Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lvshenlyl

#23581of 57,632
11.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-107990
4.3
2026-10-08
Espocrm · Espocrm · CVE-2026-105831
EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.
PT-2026-103802
6.9
2026-10-01
Ghost · Ghost · CVE-2026-103269
**Name of the Vulnerable Software and Affected Versions** Ghost versions 5.3.0 through 6.61.0 **Description** An authorization flaw allows an authenticated site member to read excerpts of posts they are not permitted to access, specifically affecting gated content. **Recommendations** Update Ghost to version 6.62.0 or later.