Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Santiago Alvarez

#21725of 56,337
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-68256
7.5
2026-08-05
Postgresql Global Development Group · Postgresql · CVE-2026-10716
**Name of the Vulnerable Software and Affected Versions** Directus versions prior to 12.1.0 **Description** An authenticated SQL injection exists in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can exploit this by creating a collection with a geometry field where the `fields[].type` value begins with geometry but includes malicious SQL syntax following the geometry subtype. **Recommendations** Update to version 12.1.0 or later.
PT-2026-50696
5.1
2026-06-18
Grav · Admin2 · CVE-2026-11982
**Name of the Vulnerable Software and Affected Versions** Grav version 2.0.0-rc.9 with Admin2 version 2.0.0-rc.14 **Description** A stored cross-site scripting (XSS) issue exists in the Admin2 Pages API save flow due to a missing XSS safety check during partial validation. Stored XSS occurs when an application receives data from a user and includes that data within its later HTTP responses in an unsafe way, allowing an attacker to store malicious scripts on the server. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.