CVE-2025-69106 — File: Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. CVSSv3.1 8.1 (HIGH)
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account. CVSSv3.1 8.8 (HIGH)
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. CVSSv3.1 9.8 (CRITICAL)
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. CVSSv3.1 9.8 (CRITICAL)
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. CVSSv3.1 9.8 (CRITICAL)
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. CVSSv3.1 9.3 (CRITICAL)
BloodHound CE v9.3.0 released with 60+ commits including bug fixes for two CVEs (CVE-2026-46625, CVE-2026-44705), dependency updates (Go 1.26.4, axios, DAWGS 0.5.5), new features (alerts system, privilege zone metrics, findings endpoint enhancements), and accessibility improvements. Notable changes include ADCS post-processing optimizations, embedded extensions preparation, and JIT Teleport configuration support.
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. CVSSv3.1 9.8 (CRITICAL)
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. CVSSv3.1 8.8 (HIGH)
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. CVSSv3.1 9.8 (CRITICAL)
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. CVSSv3.1 9.3 (CRITICAL)
Subscriber SQL Injection in Cornerstone < 7.8.8 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. CVSSv3.1 9.0 (CRITICAL)
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later. CVSSv3.1 9.1 (CRITICAL)
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. CVSSv3.1 9.8 (CRITICAL)
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. CVSSv3.1 9.3 (CRITICAL)