Anwendungssicherheit

🔴 CVE-2026-45312: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-45312: Critical Schwachstelle

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator...

31. Mai 2026 Keine Kommentare
🔴 CVE-2026-9559: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-9559: Critical Schwachstelle

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign...

31. Mai 2026 Keine Kommentare
🔴 CVE-2026-9558: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-9558: Critical Schwachstelle

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox...

31. Mai 2026 Keine Kommentare
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit ANWENDUNGSSICHERHEIT

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining...

30. Mai 2026 Keine Kommentare
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface ANWENDUNGSSICHERHEIT

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust...

30. Mai 2026 Keine Kommentare
🟡 CVE-2026-6937: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-6937: Medium Schwachstelle

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all...

30. Mai 2026 Keine Kommentare
🟡 CVE-2026-7660: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-7660: Medium Schwachstelle

The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up...

30. Mai 2026 Keine Kommentare
🟡 CVE-2026-4334: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-4334: Medium Schwachstelle

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode...

30. Mai 2026 Keine Kommentare
🟡 CVE-2026-9644: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-9644: Medium Schwachstelle

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget'...

30. Mai 2026 Keine Kommentare
🟡 CVE-2026-7048: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-7048: Medium Schwachstelle

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via...

30. Mai 2026 Keine Kommentare