CVE-2026-54000 to CVE-2026-54999
129 CVEs with public proof-of-concept exploits.
- CVE-2026-540071 PoCOpen WebUI: Cross-origin postMessage confirmation bypass via action:submit
- CVE-2026-540081 PoCOpen WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url`
- CVE-2026-540091 PoCOpen WebUI: Cross-user file disclosure via /api/chat/completions image_url field
- CVE-2026-540101 PoCOpen WebUI: Forged chat-file link allows cross-user file read and deletion
- CVE-2026-540111 PoCOpen WebUI: Stored XSS in Mermaid Markdown Preview
- CVE-2026-540121 PoCOpen WebUI: Forged model meta.knowledge allows cross-user file read and deletion
- CVE-2026-540141 PoCOpen WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui
- CVE-2026-540151 PoCOpen WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
- CVE-2026-540161 PoCOpen WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
- CVE-2026-540181 PoCOpen WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
- CVE-2026-540191 PoCOpen WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
- CVE-2026-540221 PoCOpen WebUI: Any authenticated user can read other users' private notes via Socket.IO
- CVE-2026-540511 PoCNetwork-AI has an an OS Command Injection issue
- CVE-2026-540591 PoCPillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF…
- CVE-2026-540601 PoCPillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
- CVE-2026-540611 PoCDgraph Alpha group stores can be replaced via unauthenticated external snapshot import
- CVE-2026-540631 PoCExcelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
- CVE-2026-540662 PoCsSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
- CVE-2026-540671 PoCSiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
- CVE-2026-540692 PoCsSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
- CVE-2026-540701 PoCSiYuan: Stored XSS in Bazaar marketplace via package README event handlers
- CVE-2026-540711 PoCBabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
- CVE-2026-540741 PoC@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
- CVE-2026-540881 PoCFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
- CVE-2026-540891 PoCFile Browser: Authentication Bypass via Proxy Auth Header Forgery
- CVE-2026-540901 PoCFile Browser: Command Allowlist Bypass via Shell Metacharacter Injection
- CVE-2026-540911 PoCFile Browser: Incorrect access control in public directory shares via rule path rebasing
- CVE-2026-540921 PoCFile Browser: DoS Vulnerability on Public Login API
- CVE-2026-540931 PoCFile Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
- CVE-2026-540941 PoCFile Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
- CVE-2026-540961 PoCFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
- CVE-2026-541071 PoCWindows Win32k Elevation of Privilege Vulnerability
- CVE-2026-5412110 PoCsActive Directory Certificate Services Elevation of Privilege Vulnerability
- CVE-2026-541572 PoCsLobeHub: Unauthenticated SSRF in `/webapi/proxy`
- CVE-2026-541581 PoCSiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
- CVE-2026-541631 PoCsecure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
- CVE-2026-541931 PoCWordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerability
- CVE-2026-541941 PoCWordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerability
- CVE-2026-542361 PoCvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
- CVE-2026-542721 PoCip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
- CVE-2026-542841 PoCsqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
- CVE-2026-542981 PoCAstro: XSS via Unescaped Attribute Names in Spread Props
- CVE-2026-543001 PoC@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
- CVE-2026-543471 PoCFroxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover
- CVE-2026-543481 PoCFroxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration
- CVE-2026-543502 PoCsBudibase: Anonymous NoSQL operator injection via published-app query templates
- CVE-2026-543511 PoCBudibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
- CVE-2026-543521 PoCBudibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
- CVE-2026-543531 PoCBudibase: Potential SSRF DNS rebinding bypass in outbound fetch validation
- CVE-2026-543561 PoCBudibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
- CVE-2026-544151 PoCBroken Access Control in Azuriom CMS Server Routes Allows Account Takeover
- CVE-2026-544202 PoCsKEVLiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with…
- CVE-2026-544241 PoCAn Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue…
- CVE-2026-544331 PoCIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email…
- CVE-2026-544491 PoCLangBot: Authenticated RCE Via MCP Configuration
- CVE-2026-544581 PoCAVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
- CVE-2026-544771 PoCGardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
- CVE-2026-544811 PoCInternal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
- CVE-2026-544911 PoCKoel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
- CVE-2026-544921 PoCKoel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation
- CVE-2026-544931 PoCKoel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
- CVE-2026-544941 PoCKoel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16)…
- CVE-2026-544971 PoCview_component: Reused Component Instances Retain Stale Render Context
- CVE-2026-544981 PoCview_component: around_render HTML-Safety Bypass
- CVE-2026-544991 PoCStanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- CVE-2026-545021 PoCOj: Stack Buffer Overflow in Oj.dump via Large Indent
- CVE-2026-545111 PoC@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
- CVE-2026-545121 PoCjackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation
- CVE-2026-545221 PoCMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
- CVE-2026-545231 PoCKyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any…
- CVE-2026-545261 PoCArgo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing
- CVE-2026-545272 PoCsJupyterLab Git: Stored XSS leading to RCE
- CVE-2026-545281 PoCjupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
- CVE-2026-545401 PoCAuthenticated terminal command whitelist bypass in Pheditor
- CVE-2026-545571 PoCmise HTTP backend uses raw version path for install symlink destination
- CVE-2026-545601 PoCCloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
- CVE-2026-545621 PoCCloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
- CVE-2026-545691 PoCSENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in…
- CVE-2026-545701 PoCAngleSharp: HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
- CVE-2026-545721 PoCrclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
- CVE-2026-545741 PoC`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
- CVE-2026-545901 PoCAsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
- CVE-2026-545911 PoCAsyncSSH: SCP Path Traversal to Arbitrary File Write
- CVE-2026-545921 PoCOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
- CVE-2026-545931 PoCPterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
- CVE-2026-546031 PoCOAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
- CVE-2026-546051 PoCOAuth: Cross-origin token-request redirects can expose signed request metadata
- CVE-2026-546061 PoCSunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element After Iframe Embed
- CVE-2026-546351 PoCpytonapi has a Webhook Custom Path Authentication Bypass
- CVE-2026-546591 PoCPagy I18n locale option is not validated before being used in a file path
- CVE-2026-546601 PoCswagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
- CVE-2026-546611 PoCswagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
- CVE-2026-546621 PoCswagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
- CVE-2026-546631 PoCswagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
- CVE-2026-546641 PoCswagger-typescript-api vulnerable to code injection via unescaped enum string values
- CVE-2026-546661 PoCswagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
- CVE-2026-546731 PoCelectron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
- CVE-2026-546801 PoCLogging operator has Fluentd configuration injection that allows remote code execution
- CVE-2026-546851 PoCFileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
- CVE-2026-546861 PoCWarp: DCS lifecycle hook spoofing can alter terminal session metadata
- CVE-2026-546951 PoCPipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
- CVE-2026-546961 PoCRuby JSON: JSON generator heap buffer overflow when streaming to an IO
- CVE-2026-547051 PoCmathlive's Lack of Escaping of HTML allows for XSS
- CVE-2026-547061 PoCOnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
- CVE-2026-547071 PoCOnionShare Receive mode writes uploaded files even when file uploads are disabled
- CVE-2026-547221 PoCdssrf: there a critical security bug with remove_at_symbol_in_string
- CVE-2026-547251 PoCvault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide…
- CVE-2026-547291 PoCdssrf: any users using 1.1.1.1 DNS is impacted by SSRF
- CVE-2026-547541 PoCKlever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
- CVE-2026-547571 PoCTrestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
- CVE-2026-547601 PoCLangroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
- CVE-2026-547612 PoCsTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
- CVE-2026-547621 PoCTraefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
- CVE-2026-547641 PoCForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
- CVE-2026-547651 PoCTraefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
- CVE-2026-547661 PoCVikunja: Project duplication bypasses write-permission check on the target parent project
- CVE-2026-547681 PoCWPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit…
- CVE-2026-547691 PoCLangroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
- CVE-2026-547711 PoCLangroid: handle_message() executes user-supplied tool JSON without sender verification
- CVE-2026-547871 PoCsigstore-go fails to check signature timestamps against a signing key's validity period
- CVE-2026-548061 PoCWordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability
- CVE-2026-548071 PoCWordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability
- CVE-2026-548361 PoCWordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
- CVE-2026-549001 PoCOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
- CVE-2026-549101 PoCFileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
- CVE-2026-549173 PoCsSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
- CVE-2026-549841 PoCWindows Imaging Component Remote Code Execution Vulnerability
- CVE-2026-549921 PoCMicrosoft Message Queuing Queue Manager Remote Code Execution Vulnerability
- CVE-2026-549981 PoCMicrosoft Exchange Online Elevation of Privilege Vulnerability