Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

William Bastos

#19791of 53,635
13.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-45265
7.1
2026-06-01
Unknown · Otrs Community Edition · CVE-2026-48209
**Name of the Vulnerable Software and Affected Versions** OTRS Community Edition versions 6.x and earlier OTRS Community Edition versions 7.0.x **Description** Improper neutralization of user-controllable input in ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS), which is a technique where malicious scripts are injected into a trusted website and reflected back to the user. By injecting malicious JavaScript into manipulated request URLs via crafted request parameters associated with ticket actions, attackers can execute arbitrary script code within the context of an authenticated agent session when the crafted link is opened. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-32366
6.1
2024-06-27
WordPress · Contact Form 7 · CVE-2024-4704
**Name of the Vulnerable Software and Affected Versions** Contact Form 7 versions prior to 5.9.5 **Description** The issue allows an attacker to utilize a false URL and redirect to the URL of their choosing, due to an open redirect in the plugin. **Recommendations** For versions prior to 5.9.5, update to version 5.9.5 or later to resolve the issue.