Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lzy200657

#19202of 56,330
15Total CVSS
Vulnerabilities · 2
High
2
PT-2026-57533
7.5
2026-07-12
Unknown · Shiroiadmin · CVE-2026-15488
**Name of the Vulnerable Software and Affected Versions** shiroiAdmin versions 1.1 through 1.3 **Description** An unrestricted file upload issue exists in the `FileController::upload()` function within the `app/common/controller/FileController.php` file. A remote attacker can exploit this by manipulating the `File` argument to upload arbitrary files to the system. **Recommendations** Upgrade to version 1.4. As a temporary mitigation, restrict access to the `FileController::upload()` function.
PT-2026-57534
7.5
2026-07-12
Rafymrx · Toko-Online-Roti · CVE-2026-15489
**Name of the Vulnerable Software and Affected Versions** RafyMrX TOKO-ONLINE-ROTI versions up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99 **Description** An issue exists in the `proses/login.php` file where manipulation of the `Username` argument allows for SQL injection, a technique used to interfere with the queries that an application makes to its database. This flaw enables remote exploitation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.