Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

William Bastos

#20417of 55,077
13.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-45265
7.1
2026-06-01
Unknown · Otrs Community Edition · CVE-2026-48209
**Name of the Vulnerable Software and Affected Versions** OTRS Community Edition versions 6.x and earlier OTRS Community Edition versions 7.0.x **Description** Improper neutralization of user-controllable input in ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS), which is a technique where malicious scripts are injected into a trusted website and reflected back to the user. By injecting malicious JavaScript into manipulated request URLs via crafted request parameters associated with ticket actions, attackers can execute arbitrary script code within the context of an authenticated agent session when the crafted link is opened. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-32366
6.1
2024-06-27
WordPress · Contact Form 7 · CVE-2024-4704
**Name of the Vulnerable Software and Affected Versions** Contact Form 7 versions prior to 5.9.5 **Description** The issue allows an attacker to utilize a false URL and redirect to the URL of their choosing, due to an open redirect in the plugin. **Recommendations** For versions prior to 5.9.5, update to version 5.9.5 or later to resolve the issue.