Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Islomjon Tursunov

#22356of 57,408
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-104460
7.1
2026-10-02
Getformwork · Formwork · CVE-2026-104478
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
PT-2026-104461
5.4
2026-10-02
Mindstellar · Shopclass · CVE-2026-104479
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.