Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Buggs777

#22329of 57,454
12.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-104575
6.1
2026-10-03
Forgerock · Openam · CVE-2026-105114
**Name of the Vulnerable Software and Affected Versions** OpenAM versions prior to 16.1.3 **Description** An issue exists where unauthenticated attackers can perform reflected cross-site scripting (XSS) by providing crafted parameters that are rendered without proper encoding on the OAuth2 authorization error page. By luring victims to a malicious `/oauth2/authorize` endpoint, attackers can execute JavaScript within the OpenAM origin to operate within existing sessions or redirect users to phishing pages. **Recommendations** Update to version 16.1.3 or later.
PT-2026-103820
6.5
2026-10-01
Ghost · Ghost · CVE-2026-103288
**Name of the Vulnerable Software and Affected Versions** Ghost versions 5.9.0 through 6.44.0 **Description** An input validation flaw exists in the comment like feature. This allows an authenticated member to delete comment likes or dislikes belonging to other users without proper authorization, leading to an authorization bypass and unauthorized modification of comment engagement data. **Recommendations** Update Ghost to version 6.44.1 or later.