Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Razielx64

#22222of 56,330
12.1Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-78655
5.8
2026-08-19
Git · Pkp-Lib · CVE-2026-76572
**Name of the Vulnerable Software and Affected Versions** pkp pkp-lib versions prior to 3.3.0-23 pkp pkp-lib versions prior to 3.4.0-11 pkp pkp-lib versions prior to 3.5.0-5 **Description** A remote attack is possible through the manipulation of the ` transformPHP()` function within the `classes/xslt/XSLTransformer.php` file. This issue leads to an XML External Entity (XXE) reference, which occurs when an application processes XML input containing a reference to an external entity. **Recommendations** Update to version 3.3.0-23. Update to version 3.4.0-11. Update to version 3.5.0-5. As a temporary mitigation, restrict access to the ` transformPHP()` function.
PT-2026-73047
6.3
2026-08-15
Pkp-Lib · Pkp-Lib · CVE-2026-19906
**Name of the Vulnerable Software and Affected Versions** pkp pkp-lib versions 3.3.0 through 3.5.0 **Description** A weakness exists in the API Key Generation component within the `setData()` function of the `classes/user/form/APIProfileForm.php` file. A remote attacker can manipulate the `apiKey` argument to cause insufficient entropy, which refers to a lack of randomness in the generated keys, potentially making them predictable. This attack is characterized by high complexity and is difficult to exploit. **Recommendations** Apply patch 529b5df878e571ccc727647f7748eafc1466b041 for versions 3.3.0 through 3.5.0.