Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Liu Tingwei

#23467of 56,330
10.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-87076
4.0
2026-09-08
Star7Th · Showdoc · CVE-2026-86644
A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is able to resolve this issue. This patch is called a8ea1520850b4242f395247f72e87e597506cef0. Upgrading the affected component is recommended. The vendor confirms: "The fix [...] sets Mermaid `securityLevel` to `strict`, disables `htmlLabels`, and sanitizes rendered SVG with DOMPurify."
PT-2026-35153
6.5
2026-04-25
Star7Th · Showdoc · CVE-2026-6982
**Name of the Vulnerable Software and Affected Versions** star7th ShowDoc versions prior to 3.8.1 **Description** An issue exists in the API Page Sort Endpoint within the file `server/Application/Api/Controller/PageController.class.PHP`. A remote attacker can perform SQL injection—a technique where malicious SQL statements are inserted into entry fields for execution—by manipulating the `pages` argument. **Recommendations** Upgrade to version 3.8.1.