Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hhhha

#29756of 56,330
9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-90729
4.0
2026-09-12
Xuxueli · Xxl-Job · CVE-2026-90489
A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
PT-2025-37776
5.0
2025-09-15
Unknown · Pojoin H3Blog · CVE-2025-10485
**Name of the Vulnerable Software and Affected Versions** pojoin h3blog versions prior to 5bf704425ebc11f4c24da51f32f36bb17ae20489 **Description** A vulnerability exists in pojoin h3blog due to cross-site scripting. Manipulation of the `X-Forwarded-For` argument within the `ppt log` function in the `/login` file of the HTTP Header Handler component can trigger this issue. The attack can be performed remotely. The exploit has been publicly disclosed. **Recommendations** Update to a version prior to 5bf704425ebc11f4c24da51f32f36bb17ae20489. As a temporary workaround, consider restricting or disabling the use of the `X-Forwarded-For` header.