Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

R3Zk0N

#15042of 55,140
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-30495
9.8
2026-04-05
Wisdom · Pegasus Cms · CVE-2019-25687
**Name of the Vulnerable Software and Affected Versions** Pegasus CMS version 1.0 **Description** An issue in the extra fields.php plugin allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality, which is a function that evaluates a string as PHP code. Attackers can send POST requests to the 'submit.php' endpoint containing malicious PHP code within the `action` parameter to achieve code execution and obtain an interactive shell. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the extra fields.php plugin or avoid using the `action` parameter in the 'submit.php' endpoint as a temporary mitigation measure.
PT-2023-16962
8.8
2023-04-10
WordPress · Jetengine · CVE-2023-1406
**Name of the Vulnerable Software and Affected Versions** JetEngine WordPress plugin versions prior to 3.1.3.1 **Description** The issue allows for remote code execution due to the plugin's failure to properly verify that uploaded files are not executable. **Recommendations** For versions prior to 3.1.3.1, update to version 3.1.3.1 or later to resolve the issue.