Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Leon Bytyci

#20125of 56,330
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-90003
6.1
2026-09-11
Chamilo · Chamilo Lms · CVE-2026-82535
Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey submission endpoint. Attackers can submit crafted answers containing unescaped HTML rendered in reporting views to execute arbitrary scripts in the browser sessions of teachers or administrators, enabling persistent backdoor account creation by exploiting the victim's authenticated session.
PT-2026-83848
8.1
2026-08-31
WordPress · Profilepress · CVE-2026-66047
**Name of the Vulnerable Software and Affected Versions** ProfilePress versions prior to 4.17.2 **Description** An unauthenticated remote code execution issue exists in the ProfilePress WordPress plugin. Unauthenticated attackers can install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the `ppress connect process` AJAX handler. By providing a caller-controlled URL through the `file request` parameter, an attacker can trigger a silent plugin installation and activation, resulting in PHP code execution with the privileges of the web-server user. **Recommendations** Update ProfilePress to version 4.17.2 or later.