Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ali Khafagy

#23624of 56,330
10.1Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-89679
4.2
2026-09-11
Flextype · Flextype · CVE-2026-89145
Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.
PT-2026-89456
5.9
2026-09-10
Flextype · Flextype · CVE-2026-88897
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.