admin/config-module.php' endpoint. This occurs when a crafted payload is injected, allowing the execution of malicious scripts in the context of the user's session. **Recommendations** Update to GitHub commit 5184cff or a newer version. As a temporary mitigation, restrict access to the '/admin/config-module.php' endpoint.