Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Daniel Celis

#15143of 56,330
18.9Total CVSS
Vulnerabilities · 3
Medium
2
High
1
PT-2026-58059
6.5
2026-07-14
Os4Ed · Opensis Classic · CVE-2026-11944
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
PT-2026-48668
7.1
2026-06-11
Unknown · Opensis Classic · CVE-2026-8406
**Name of the Vulnerable Software and Affected Versions** openSIS Classic version 9.3 **Description** An insecure direct object reference in the messaging module allows authenticated users with access to that module to request sent-message details. This is achieved by supplying an arbitrary `mail id` value to the 'modules/messaging/SentMail.php' endpoint. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-4914
5.3
2026-01-27
Askbot · Askbot · CVE-2026-1213
**Name of the Vulnerable Software and Affected Versions** askbot versions prior to 0.12.2 **Description** An authenticated attacker with normal user permissions can modify the profile picture of other application users. **Recommendations** Update to a version later than 0.12.2.