<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Newest Web App Scanning Plugins from Tenable</title>
        <link>https://www.tenable.com/plugins/feeds?sort=newest&amp;type=was</link>
        <description>Get the latest plugin updates from Tenable</description>
        <lastBuildDate>Sat, 05 Sep 2026 10:35:47 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>Tenable Plugins</generator>
        <image>
            <title>Newest Web App Scanning Plugins from Tenable</title>
            <url>https://www.tenable.com/themes/custom/tenable/img/favicons/apple-touch-icon.png</url>
            <link>https://www.tenable.com/plugins/feeds?sort=newest&amp;type=was</link>
        </image>
        <copyright>Copyright 2026 Tenable, Inc. All rights reserved.</copyright>
        <atom:link href="https://www.tenable.com/plugins/feeds?sort=newest&amp;type=was" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[Joomla! 6.x < 6.1.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115460</link>
            <guid>https://www.tenable.com/plugins/was/115460</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115460 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 6.x < 6.1.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Joomla! installed on the remote host is prior to 5.4.8 / 6.1.3. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - Lack of output processing allows a response header injection in the multiple download views, leading to reflected file download / content-type confusion. (CVE-2026-71572)<br /></span><span><br /></span><span> - An improper implementation prevents configured CORS origins from being properly validated in CORS requests. (CVE-2026-71573)<br /></span><span><br /></span><span> - Improper access validation permits unauthorized users to execute mutation operations through webservice endpoints. (CVE-2026-71574)<br /></span><span><br /></span><span> - An improper access check allows unauthorized users to create fields for inaccessible components via the custom fields webservice endpoints. (CVE-2026-72531)<br /></span><span><br /></span><span> - An improper access check allows unauthorized users to create categories for inaccessible components via the category webservice endpoints. (CVE-2026-72532)<br /></span><span><br /></span><span> - Improper escaping flags create a cross-site scripting (XSS) vulnerability through schema.org outputs. (CVE-2026-73336)<br /></span><span><br /></span><span> - Insufficient state checks lead to a vector that allows bypassing multi-factor authentication (MFA) checks. (CVE-2026-73337)<br /></span><span><br /></span><span> - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. (CVE-2026-73371)<br /></span><span><br /></span><span> - An improper access check injects contact information for inaccessible contact items into schema.org snippets. (CVE-2026-73372)<br /></span><span><br /></span><span> - The default list of dangerous file types does not include SHTML files, potentially allowing unrestricted uploads that could execute as code on servers configured to process them. (CVE-2026-73373)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! version 6.1.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115460">https://www.tenable.com/plugins/was/115460</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 5.x < 5.4.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115459</link>
            <guid>https://www.tenable.com/plugins/was/115459</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115459 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 5.x < 5.4.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Joomla! installed on the remote host is prior to 5.4.8 / 6.1.3. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - Lack of output processing allows a response header injection in the multiple download views, leading to reflected file download / content-type confusion. (CVE-2026-71572)<br /></span><span><br /></span><span> - An improper implementation prevents configured CORS origins from being properly validated in CORS requests. (CVE-2026-71573)<br /></span><span><br /></span><span> - Improper access validation permits unauthorized users to execute mutation operations through webservice endpoints. (CVE-2026-71574)<br /></span><span><br /></span><span> - An improper access check allows unauthorized users to create fields for inaccessible components via the custom fields webservice endpoints. (CVE-2026-72531)<br /></span><span><br /></span><span> - An improper access check allows unauthorized users to create categories for inaccessible components via the category webservice endpoints. (CVE-2026-72532)<br /></span><span><br /></span><span> - Improper escaping flags create a cross-site scripting (XSS) vulnerability through schema.org outputs. (CVE-2026-73336)<br /></span><span><br /></span><span> - Insufficient state checks lead to a vector that allows bypassing multi-factor authentication (MFA) checks. (CVE-2026-73337)<br /></span><span><br /></span><span> - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. (CVE-2026-73371)<br /></span><span><br /></span><span> - An improper access check injects contact information for inaccessible contact items into schema.org snippets. (CVE-2026-73372)<br /></span><span><br /></span><span> - The default list of dangerous file types does not include SHTML files, potentially allowing unrestricted uploads that could execute as code on servers configured to process them. (CVE-2026-73373)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! version 5.4.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115459">https://www.tenable.com/plugins/was/115459</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WPMU DEV Dashboard Plugin for WordPress < 5.0.2 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115458</link>
            <guid>https://www.tenable.com/plugins/was/115458</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115458 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>WPMU DEV Dashboard Plugin for WordPress < 5.0.2 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>The WordPress WPMU DEV Dashboard Plugin installed on the remote host is affected by an Authentication Bypass through SSO HMAC Canonicalization Confusion.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WPMU DEV Dashboard Plugin for WordPress version 5.0.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115458">https://www.tenable.com/plugins/was/115458</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[TranslatePress Plugin for WordPress < 3.3.2 Unauthenticated Account Takeover]]></title>
            <link>https://www.tenable.com/plugins/was/115457</link>
            <guid>https://www.tenable.com/plugins/was/115457</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115457 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>TranslatePress Plugin for WordPress < 3.3.2 Unauthenticated Account Takeover<br /></span>
      <h3>Description</h3>
      <span>The WordPress TranslatePress Plugin installed on the remote host is affected by an Unauthenticated Account Takeover through the password reset link disclosure.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to TranslatePress Plugin for WordPress version 3.3.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115457">https://www.tenable.com/plugins/was/115457</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Gitea < 1.27.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115456</link>
            <guid>https://www.tenable.com/plugins/was/115456</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115456 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Gitea < 1.27.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Gitea running on the remote host is prior to 1.27.1. It is, therefore, affected by a Remote Code Execution through diffpatch Git Hook Installation. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Gitea version 1.27.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115456">https://www.tenable.com/plugins/was/115456</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Avada Website Builder Theme for WordPress < 7.16.1 Unauthenticated Arbitrary File Write]]></title>
            <link>https://www.tenable.com/plugins/was/115455</link>
            <guid>https://www.tenable.com/plugins/was/115455</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115455 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Avada Website Builder Theme for WordPress < 7.16.1 Unauthenticated Arbitrary File Write<br /></span>
      <h3>Description</h3>
      <span>The WordPress Avada Website Builder Theme installed on the remote host is affected by an Unauthenticated Arbitrary File Write due to a chain of authorization and input validation weaknesses.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Avada Website Builder Theme for WordPress version 7.16.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115455">https://www.tenable.com/plugins/was/115455</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Avada Fusion Builder Plugin for WordPress < 3.16.1 Unauthenticated Arbitrary File Write]]></title>
            <link>https://www.tenable.com/plugins/was/115454</link>
            <guid>https://www.tenable.com/plugins/was/115454</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115454 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Avada Fusion Builder Plugin for WordPress < 3.16.1 Unauthenticated Arbitrary File Write<br /></span>
      <h3>Description</h3>
      <span>The WordPress Avada Fusion Builder Plugin installed on the remote host is affected by an Unauthenticated Arbitrary File Write due to a chain of authorization and input validation weaknesses.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Avada Fusion Builder Plugin for WordPress version 3.16.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115454">https://www.tenable.com/plugins/was/115454</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SPIP CMS 4.4.20 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115453</link>
            <guid>https://www.tenable.com/plugins/was/115453</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115453 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>SPIP CMS 4.4.20 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>The SPIP CMS versions 4.4.20 allows unauthenticated remote attackers to execute arbitrary code due to a code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to SPIP CMS 4.4.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115453">https://www.tenable.com/plugins/was/115453</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SPIP CMS < 4.4.20 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115452</link>
            <guid>https://www.tenable.com/plugins/was/115452</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115452 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>SPIP CMS < 4.4.20 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>The SPIP CMS versions 4.4.20 allows unauthenticated remote attackers to execute arbitrary code due to an to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to SPIP CMS 4.4.20 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115452">https://www.tenable.com/plugins/was/115452</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Pods Plugin for WordPress < 2.8.23.4 Unauthenticated Privilege Escalation]]></title>
            <link>https://www.tenable.com/plugins/was/115451</link>
            <guid>https://www.tenable.com/plugins/was/115451</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115451 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Pods Plugin for WordPress < 2.8.23.4 Unauthenticated Privilege Escalation<br /></span>
      <h3>Description</h3>
      <span>The WordPress Pods Plugin installed on the remote host is affected by an unauthenticated privilege escalation via an authorization bypass to admin methods via 'pods_admin' AJAX Router<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Pods Plugin for WordPress 2.8.23.4 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115451">https://www.tenable.com/plugins/was/115451</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Pods Plugin for WordPress < 2.9.19.4 Unauthenticated Privilege Escalation]]></title>
            <link>https://www.tenable.com/plugins/was/115450</link>
            <guid>https://www.tenable.com/plugins/was/115450</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115450 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Pods Plugin for WordPress < 2.9.19.4 Unauthenticated Privilege Escalation<br /></span>
      <h3>Description</h3>
      <span>The WordPress Pods Plugin installed on the remote host is affected by an unauthenticated privilege escalation via an authorization bypass to admin methods via 'pods_admin' AJAX Router<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Pods Plugin for WordPress 2.9.19.4 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115450">https://www.tenable.com/plugins/was/115450</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Pods Plugin for WordPress < 3.0.10.4 Unauthenticated Privilege Escalation]]></title>
            <link>https://www.tenable.com/plugins/was/115449</link>
            <guid>https://www.tenable.com/plugins/was/115449</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115449 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Pods Plugin for WordPress < 3.0.10.4 Unauthenticated Privilege Escalation<br /></span>
      <h3>Description</h3>
      <span>The WordPress Pods Plugin installed on the remote host is affected by an unauthenticated privilege escalation via an authorization bypass to admin methods via 'pods_admin' AJAX Router<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Pods Plugin for WordPress 3.0.10.4 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115449">https://www.tenable.com/plugins/was/115449</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Pods Plugin for WordPress < 3.1.4.2 Unauthenticated Privilege Escalation]]></title>
            <link>https://www.tenable.com/plugins/was/115448</link>
            <guid>https://www.tenable.com/plugins/was/115448</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115448 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Pods Plugin for WordPress < 3.1.4.2 Unauthenticated Privilege Escalation<br /></span>
      <h3>Description</h3>
      <span>The WordPress Pods Plugin installed on the remote host is affected by an unauthenticated privilege escalation via an authorization bypass to admin methods via 'pods_admin' AJAX Router<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Pods Plugin for WordPress 3.1.4.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115448">https://www.tenable.com/plugins/was/115448</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Pods Plugin for WordPress < 3.2.8.3 Unauthenticated Privilege Escalation]]></title>
            <link>https://www.tenable.com/plugins/was/115447</link>
            <guid>https://www.tenable.com/plugins/was/115447</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115447 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Pods Plugin for WordPress < 3.2.8.3 Unauthenticated Privilege Escalation<br /></span>
      <h3>Description</h3>
      <span>The WordPress Pods Plugin installed on the remote host is affected by an unauthenticated privilege escalation via an authorization bypass to admin methods via 'pods_admin' AJAX Router<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Pods Plugin for WordPress 3.2.8.3 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115447">https://www.tenable.com/plugins/was/115447</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Pods Plugin for WordPress < 3.3.9.1 Unauthenticated Privilege Escalation]]></title>
            <link>https://www.tenable.com/plugins/was/115446</link>
            <guid>https://www.tenable.com/plugins/was/115446</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115446 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Pods Plugin for WordPress < 3.3.9.1 Unauthenticated Privilege Escalation<br /></span>
      <h3>Description</h3>
      <span>The WordPress Pods Plugin installed on the remote host is affected by an unauthenticated privilege escalation via an authorization bypass to admin methods via 'pods_admin' AJAX Router<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Pods Plugin for WordPress 3.3.9.1 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115446">https://www.tenable.com/plugins/was/115446</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Elementor Pro Plugin for WordPress < 4.2.2 Arbitrary File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115445</link>
            <guid>https://www.tenable.com/plugins/was/115445</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115445 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Elementor Pro Plugin for WordPress < 4.2.2 Arbitrary File Upload<br /></span>
      <h3>Description</h3>
      <span>The WordPress Elementor Pro Plugin installed on the remote host is affected by an authenticated arbitrary file upload vulnerability that could lead to remote code execution.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Elementor Pro Plugin for WordPress 4.2.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115445">https://www.tenable.com/plugins/was/115445</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Zimbra Collaboration < 10.1.20 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115444</link>
            <guid>https://www.tenable.com/plugins/was/115444</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115444 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Zimbra Collaboration < 10.1.20 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Zimbra Collaboration running on the remote host is prior to 10.1.20. It is, therefore, affected by a Remote Code Execution due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Zimbra Collaboration version 10.1.20 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115444">https://www.tenable.com/plugins/was/115444</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft SharePoint Server 2016 < 16.0.5556.1005 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115443</link>
            <guid>https://www.tenable.com/plugins/was/115443</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115443 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Microsoft SharePoint Server 2016 < 16.0.5556.1005 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Microsoft SharePoint application running on the remote host is affected by a remote code execution vulnerability due to the deserialization of untrusted data.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Microsoft SharePoint Server 2016 build 16.0.5556.1005 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115443">https://www.tenable.com/plugins/was/115443</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft SharePoint Server 2019 < 16.0.10417.20153 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115442</link>
            <guid>https://www.tenable.com/plugins/was/115442</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115442 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Microsoft SharePoint Server 2019 < 16.0.10417.20153 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Microsoft SharePoint application running on the remote host is affected by a remote code execution vulnerability due to the deserialization of untrusted data.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Microsoft SharePoint Server 2019 build 16.0.10417.20153 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115442">https://www.tenable.com/plugins/was/115442</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft SharePoint Server 2016 < 16.0.5561.1001 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115441</link>
            <guid>https://www.tenable.com/plugins/was/115441</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115441 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Microsoft SharePoint Server 2016 < 16.0.5561.1001 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Microsoft SharePoint application running on the remote host is affected by multiple vulnerabilities.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Microsoft SharePoint Server 2016 build 16.0.5561.1001 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115441">https://www.tenable.com/plugins/was/115441</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft SharePoint Server 2019 < 16.0.10417.20175 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115440</link>
            <guid>https://www.tenable.com/plugins/was/115440</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115440 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Microsoft SharePoint Server 2019 < 16.0.10417.20175 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Microsoft SharePoint application running on the remote host is affected by multiple vulnerabilities.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Microsoft SharePoint Server 2019 build 16.0.10417.20175 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115440">https://www.tenable.com/plugins/was/115440</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GitLab 18.2 < 18.11.11 / 19.0 < 19.0.8 / 19.1 < 19.1.6 / 19.2 < 19.2.4 GraphQL Arbitrary Method Invocation]]></title>
            <link>https://www.tenable.com/plugins/was/115439</link>
            <guid>https://www.tenable.com/plugins/was/115439</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115439 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>GitLab 18.2 < 18.11.11 / 19.0 < 19.0.8 / 19.1 < 19.1.6 / 19.2 < 19.2.4 GraphQL Arbitrary Method Invocation<br /></span>
      <h3>Description</h3>
      <span>GitLab CE/EE versions starting from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 is affected by an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to GitLab version 18.11.11, 19.0.8, 19.1.6, 19.2.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115439">https://www.tenable.com/plugins/was/115439</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ray < 2.56.0 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115438</link>
            <guid>https://www.tenable.com/plugins/was/115438</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115438 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Ray < 2.56.0 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Ray is prior to 2.56.0. Therefore, it may be affected by a Remote Code Execution due to the unsafe deserialization performed by the default decoder of ray.data.read_webdataset(), which calls pickle.loads() on .pickle / .pkl members and torch.load() with weights_only=False on .pt / .pth members of an attacker-supplied WebDataset TAR file.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ray version 2.56.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115438">https://www.tenable.com/plugins/was/115438</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ray < 2.8.1 Local File Inclusion]]></title>
            <link>https://www.tenable.com/plugins/was/115437</link>
            <guid>https://www.tenable.com/plugins/was/115437</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115437 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Ray < 2.8.1 Local File Inclusion<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Ray is prior to 2.8.1. Therefore, it may be affected by a Local File Inclusion in the /static/ directory of the Ray Dashboard, which allows an unauthenticated attacker to read arbitrary files on the server.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ray version 2.8.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115437">https://www.tenable.com/plugins/was/115437</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ray < 2.52.0 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115436</link>
            <guid>https://www.tenable.com/plugins/was/115436</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115436 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Ray < 2.52.0 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Ray is prior to 2.52.0. Therefore, it may be affected by a Remote Code Execution through a DNS Rebinding Attack.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ray version 2.52.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115436">https://www.tenable.com/plugins/was/115436</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Forminator Forms Plugin for WordPress < 1.56.2 Unauthenticated Arbitrary File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115435</link>
            <guid>https://www.tenable.com/plugins/was/115435</guid>
            <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115435 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Forminator Forms Plugin for WordPress < 1.56.2 Unauthenticated Arbitrary File Upload<br /></span>
      <h3>Description</h3>
      <span>The WordPress Forminator Forms Plugin installed on the remote host is affected by an Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Forminator Forms for WordPress version 1.56.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115435">https://www.tenable.com/plugins/was/115435</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MLflow < 3.15.0 Server-Side Request Forgery]]></title>
            <link>https://www.tenable.com/plugins/was/115434</link>
            <guid>https://www.tenable.com/plugins/was/115434</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115434 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>MLflow < 3.15.0 Server-Side Request Forgery<br /></span>
      <h3>Description</h3>
      <span>According to the self-reported version in its response header, the version of LobeChat hosted on the remote web server is prior to 3.15.0. It is, therefore, affected by an unauthenticated full-read Server-Side Request Forgery in webhook delivery.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MLflow version 3.15.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115434">https://www.tenable.com/plugins/was/115434</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[REDCap < 14.9.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115433</link>
            <guid>https://www.tenable.com/plugins/was/115433</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115433 with High Severity</p>
      <h3>Synopsis</h3>
      <span>REDCap < 14.9.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of REDCap running on the remote host is prior to 14.9.6. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An HTML injection issue in the Project Dashboard name, allowing an attacker to trigger a logout request through a crafted link, terminating the session of any user clicking on the dashboard name, or to redirect them to a phishing website. (CVE-2024-56310)<br /></span><span><br /></span><span>- An HTML injection issue in the Notes section of a calendar event, allowing an attacker to trigger a logout request or to redirect a user to a phishing website. (CVE-2024-56311)<br /></span><span><br /></span><span>- A stored cross-site scripting (XSS) issue in the Project Dashboard name, allowing an authenticated user to inject arbitrary scripts executed when another user opens the dashboard. (CVE-2024-56312)<br /></span><span><br /></span><span>- A stored cross-site scripting (XSS) issue in the Notes field of a calendar event, allowing an authenticated user to inject arbitrary scripts executed when the event is viewed. (CVE-2024-56313)<br /></span><span><br /></span><span>- A stored cross-site scripting (XSS) issue in the Project name, allowing an authenticated user to inject arbitrary scripts executed when another user accesses the project. (CVE-2024-56314)<br /></span><span><br /></span><span>- A stored cross-site scripting (XSS) issue in the message field of the built-in messenger, allowing an authenticated user to inject arbitrary scripts executed when the recipient opens the message. (CVE-2024-56376)<br /></span><span><br /></span><span>- A stored cross-site scripting (XSS) issue in the Survey Title and Survey Instructions fields, allowing an authenticated user to inject arbitrary scripts executed when a respondent opens the survey. (CVE-2024-56377)<br /></span><span><br /></span><span>- A reflected cross-site scripting (XSS) issue in the email subject field, reachable through the upload of a CSV file containing a list of alert configurations. (CVE-2025-23110)<br /></span><span><br /></span><span>- An HTML injection issue via the survey field name, allowing an attacker to redirect a survey respondent to a phishing website. (CVE-2025-23111)<br /></span><span><br /></span><span>- A stored cross-site scripting (XSS) issue via the survey field name, allowing an authenticated user to inject arbitrary scripts executed when a respondent opens the survey. (CVE-2025-23112)<br /></span><span><br /></span><span>- An HTML injection issue via the alert-title field, reachable through the upload of a CSV file containing a list of alert configurations, leading to a cross-site request forgery (CSRF) logout of the victim. (CVE-2025-23113)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to REDCap version 14.9.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115433">https://www.tenable.com/plugins/was/115433</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GeoServer 3.0.0 < 3.0.1 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115432</link>
            <guid>https://www.tenable.com/plugins/was/115432</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115432 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>GeoServer 3.0.0 < 3.0.1 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of GeoServer running on the remote host is 2.27.1 prior to 2.27.6, or 2.28.x prior to 2.28.5, or 3.0.0. It is, therefore, affected by an unauthenticated SQL injection vulnerability in the jsonArrayContains OGC Filter function, provided by the bundled GeoTools PostGIS data store.<br /></span><span><br /></span><span>The jsonArrayContains(<column>, <pointer>, <value>) function writes <value> into the generated SQL without escaping it, allowing an unauthenticated, remote attacker to execute arbitrary SQL expressions in the database. Exploitation requires a PostGIS data store running PostGIS 12 or greater with a String or JSON field. This issue is a regression of CVE-2023-25158 limited to the jsonArrayContains function, and the mitigations documented for that issue, enabling prepared statements and disabling encode functions, are not effective.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to GeoServer version 3.0.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115432">https://www.tenable.com/plugins/was/115432</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GeoServer 2.28.x < 2.28.5 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115431</link>
            <guid>https://www.tenable.com/plugins/was/115431</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115431 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>GeoServer 2.28.x < 2.28.5 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of GeoServer running on the remote host is 2.27.1 prior to 2.27.6, or 2.28.x prior to 2.28.5, or 3.0.0. It is, therefore, affected by an unauthenticated SQL injection vulnerability in the jsonArrayContains OGC Filter function, provided by the bundled GeoTools PostGIS data store.<br /></span><span><br /></span><span>The jsonArrayContains(<column>, <pointer>, <value>) function writes <value> into the generated SQL without escaping it, allowing an unauthenticated, remote attacker to execute arbitrary SQL expressions in the database. Exploitation requires a PostGIS data store running PostGIS 12 or greater with a String or JSON field. This issue is a regression of CVE-2023-25158 limited to the jsonArrayContains function, and the mitigations documented for that issue, enabling prepared statements and disabling encode functions, are not effective.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to GeoServer version 2.28.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115431">https://www.tenable.com/plugins/was/115431</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GeoServer 2.27.1 < 2.27.6 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115430</link>
            <guid>https://www.tenable.com/plugins/was/115430</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115430 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>GeoServer 2.27.1 < 2.27.6 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of GeoServer running on the remote host is 2.27.1 prior to 2.27.6, or 2.28.x prior to 2.28.5, or 3.0.0. It is, therefore, affected by an unauthenticated SQL injection vulnerability in the jsonArrayContains OGC Filter function, provided by the bundled GeoTools PostGIS data store.<br /></span><span><br /></span><span>The jsonArrayContains(<column>, <pointer>, <value>) function writes <value> into the generated SQL without escaping it, allowing an unauthenticated, remote attacker to execute arbitrary SQL expressions in the database. Exploitation requires a PostGIS data store running PostGIS 12 or greater with a String or JSON field. This issue is a regression of CVE-2023-25158 limited to the jsonArrayContains function, and the mitigations documented for that issue, enabling prepared statements and disabling encode functions, are not effective.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to GeoServer version 2.27.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115430">https://www.tenable.com/plugins/was/115430</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.58.x < 1.58.24 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115429</link>
            <guid>https://www.tenable.com/plugins/was/115429</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115429 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.58.x < 1.58.24 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.58.24 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115429">https://www.tenable.com/plugins/was/115429</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.58.x < 0.58.24 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115428</link>
            <guid>https://www.tenable.com/plugins/was/115428</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115428 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.58.x < 0.58.24 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.58.24 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115428">https://www.tenable.com/plugins/was/115428</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.59.x < 1.59.21 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115427</link>
            <guid>https://www.tenable.com/plugins/was/115427</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115427 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.59.x < 1.59.21 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.59.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115427">https://www.tenable.com/plugins/was/115427</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.59.x < 0.59.21 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115426</link>
            <guid>https://www.tenable.com/plugins/was/115426</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115426 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.59.x < 0.59.21 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.59.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115426">https://www.tenable.com/plugins/was/115426</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.60.x < 1.60.17 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115425</link>
            <guid>https://www.tenable.com/plugins/was/115425</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115425 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.60.x < 1.60.17 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.60.17 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115425">https://www.tenable.com/plugins/was/115425</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.60.x < 0.60.17 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115424</link>
            <guid>https://www.tenable.com/plugins/was/115424</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115424 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.60.x < 0.60.17 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.60.17 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115424">https://www.tenable.com/plugins/was/115424</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.61.x < 1.61.11 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115423</link>
            <guid>https://www.tenable.com/plugins/was/115423</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115423 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.61.x < 1.61.11 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.61.11 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115423">https://www.tenable.com/plugins/was/115423</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.61.x < 0.61.11 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115422</link>
            <guid>https://www.tenable.com/plugins/was/115422</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115422 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.61.x < 0.61.11 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.61.11 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115422">https://www.tenable.com/plugins/was/115422</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.62.x < 1.62.9 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115421</link>
            <guid>https://www.tenable.com/plugins/was/115421</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115421 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.62.x < 1.62.9 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.62.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115421">https://www.tenable.com/plugins/was/115421</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.62.x < 0.62.9 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115420</link>
            <guid>https://www.tenable.com/plugins/was/115420</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115420 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.62.x < 0.62.9 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.62.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115420">https://www.tenable.com/plugins/was/115420</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.63.x < 1.63.5 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115419</link>
            <guid>https://www.tenable.com/plugins/was/115419</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115419 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.63.x < 1.63.5 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.63.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115419">https://www.tenable.com/plugins/was/115419</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.63.x < 0.63.5 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115418</link>
            <guid>https://www.tenable.com/plugins/was/115418</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115418 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.63.x < 0.63.5 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is 58.x prior to 58.24, or 59.x prior to 59.21, or 60.x prior to 60.17, or 61.x prior to 61.11, or 62.x prior to 62.9, or 63.x prior to 63.5. It is, therefore, affected by a SQL injection vulnerability.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can inject arbitrary SQL into the Metabase application database through the /api/session/reset_password endpoint, which can grant them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. The vendor has confirmed active exploitation of this vulnerability. (CVE-2026-72898)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.63.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115418">https://www.tenable.com/plugins/was/115418</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise < 1.58.28 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115417</link>
            <guid>https://www.tenable.com/plugins/was/115417</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115417 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise < 1.58.28 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.58.28 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115417">https://www.tenable.com/plugins/was/115417</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase < 0.58.28 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115416</link>
            <guid>https://www.tenable.com/plugins/was/115416</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115416 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase < 0.58.28 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.58.28 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115416">https://www.tenable.com/plugins/was/115416</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.59.x < 1.59.25 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115415</link>
            <guid>https://www.tenable.com/plugins/was/115415</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115415 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.59.x < 1.59.25 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.59.25 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115415">https://www.tenable.com/plugins/was/115415</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.59.x < 0.59.25 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115414</link>
            <guid>https://www.tenable.com/plugins/was/115414</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115414 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.59.x < 0.59.25 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.59.25 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115414">https://www.tenable.com/plugins/was/115414</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.60.x < 1.60.21 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115413</link>
            <guid>https://www.tenable.com/plugins/was/115413</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115413 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.60.x < 1.60.21 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.60.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115413">https://www.tenable.com/plugins/was/115413</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.60.x < 0.60.21 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115412</link>
            <guid>https://www.tenable.com/plugins/was/115412</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115412 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.60.x < 0.60.21 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.60.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115412">https://www.tenable.com/plugins/was/115412</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.61.x < 1.61.15 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115411</link>
            <guid>https://www.tenable.com/plugins/was/115411</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115411 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.61.x < 1.61.15 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.61.15 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115411">https://www.tenable.com/plugins/was/115411</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.61.x < 0.61.15 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115410</link>
            <guid>https://www.tenable.com/plugins/was/115410</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115410 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.61.x < 0.61.15 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.61.15 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115410">https://www.tenable.com/plugins/was/115410</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.62.x < 1.62.13 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115409</link>
            <guid>https://www.tenable.com/plugins/was/115409</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115409 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.62.x < 1.62.13 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.62.13 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115409">https://www.tenable.com/plugins/was/115409</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.62.x < 0.62.13 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115408</link>
            <guid>https://www.tenable.com/plugins/was/115408</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115408 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.62.x < 0.62.13 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.62.13 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115408">https://www.tenable.com/plugins/was/115408</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase Enterprise 1.63.x < 1.63.10 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115407</link>
            <guid>https://www.tenable.com/plugins/was/115407</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115407 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase Enterprise 1.63.x < 1.63.10 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase Enterprise version 1.63.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115407">https://www.tenable.com/plugins/was/115407</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Metabase 0.63.x < 0.63.10 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115406</link>
            <guid>https://www.tenable.com/plugins/was/115406</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115406 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Metabase 0.63.x < 0.63.10 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Metabase running on the remote host is prior to 58.28, or 59.x prior to 59.25, or 60.x prior to 60.21, or 61.x prior to 61.15, or 62.x prior to 62.13, or 63.x prior to 63.10. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Multiple SQL injection issues where a crafted value carried by query parameters and filters, cast options, stored metric and segment definitions, custom column types or schema creation code could reach the database as raw SQL rather than being treated as data.<br /></span><span><br /></span><span>- A vulnerable version of the HoneySQL SQL generation library. (CVE-2026-61620)<br /></span><span><br /></span><span>- Incomplete permission checks on content referenced by cards, dashboards, actions and transforms, allowing a user to indirectly reach data or a database they do not otherwise have access to.<br /></span><span><br /></span><span>- A rate limiting bypass on the login and password reset endpoints by varying a request header, weakening brute-force protection.<br /></span><span><br /></span><span>- A missing permission revalidation when reverting a card or a dashboard to an earlier version, allowing sensitive settings such as an embedding configuration, a public sharing link, a data source or a collection location to be restored.<br /></span><span><br /></span><span>- Multiple data sandboxing and connection impersonation bypasses, including the ability for a non-administrator to edit or delete the questions defining a sandbox and thereby elevate their own permissions.<br /></span><span><br /></span><span>- A loose request body validation on many API endpoints, which acted on unexpected fields.<br /></span><span><br /></span><span>- Multiple network exposure issues, including a legacy HTTP action execution path allowing server-side request forgery to internal addresses, database SSH tunnels not bound to the loopback interface, and an unauthenticated request able to influence the configured site URL.<br /></span><span><br /></span><span>- Multiple missing privilege checks on administrative and settings management operations, including public link publishing for a question, the database health-check endpoint, the Settings Manager scope, and a deactivated administrator regaining admin rights on their next single sign-on login.<br /></span><span><br /></span><span>- A client-side override of the server result row count and download limits.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Metabase version 0.63.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115406">https://www.tenable.com/plugins/was/115406</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 4.7.x < 4.7.35 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115405</link>
            <guid>https://www.tenable.com/plugins/was/115405</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115405 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 4.7.x < 4.7.35 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 4.7.35 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115405">https://www.tenable.com/plugins/was/115405</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 4.8.x < 4.8.30 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115404</link>
            <guid>https://www.tenable.com/plugins/was/115404</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115404 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 4.8.x < 4.8.30 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 4.8.30 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115404">https://www.tenable.com/plugins/was/115404</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 4.9.x < 4.9.31 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115403</link>
            <guid>https://www.tenable.com/plugins/was/115403</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115403 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 4.9.x < 4.9.31 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 4.9.31 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115403">https://www.tenable.com/plugins/was/115403</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.0.x < 5.0.27 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115402</link>
            <guid>https://www.tenable.com/plugins/was/115402</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115402 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.0.x < 5.0.27 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.0.27 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115402">https://www.tenable.com/plugins/was/115402</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.1.x < 5.1.24 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115401</link>
            <guid>https://www.tenable.com/plugins/was/115401</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115401 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.1.x < 5.1.24 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.1.24 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115401">https://www.tenable.com/plugins/was/115401</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.2.x < 5.2.26 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115400</link>
            <guid>https://www.tenable.com/plugins/was/115400</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115400 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.2.x < 5.2.26 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.2.26 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115400">https://www.tenable.com/plugins/was/115400</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.3.x < 5.3.23 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115399</link>
            <guid>https://www.tenable.com/plugins/was/115399</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115399 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.3.x < 5.3.23 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.3.23 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115399">https://www.tenable.com/plugins/was/115399</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.4.x < 5.4.21 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115398</link>
            <guid>https://www.tenable.com/plugins/was/115398</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115398 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.4.x < 5.4.21 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.4.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115398">https://www.tenable.com/plugins/was/115398</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.5.x < 5.5.20 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115397</link>
            <guid>https://www.tenable.com/plugins/was/115397</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115397 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.5.x < 5.5.20 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.5.20 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115397">https://www.tenable.com/plugins/was/115397</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.6.x < 5.6.19 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115396</link>
            <guid>https://www.tenable.com/plugins/was/115396</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115396 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.6.x < 5.6.19 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.6.19 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115396">https://www.tenable.com/plugins/was/115396</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.7.x < 5.7.17 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115395</link>
            <guid>https://www.tenable.com/plugins/was/115395</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115395 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.7.x < 5.7.17 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.7.17 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115395">https://www.tenable.com/plugins/was/115395</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.8.x < 5.8.15 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115394</link>
            <guid>https://www.tenable.com/plugins/was/115394</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115394 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.8.x < 5.8.15 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.8.15 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115394">https://www.tenable.com/plugins/was/115394</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.9.x < 5.9.16 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115393</link>
            <guid>https://www.tenable.com/plugins/was/115393</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115393 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.9.x < 5.9.16 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.9.16 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115393">https://www.tenable.com/plugins/was/115393</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.0.x < 6.0.14 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115392</link>
            <guid>https://www.tenable.com/plugins/was/115392</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115392 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.0.x < 6.0.14 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.0.14 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115392">https://www.tenable.com/plugins/was/115392</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.1.x < 6.1.12 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115391</link>
            <guid>https://www.tenable.com/plugins/was/115391</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115391 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.1.x < 6.1.12 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.1.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115391">https://www.tenable.com/plugins/was/115391</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.2.x < 6.2.11 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115390</link>
            <guid>https://www.tenable.com/plugins/was/115390</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115390 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.2.x < 6.2.11 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.2.11 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115390">https://www.tenable.com/plugins/was/115390</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.3.x < 6.3.10 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115389</link>
            <guid>https://www.tenable.com/plugins/was/115389</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115389 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.3.x < 6.3.10 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.3.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115389">https://www.tenable.com/plugins/was/115389</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.4.x < 6.4.10 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115388</link>
            <guid>https://www.tenable.com/plugins/was/115388</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115388 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.4.x < 6.4.10 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.4.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115388">https://www.tenable.com/plugins/was/115388</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.5.x < 6.5.10 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115387</link>
            <guid>https://www.tenable.com/plugins/was/115387</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115387 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.5.x < 6.5.10 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.5.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115387">https://www.tenable.com/plugins/was/115387</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.6.x < 6.6.7 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115386</link>
            <guid>https://www.tenable.com/plugins/was/115386</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115386 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.6.x < 6.6.7 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.6.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115386">https://www.tenable.com/plugins/was/115386</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.7.x < 6.7.7 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115385</link>
            <guid>https://www.tenable.com/plugins/was/115385</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115385 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.7.x < 6.7.7 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.7.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115385">https://www.tenable.com/plugins/was/115385</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.8.x < 6.8.8 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115384</link>
            <guid>https://www.tenable.com/plugins/was/115384</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115384 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.8.x < 6.8.8 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.8.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115384">https://www.tenable.com/plugins/was/115384</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.9.x < 6.9.7 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115383</link>
            <guid>https://www.tenable.com/plugins/was/115383</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115383 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.9.x < 6.9.7 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.9.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115383">https://www.tenable.com/plugins/was/115383</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 7.0.x < 7.0.4 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115382</link>
            <guid>https://www.tenable.com/plugins/was/115382</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115382 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 7.0.x < 7.0.4 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by a remote code execution vulnerability via a malicious Postscript file upload by an Author level user or higher. Exploitation requires that Imagick and Ghostscript are in use on the server, as the weakness lies in Ghostscript's handling of certain embedded files, and that the attacker has the upload_files capability. (CVE-2026-65640)<br /></span><span><br /></span><span>Note that the scanner has not tested for this issue but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 7.0.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115382">https://www.tenable.com/plugins/was/115382</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 4.7.x < 4.7.34 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115381</link>
            <guid>https://www.tenable.com/plugins/was/115381</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115381 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 4.7.x < 4.7.34 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 4.7.34 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115381">https://www.tenable.com/plugins/was/115381</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 4.8.x < 4.8.29 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115380</link>
            <guid>https://www.tenable.com/plugins/was/115380</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115380 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 4.8.x < 4.8.29 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 4.8.29 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115380">https://www.tenable.com/plugins/was/115380</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 4.9.x < 4.9.30 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115379</link>
            <guid>https://www.tenable.com/plugins/was/115379</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115379 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 4.9.x < 4.9.30 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 4.9.30 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115379">https://www.tenable.com/plugins/was/115379</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.0.x < 5.0.26 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115378</link>
            <guid>https://www.tenable.com/plugins/was/115378</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115378 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.0.x < 5.0.26 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.0.26 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115378">https://www.tenable.com/plugins/was/115378</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.1.x < 5.1.23 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115377</link>
            <guid>https://www.tenable.com/plugins/was/115377</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115377 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.1.x < 5.1.23 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.1.23 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115377">https://www.tenable.com/plugins/was/115377</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.2.x < 5.2.25 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115376</link>
            <guid>https://www.tenable.com/plugins/was/115376</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115376 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.2.x < 5.2.25 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.2.25 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115376">https://www.tenable.com/plugins/was/115376</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.3.x < 5.3.22 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115375</link>
            <guid>https://www.tenable.com/plugins/was/115375</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115375 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.3.x < 5.3.22 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.3.22 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115375">https://www.tenable.com/plugins/was/115375</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.4.x < 5.4.20 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115374</link>
            <guid>https://www.tenable.com/plugins/was/115374</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115374 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.4.x < 5.4.20 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.4.20 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115374">https://www.tenable.com/plugins/was/115374</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.5.x < 5.5.19 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115373</link>
            <guid>https://www.tenable.com/plugins/was/115373</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115373 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.5.x < 5.5.19 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.5.19 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115373">https://www.tenable.com/plugins/was/115373</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.6.x < 5.6.18 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115372</link>
            <guid>https://www.tenable.com/plugins/was/115372</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115372 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.6.x < 5.6.18 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.6.18 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115372">https://www.tenable.com/plugins/was/115372</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.7.x < 5.7.16 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115371</link>
            <guid>https://www.tenable.com/plugins/was/115371</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115371 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.7.x < 5.7.16 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.7.16 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115371">https://www.tenable.com/plugins/was/115371</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.8.x < 5.8.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115370</link>
            <guid>https://www.tenable.com/plugins/was/115370</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115370 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.8.x < 5.8.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.8.14 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115370">https://www.tenable.com/plugins/was/115370</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 5.9.x < 5.9.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115369</link>
            <guid>https://www.tenable.com/plugins/was/115369</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115369 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 5.9.x < 5.9.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 5.9.14 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115369">https://www.tenable.com/plugins/was/115369</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.0.x < 6.0.13 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115368</link>
            <guid>https://www.tenable.com/plugins/was/115368</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115368 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.0.x < 6.0.13 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.0.13 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115368">https://www.tenable.com/plugins/was/115368</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.1.x < 6.1.11 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115367</link>
            <guid>https://www.tenable.com/plugins/was/115367</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115367 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.1.x < 6.1.11 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.1.11 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115367">https://www.tenable.com/plugins/was/115367</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.2.x < 6.2.10 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115366</link>
            <guid>https://www.tenable.com/plugins/was/115366</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115366 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.2.x < 6.2.10 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.2.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115366">https://www.tenable.com/plugins/was/115366</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.3.x < 6.3.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115365</link>
            <guid>https://www.tenable.com/plugins/was/115365</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115365 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.3.x < 6.3.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.3.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115365">https://www.tenable.com/plugins/was/115365</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.4.x < 6.4.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115364</link>
            <guid>https://www.tenable.com/plugins/was/115364</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115364 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.4.x < 6.4.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.4.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115364">https://www.tenable.com/plugins/was/115364</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.5.x < 6.5.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115363</link>
            <guid>https://www.tenable.com/plugins/was/115363</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115363 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.5.x < 6.5.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.5.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115363">https://www.tenable.com/plugins/was/115363</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.6.x < 6.6.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115362</link>
            <guid>https://www.tenable.com/plugins/was/115362</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115362 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.6.x < 6.6.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.6.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115362">https://www.tenable.com/plugins/was/115362</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.7.x < 6.7.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115361</link>
            <guid>https://www.tenable.com/plugins/was/115361</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115361 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.7.x < 6.7.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.7.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115361">https://www.tenable.com/plugins/was/115361</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.8.x < 6.8.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115360</link>
            <guid>https://www.tenable.com/plugins/was/115360</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115360 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.8.x < 6.8.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.8.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115360">https://www.tenable.com/plugins/was/115360</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.9.x < 6.9.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115359</link>
            <guid>https://www.tenable.com/plugins/was/115359</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115359 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.9.x < 6.9.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 6.9.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115359">https://www.tenable.com/plugins/was/115359</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 7.0.x < 7.0.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115358</link>
            <guid>https://www.tenable.com/plugins/was/115358</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115358 with High Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 7.0.x < 7.0.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of WordPress installed on the remote host is affected by multiple vulnerabilities:<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Date block.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in the Post Content block.<br /></span><span><br /></span><span> - An information disclosure issue in the Latest Comments block exposing comments on password-protected posts.<br /></span><span><br /></span><span> - A bypass of the email address confirmation flow.<br /></span><span><br /></span><span> - An Author+ CSS injection issue via a bypass of the safe CSS attribute filter.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in posts via the emoji settings element.<br /></span><span><br /></span><span> - A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site.<br /></span><span><br /></span><span> - A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges.<br /></span><span><br /></span><span> - A pre-auth reflected cross-site scripting (XSS) issue on the login screen with potential to lead to PHP code execution. (CVE-2026-64638)<br /></span><span><br /></span><span> - A disclosure of notes in comment feeds.<br /></span><span><br /></span><span> - An enumeration of post slugs.<br /></span><span><br /></span><span> - A Contributor+ stored cross-site scripting (XSS) issue in Quick Edit on sites with a large number of users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress version 7.0.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115358">https://www.tenable.com/plugins/was/115358</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.10.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115357</link>
            <guid>https://www.tenable.com/plugins/was/115357</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115357 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.10.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Langflow is vulnerable to an attack allowing an unauthenticated attacker to execute arbitrary code via a specially forged request on the '/api/v1/validate/code' endpoint. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.10.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115357">https://www.tenable.com/plugins/was/115357</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N-Able N-Central < 2026.3.1.7 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115356</link>
            <guid>https://www.tenable.com/plugins/was/115356</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115356 with High Severity</p>
      <h3>Synopsis</h3>
      <span>N-Able N-Central < 2026.3.1.7 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of N-Able N-Central running on the remote host is prior to 2026.3.1.7. It is, therefore, affected by an Authentication Bypass and Account Takeover.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to N-Able N-Central version 2026.3.1.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115356">https://www.tenable.com/plugins/was/115356</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.2.x < 8.2.33 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115355</link>
            <guid>https://www.tenable.com/plugins/was/115355</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115355 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.2.x < 8.2.33 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.33, 8.3.x prior to 8.3.33, 8.4.x prior to 8.4.24, or 8.5.x prior to 8.5.9. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Out-of-bounds write in bccomp() in BCMath. (CVE-2026-17544)<br /></span><span><br /></span><span>- Vulnerability in the bundled libgd library. (CVE-2026-9672)<br /></span><span><br /></span><span>- SQL injection via E'...' backslash breakout in PGSQL. (CVE-2026-17543)<br /></span><span><br /></span><span>- Crash via recursive symlinks in Phar. (CVE-2026-7260)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.2.33 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115355">https://www.tenable.com/plugins/was/115355</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.3.x < 8.3.33 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115354</link>
            <guid>https://www.tenable.com/plugins/was/115354</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115354 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.3.x < 8.3.33 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.33, 8.3.x prior to 8.3.33, 8.4.x prior to 8.4.24, or 8.5.x prior to 8.5.9. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Out-of-bounds write in bccomp() in BCMath. (CVE-2026-17544)<br /></span><span><br /></span><span>- Vulnerability in the bundled libgd library. (CVE-2026-9672)<br /></span><span><br /></span><span>- SQL injection via E'...' backslash breakout in PGSQL. (CVE-2026-17543)<br /></span><span><br /></span><span>- Crash via recursive symlinks in Phar. (CVE-2026-7260)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.3.33 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115354">https://www.tenable.com/plugins/was/115354</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.4.x < 8.4.24 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115353</link>
            <guid>https://www.tenable.com/plugins/was/115353</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115353 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.4.x < 8.4.24 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.33, 8.3.x prior to 8.3.33, 8.4.x prior to 8.4.24, or 8.5.x prior to 8.5.9. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Out-of-bounds write in bccomp() in BCMath. (CVE-2026-17544)<br /></span><span><br /></span><span>- Vulnerability in the bundled libgd library. (CVE-2026-9672)<br /></span><span><br /></span><span>- SQL injection via E'...' backslash breakout in PGSQL. (CVE-2026-17543)<br /></span><span><br /></span><span>- Crash via recursive symlinks in Phar. (CVE-2026-7260)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.4.24 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115353">https://www.tenable.com/plugins/was/115353</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.5.x < 8.5.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115352</link>
            <guid>https://www.tenable.com/plugins/was/115352</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115352 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.5.x < 8.5.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.33, 8.3.x prior to 8.3.33, 8.4.x prior to 8.4.24, or 8.5.x prior to 8.5.9. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Out-of-bounds write in bccomp() in BCMath. (CVE-2026-17544)<br /></span><span><br /></span><span>- Vulnerability in the bundled libgd library. (CVE-2026-9672)<br /></span><span><br /></span><span>- SQL injection via E'...' backslash breakout in PGSQL. (CVE-2026-17543)<br /></span><span><br /></span><span>- Crash via recursive symlinks in Phar. (CVE-2026-7260)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.5.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115352">https://www.tenable.com/plugins/was/115352</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.x < 9.0.121 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115351</link>
            <guid>https://www.tenable.com/plugins/was/115351</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115351 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.x < 9.0.121 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is prior to 9.0.121, 10.1.59, or 11.0.25. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The security constraint processing enabled a security constraint bypass if a constraint for a longer path was specified before a more restrictive constraint for a shorter sub-path. (CVE-2026-65182)<br /></span><span><br /></span><span>- A race condition (TOCTOU) when creating a Unix Domain Socket allowed an unauthorized local user to access the Unix Domain Socket. (CVE-2026-65183)<br /></span><span><br /></span><span>- An incomplete fix for CVE-2026-32990 allowed HTTP/2 no-authority requests to bypass strict SNI validation. (CVE-2026-65637)<br /></span><span><br /></span><span>- A limited replay attack was possible with DIGEST authentication if a client made an authenticated request with a nonceCount on the upper boundary of the replay window before windowSize requests had been made. (CVE-2026-65905)<br /></span><span><br /></span><span>- An off-by-one error in the RewriteValve [N] flag caused rewrite processing to restart at the second rule rather than the first, potentially allowing an attacker to bypass access control. (CVE-2026-65927)<br /></span><span><br /></span><span>- The WebSocket chat example provided an unbounded buffer for undelivered messages, allowing a maliciously slow client to cause memory exhaustion and failure of the Tomcat process. (CVE-2026-66299)<br /></span><span><br /></span><span>- security-role-ref definitions were incorrectly used as role aliases within the Realm, allowing servlet role references to bypass declarative role constraints. (CVE-2026-66422)<br /></span><span><br /></span><span>- The FORM authentication process allowed the bypassing of a security constraint that limited user access to a resource via POST but not GET. (CVE-2026-68525)<br /></span><span><br /></span><span>- For some authentication methods (e.g., CLIENT-CERT, SPNEGO), a user would be authenticated even if the user did not exist in the DataSourceRealm or JDBCRealm. (CVE-2026-68569)<br /></span><span><br /></span><span>- An allocation leak in HTTP/2 backlog tracking when a stream was reset could be manipulated to trigger a denial of service. (CVE-2026-68763)<br /></span><span><br /></span><span>- If the session ID for an authenticated HTTP session was changed after a WebSocket connection was established, the WebSocket session was not closed when the HTTP session ended as required by the Jakarta WebSocket specification. (CVE-2026-73180)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.121 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115351">https://www.tenable.com/plugins/was/115351</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.x < 10.1.59 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115350</link>
            <guid>https://www.tenable.com/plugins/was/115350</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115350 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.x < 10.1.59 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is prior to 9.0.121, 10.1.59, or 11.0.25. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The security constraint processing enabled a security constraint bypass if a constraint for a longer path was specified before a more restrictive constraint for a shorter sub-path. (CVE-2026-65182)<br /></span><span><br /></span><span>- A race condition (TOCTOU) when creating a Unix Domain Socket allowed an unauthorized local user to access the Unix Domain Socket. (CVE-2026-65183)<br /></span><span><br /></span><span>- An incomplete fix for CVE-2026-32990 allowed HTTP/2 no-authority requests to bypass strict SNI validation. (CVE-2026-65637)<br /></span><span><br /></span><span>- A limited replay attack was possible with DIGEST authentication if a client made an authenticated request with a nonceCount on the upper boundary of the replay window before windowSize requests had been made. (CVE-2026-65905)<br /></span><span><br /></span><span>- An off-by-one error in the RewriteValve [N] flag caused rewrite processing to restart at the second rule rather than the first, potentially allowing an attacker to bypass access control. (CVE-2026-65927)<br /></span><span><br /></span><span>- The WebSocket chat example provided an unbounded buffer for undelivered messages, allowing a maliciously slow client to cause memory exhaustion and failure of the Tomcat process. (CVE-2026-66299)<br /></span><span><br /></span><span>- security-role-ref definitions were incorrectly used as role aliases within the Realm, allowing servlet role references to bypass declarative role constraints. (CVE-2026-66422)<br /></span><span><br /></span><span>- The FORM authentication process allowed the bypassing of a security constraint that limited user access to a resource via POST but not GET. (CVE-2026-68525)<br /></span><span><br /></span><span>- For some authentication methods (e.g., CLIENT-CERT, SPNEGO), a user would be authenticated even if the user did not exist in the DataSourceRealm or JDBCRealm. (CVE-2026-68569)<br /></span><span><br /></span><span>- An allocation leak in HTTP/2 backlog tracking when a stream was reset could be manipulated to trigger a denial of service. (CVE-2026-68763)<br /></span><span><br /></span><span>- If the session ID for an authenticated HTTP session was changed after a WebSocket connection was established, the WebSocket session was not closed when the HTTP session ended as required by the Jakarta WebSocket specification. (CVE-2026-73180)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.59 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115350">https://www.tenable.com/plugins/was/115350</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.x < 11.0.25 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115349</link>
            <guid>https://www.tenable.com/plugins/was/115349</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115349 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.x < 11.0.25 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is prior to 9.0.121, 10.1.59, or 11.0.25. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The security constraint processing enabled a security constraint bypass if a constraint for a longer path was specified before a more restrictive constraint for a shorter sub-path. (CVE-2026-65182)<br /></span><span><br /></span><span>- A race condition (TOCTOU) when creating a Unix Domain Socket allowed an unauthorized local user to access the Unix Domain Socket. (CVE-2026-65183)<br /></span><span><br /></span><span>- An incomplete fix for CVE-2026-32990 allowed HTTP/2 no-authority requests to bypass strict SNI validation. (CVE-2026-65637)<br /></span><span><br /></span><span>- A limited replay attack was possible with DIGEST authentication if a client made an authenticated request with a nonceCount on the upper boundary of the replay window before windowSize requests had been made. (CVE-2026-65905)<br /></span><span><br /></span><span>- An off-by-one error in the RewriteValve [N] flag caused rewrite processing to restart at the second rule rather than the first, potentially allowing an attacker to bypass access control. (CVE-2026-65927)<br /></span><span><br /></span><span>- The WebSocket chat example provided an unbounded buffer for undelivered messages, allowing a maliciously slow client to cause memory exhaustion and failure of the Tomcat process. (CVE-2026-66299)<br /></span><span><br /></span><span>- security-role-ref definitions were incorrectly used as role aliases within the Realm, allowing servlet role references to bypass declarative role constraints. (CVE-2026-66422)<br /></span><span><br /></span><span>- The FORM authentication process allowed the bypassing of a security constraint that limited user access to a resource via POST but not GET. (CVE-2026-68525)<br /></span><span><br /></span><span>- For some authentication methods (e.g., CLIENT-CERT, SPNEGO), a user would be authenticated even if the user did not exist in the DataSourceRealm or JDBCRealm. (CVE-2026-68569)<br /></span><span><br /></span><span>- An allocation leak in HTTP/2 backlog tracking when a stream was reset could be manipulated to trigger a denial of service. (CVE-2026-68763)<br /></span><span><br /></span><span>- If the session ID for an authenticated HTTP session was changed after a WebSocket connection was established, the WebSocket session was not closed when the HTTP session ended as required by the Jakarta WebSocket specification. (CVE-2026-73180)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.25 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115349">https://www.tenable.com/plugins/was/115349</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Advanced Responsive Video Embedder Plugin for WordPress 10.8.7 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115348</link>
            <guid>https://www.tenable.com/plugins/was/115348</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115348 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Advanced Responsive Video Embedder Plugin for WordPress 10.8.7 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>The WordPress Advanced Responsive Video Embedder Plugin installed on the remote host is affected by an Unauthenticated Authentication Bypass via Hardcoded Backdoor.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Advanced Responsive Video Embedder for WordPress version 10.8.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115348">https://www.tenable.com/plugins/was/115348</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JetBrains TeamCity 2026.x < 2026.1.3 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115346</link>
            <guid>https://www.tenable.com/plugins/was/115346</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115346 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>JetBrains TeamCity 2026.x < 2026.1.3 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of JetBrains TeamCity running on the remote host is < 2025.11.7 or 2026.x < 2026.1.3. It is, therefore, affected by a Remote Code Execution via the agent polling protocol.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to JetBrains TeamCity version 2026.1.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115346">https://www.tenable.com/plugins/was/115346</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JetBrains TeamCity < 2025.11.7 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115345</link>
            <guid>https://www.tenable.com/plugins/was/115345</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115345 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>JetBrains TeamCity < 2025.11.7 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of JetBrains TeamCity running on the remote host is < 2025.11.7 or 2026.x < 2026.1.3. It is, therefore, affected by a Remote Code Execution via the agent polling protocol.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to JetBrains TeamCity version 2025.11.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115345">https://www.tenable.com/plugins/was/115345</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WP Go Maps Plugin for WordPress < 6.0.27 Multiple Cross-site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115344</link>
            <guid>https://www.tenable.com/plugins/was/115344</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115344 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WP Go Maps Plugin for WordPress < 6.0.27 Multiple Cross-site Scripting<br /></span>
      <h3>Description</h3>
      <span>The WordPress WP Go Maps Plugin installed on the remote host is affected by multiple Cross-site Scripting.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WP Go Maps Plugin for WordPress 6.0.27 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115344">https://www.tenable.com/plugins/was/115344</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.43.x < 1.43.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115343</link>
            <guid>https://www.tenable.com/plugins/was/115343</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115343 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.43.x < 1.43.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.12, 1.42.x prior to 1.42.6 or 1.43.x prior to 1.43.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Improper restrictions on the file revert action. (CVE-2025-32696)<br /></span><span><br /></span><span>- PermissionManager fails to differentiate between cascading protection sources, allowing an unauthorized user to edit protected pages. (CVE-2025-32697)<br /></span><span><br /></span><span>- LogPager restriction enforcement functions do not properly restrict access to suppressed log entries. (CVE-2025-32698)<br /></span><span><br /></span><span>- Potential JavaScript injection via Unicode normalization enabling XSS attacks. (CVE-2025-32699)<br /></span><span><br /></span><span>- An i18n XSS vulnerability in HTMLMultiSelectField with sections. (CVE-2025-3469)<br /></span><span><br /></span><span>- AbuseFilter log interfaces expose private/hidden filters when they should be restricted. (CVE-2025-32700)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115343">https://www.tenable.com/plugins/was/115343</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.42.x < 1.42.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115342</link>
            <guid>https://www.tenable.com/plugins/was/115342</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115342 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.42.x < 1.42.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.12, 1.42.x prior to 1.42.6 or 1.43.x prior to 1.43.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Improper restrictions on the file revert action. (CVE-2025-32696)<br /></span><span><br /></span><span>- PermissionManager fails to differentiate between cascading protection sources, allowing an unauthorized user to edit protected pages. (CVE-2025-32697)<br /></span><span><br /></span><span>- LogPager restriction enforcement functions do not properly restrict access to suppressed log entries. (CVE-2025-32698)<br /></span><span><br /></span><span>- Potential JavaScript injection via Unicode normalization enabling XSS attacks. (CVE-2025-32699)<br /></span><span><br /></span><span>- An i18n XSS vulnerability in HTMLMultiSelectField with sections. (CVE-2025-3469)<br /></span><span><br /></span><span>- AbuseFilter log interfaces expose private/hidden filters when they should be restricted. (CVE-2025-32700)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.42.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115342">https://www.tenable.com/plugins/was/115342</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.39.12 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115341</link>
            <guid>https://www.tenable.com/plugins/was/115341</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115341 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.39.12 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.12, 1.42.x prior to 1.42.6 or 1.43.x prior to 1.43.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Improper restrictions on the file revert action. (CVE-2025-32696)<br /></span><span><br /></span><span>- PermissionManager fails to differentiate between cascading protection sources, allowing an unauthorized user to edit protected pages. (CVE-2025-32697)<br /></span><span><br /></span><span>- LogPager restriction enforcement functions do not properly restrict access to suppressed log entries. (CVE-2025-32698)<br /></span><span><br /></span><span>- Potential JavaScript injection via Unicode normalization enabling XSS attacks. (CVE-2025-32699)<br /></span><span><br /></span><span>- An i18n XSS vulnerability in HTMLMultiSelectField with sections. (CVE-2025-3469)<br /></span><span><br /></span><span>- AbuseFilter log interfaces expose private/hidden filters when they should be restricted. (CVE-2025-32700)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.39.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115341">https://www.tenable.com/plugins/was/115341</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.43.x < 1.43.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115340</link>
            <guid>https://www.tenable.com/plugins/was/115340</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115340 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.43.x < 1.43.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.13, 1.42.x prior to 1.42.7 or 1.43.x prior to 1.43.2. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Failure to escape the newpage message in FeedUtils enabling XSS attacks. (CVE-2025-32072)<br /></span><span><br /></span><span>- BlockList discloses rows containing suppressed users. (CVE-2025-6589)<br /></span><span><br /></span><span>- Failure to escape usernames in HTMLUserTextField validation errors enabling XSS attacks. (CVE-2025-6590)<br /></span><span><br /></span><span>- Failure to escape i18n messages in the action=feedcontributions API enabling XSS attacks. (CVE-2025-6591)<br /></span><span><br /></span><span>- Account creation links a temporary username/IP with the real username. (CVE-2025-6592)<br /></span><span><br /></span><span>- IP address leak to an unverified email. (CVE-2025-6593)<br /></span><span><br /></span><span>- Reflected XSS in apisandbox when an invalid 'format' value is provided. (CVE-2025-6594)<br /></span><span><br /></span><span>- Stored XSS through system messages in MultimediaViewer. (CVE-2025-6595)<br /></span><span><br /></span><span>- Vector inserts portlet labels as HTML, allowing stored XSS. (CVE-2025-6596)<br /></span><span><br /></span><span>- Autocreation is treated as a login for reauthentication. (CVE-2025-6597)<br /></span><span><br /></span><span>- Extensions are unable to suppress the reauth flag on login. (CVE-2025-6926)<br /></span><span><br /></span><span>- Autoblocks visibility and hidden username leaks. (CVE-2025-6927)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115340">https://www.tenable.com/plugins/was/115340</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.42.x < 1.42.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115339</link>
            <guid>https://www.tenable.com/plugins/was/115339</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115339 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.42.x < 1.42.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.13, 1.42.x prior to 1.42.7 or 1.43.x prior to 1.43.2. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Failure to escape the newpage message in FeedUtils enabling XSS attacks. (CVE-2025-32072)<br /></span><span><br /></span><span>- BlockList discloses rows containing suppressed users. (CVE-2025-6589)<br /></span><span><br /></span><span>- Failure to escape usernames in HTMLUserTextField validation errors enabling XSS attacks. (CVE-2025-6590)<br /></span><span><br /></span><span>- Failure to escape i18n messages in the action=feedcontributions API enabling XSS attacks. (CVE-2025-6591)<br /></span><span><br /></span><span>- Account creation links a temporary username/IP with the real username. (CVE-2025-6592)<br /></span><span><br /></span><span>- IP address leak to an unverified email. (CVE-2025-6593)<br /></span><span><br /></span><span>- Reflected XSS in apisandbox when an invalid 'format' value is provided. (CVE-2025-6594)<br /></span><span><br /></span><span>- Stored XSS through system messages in MultimediaViewer. (CVE-2025-6595)<br /></span><span><br /></span><span>- Vector inserts portlet labels as HTML, allowing stored XSS. (CVE-2025-6596)<br /></span><span><br /></span><span>- Autocreation is treated as a login for reauthentication. (CVE-2025-6597)<br /></span><span><br /></span><span>- Extensions are unable to suppress the reauth flag on login. (CVE-2025-6926)<br /></span><span><br /></span><span>- Autoblocks visibility and hidden username leaks. (CVE-2025-6927)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.42.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115339">https://www.tenable.com/plugins/was/115339</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.39.13 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115338</link>
            <guid>https://www.tenable.com/plugins/was/115338</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115338 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.39.13 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.13, 1.42.x prior to 1.42.7 or 1.43.x prior to 1.43.2. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Failure to escape the newpage message in FeedUtils enabling XSS attacks. (CVE-2025-32072)<br /></span><span><br /></span><span>- BlockList discloses rows containing suppressed users. (CVE-2025-6589)<br /></span><span><br /></span><span>- Failure to escape usernames in HTMLUserTextField validation errors enabling XSS attacks. (CVE-2025-6590)<br /></span><span><br /></span><span>- Failure to escape i18n messages in the action=feedcontributions API enabling XSS attacks. (CVE-2025-6591)<br /></span><span><br /></span><span>- Account creation links a temporary username/IP with the real username. (CVE-2025-6592)<br /></span><span><br /></span><span>- IP address leak to an unverified email. (CVE-2025-6593)<br /></span><span><br /></span><span>- Reflected XSS in apisandbox when an invalid 'format' value is provided. (CVE-2025-6594)<br /></span><span><br /></span><span>- Stored XSS through system messages in MultimediaViewer. (CVE-2025-6595)<br /></span><span><br /></span><span>- Vector inserts portlet labels as HTML, allowing stored XSS. (CVE-2025-6596)<br /></span><span><br /></span><span>- Autocreation is treated as a login for reauthentication. (CVE-2025-6597)<br /></span><span><br /></span><span>- Extensions are unable to suppress the reauth flag on login. (CVE-2025-6926)<br /></span><span><br /></span><span>- Autoblocks visibility and hidden username leaks. (CVE-2025-6927)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.39.13 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115338">https://www.tenable.com/plugins/was/115338</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.44.x < 1.44.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115337</link>
            <guid>https://www.tenable.com/plugins/was/115337</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115337 with High Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.44.x < 1.44.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.14, 1.43.x prior to 1.43.4 or 1.44.x prior to 1.44.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- REST does not set a cache-control value of max-age=60 for redirects. (CVE-2025-61634)<br /></span><span><br /></span><span>- ApiFancyCaptchaReload does not reuse the badcaptcha rate limit in ConfirmEdit. (CVE-2025-61635)<br /></span><span><br /></span><span>- Failure to escape rawElement $content. (CVE-2025-61636)<br /></span><span><br /></span><span>- Failure to escape three system messages used by live preview. (CVE-2025-61637)<br /></span><span><br /></span><span>- Failure to sanitize data- attributes (also affects Parsoid). (CVE-2025-61638)<br /></span><span><br /></span><span>- Improper use of ManualLogEntry::getDeleted in ::getRecentChange. (CVE-2025-61639)<br /></span><span><br /></span><span>- Messages are inserted as HTML instead of being parsed. (CVE-2025-61640)<br /></span><span><br /></span><span>- maxsize is not disabled in QueryAllPages in miser mode. (CVE-2025-61641)<br /></span><span><br /></span><span>- Failure to escape the submit button label for Codex-based HTMLForms. (CVE-2025-61642)<br /></span><span><br /></span><span>- Suppressed recent changes are sent to RCFeeds. (CVE-2025-61643)<br /></span><span><br /></span><span>- i18n XSS in CodexTablePager. (CVE-2025-61645)<br /></span><span><br /></span><span>- Hidden usernames are leaked in Watchlist/RecentChanges. (CVE-2025-61646)<br /></span><span><br /></span><span>- Failure to escape system messages before inserting them as HTML in CheckUser. (CVE-2025-61648)<br /></span><span><br /></span><span>- XSS in the tempuser-expired-link-tooltip message in CheckUser. (CVE-2025-61651)<br /></span><span><br /></span><span>- API does not check user read permissions before showing PageInfo in DiscussionTools. (CVE-2025-61652)<br /></span><span><br /></span><span>- Missing authorizeRead check for the extracts endpoint in TextExtracts. (CVE-2025-61653)<br /></span><span><br /></span><span>- Deleted entries are not excluded when counting thanks in Thanks. (CVE-2025-61654)<br /></span><span><br /></span><span>- Improper escaping and parsing of system messages in VisualEditor. (CVE-2025-61655)<br /></span><span><br /></span><span>- Failure to sanitize attributes unwrapped from data-ve-attributes in VisualEditor. (CVE-2025-61656)<br /></span><span><br /></span><span>- Sticky header labels are inserted as HTML instead of text in Vector. (CVE-2025-61657)<br /></span><span><br /></span><span>- Missing config variable to exclude from GlobalContributions in CheckUser. (CVE-2025-61658)<br /></span><span><br /></span><span>- Reauth for enabling 2FA can be bypassed by submitting a form in OATHAuth. (CVE-2025-11173)<br /></span><span><br /></span><span>- DiscussionTools uses an insufficient regex. (CVE-2025-11175)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.44.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115337">https://www.tenable.com/plugins/was/115337</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.43.x < 1.43.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115336</link>
            <guid>https://www.tenable.com/plugins/was/115336</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115336 with High Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.43.x < 1.43.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.14, 1.43.x prior to 1.43.4 or 1.44.x prior to 1.44.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- REST does not set a cache-control value of max-age=60 for redirects. (CVE-2025-61634)<br /></span><span><br /></span><span>- ApiFancyCaptchaReload does not reuse the badcaptcha rate limit in ConfirmEdit. (CVE-2025-61635)<br /></span><span><br /></span><span>- Failure to escape rawElement $content. (CVE-2025-61636)<br /></span><span><br /></span><span>- Failure to escape three system messages used by live preview. (CVE-2025-61637)<br /></span><span><br /></span><span>- Failure to sanitize data- attributes (also affects Parsoid). (CVE-2025-61638)<br /></span><span><br /></span><span>- Improper use of ManualLogEntry::getDeleted in ::getRecentChange. (CVE-2025-61639)<br /></span><span><br /></span><span>- Messages are inserted as HTML instead of being parsed. (CVE-2025-61640)<br /></span><span><br /></span><span>- maxsize is not disabled in QueryAllPages in miser mode. (CVE-2025-61641)<br /></span><span><br /></span><span>- Failure to escape the submit button label for Codex-based HTMLForms. (CVE-2025-61642)<br /></span><span><br /></span><span>- Suppressed recent changes are sent to RCFeeds. (CVE-2025-61643)<br /></span><span><br /></span><span>- i18n XSS in CodexTablePager. (CVE-2025-61645)<br /></span><span><br /></span><span>- Hidden usernames are leaked in Watchlist/RecentChanges. (CVE-2025-61646)<br /></span><span><br /></span><span>- Failure to escape system messages before inserting them as HTML in CheckUser. (CVE-2025-61648)<br /></span><span><br /></span><span>- XSS in the tempuser-expired-link-tooltip message in CheckUser. (CVE-2025-61651)<br /></span><span><br /></span><span>- API does not check user read permissions before showing PageInfo in DiscussionTools. (CVE-2025-61652)<br /></span><span><br /></span><span>- Missing authorizeRead check for the extracts endpoint in TextExtracts. (CVE-2025-61653)<br /></span><span><br /></span><span>- Deleted entries are not excluded when counting thanks in Thanks. (CVE-2025-61654)<br /></span><span><br /></span><span>- Improper escaping and parsing of system messages in VisualEditor. (CVE-2025-61655)<br /></span><span><br /></span><span>- Failure to sanitize attributes unwrapped from data-ve-attributes in VisualEditor. (CVE-2025-61656)<br /></span><span><br /></span><span>- Sticky header labels are inserted as HTML instead of text in Vector. (CVE-2025-61657)<br /></span><span><br /></span><span>- Missing config variable to exclude from GlobalContributions in CheckUser. (CVE-2025-61658)<br /></span><span><br /></span><span>- Reauth for enabling 2FA can be bypassed by submitting a form in OATHAuth. (CVE-2025-11173)<br /></span><span><br /></span><span>- DiscussionTools uses an insufficient regex. (CVE-2025-11175)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115336">https://www.tenable.com/plugins/was/115336</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.39.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115335</link>
            <guid>https://www.tenable.com/plugins/was/115335</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115335 with High Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.39.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.14, 1.43.x prior to 1.43.4 or 1.44.x prior to 1.44.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- REST does not set a cache-control value of max-age=60 for redirects. (CVE-2025-61634)<br /></span><span><br /></span><span>- ApiFancyCaptchaReload does not reuse the badcaptcha rate limit in ConfirmEdit. (CVE-2025-61635)<br /></span><span><br /></span><span>- Failure to escape rawElement $content. (CVE-2025-61636)<br /></span><span><br /></span><span>- Failure to escape three system messages used by live preview. (CVE-2025-61637)<br /></span><span><br /></span><span>- Failure to sanitize data- attributes (also affects Parsoid). (CVE-2025-61638)<br /></span><span><br /></span><span>- Improper use of ManualLogEntry::getDeleted in ::getRecentChange. (CVE-2025-61639)<br /></span><span><br /></span><span>- Messages are inserted as HTML instead of being parsed. (CVE-2025-61640)<br /></span><span><br /></span><span>- maxsize is not disabled in QueryAllPages in miser mode. (CVE-2025-61641)<br /></span><span><br /></span><span>- Failure to escape the submit button label for Codex-based HTMLForms. (CVE-2025-61642)<br /></span><span><br /></span><span>- Suppressed recent changes are sent to RCFeeds. (CVE-2025-61643)<br /></span><span><br /></span><span>- i18n XSS in CodexTablePager. (CVE-2025-61645)<br /></span><span><br /></span><span>- Hidden usernames are leaked in Watchlist/RecentChanges. (CVE-2025-61646)<br /></span><span><br /></span><span>- Failure to escape system messages before inserting them as HTML in CheckUser. (CVE-2025-61648)<br /></span><span><br /></span><span>- XSS in the tempuser-expired-link-tooltip message in CheckUser. (CVE-2025-61651)<br /></span><span><br /></span><span>- API does not check user read permissions before showing PageInfo in DiscussionTools. (CVE-2025-61652)<br /></span><span><br /></span><span>- Missing authorizeRead check for the extracts endpoint in TextExtracts. (CVE-2025-61653)<br /></span><span><br /></span><span>- Deleted entries are not excluded when counting thanks in Thanks. (CVE-2025-61654)<br /></span><span><br /></span><span>- Improper escaping and parsing of system messages in VisualEditor. (CVE-2025-61655)<br /></span><span><br /></span><span>- Failure to sanitize attributes unwrapped from data-ve-attributes in VisualEditor. (CVE-2025-61656)<br /></span><span><br /></span><span>- Sticky header labels are inserted as HTML instead of text in Vector. (CVE-2025-61657)<br /></span><span><br /></span><span>- Missing config variable to exclude from GlobalContributions in CheckUser. (CVE-2025-61658)<br /></span><span><br /></span><span>- Reauth for enabling 2FA can be bypassed by submitting a form in OATHAuth. (CVE-2025-11173)<br /></span><span><br /></span><span>- DiscussionTools uses an insufficient regex. (CVE-2025-11175)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.39.14 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115335">https://www.tenable.com/plugins/was/115335</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.44.x < 1.44.2 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115334</link>
            <guid>https://www.tenable.com/plugins/was/115334</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115334 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.44.x < 1.44.2 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.15, 1.43.x prior to 1.43.5 or 1.44.x prior to 1.44.2. It is, therefore, affected by a vulnerability as follows.<br /></span><span><br /></span><span>- A low severity cross-site scripting (XSS) issue in MediaWiki core affecting all active release branches, which became apparent during CheckUser extension backport corrections. (CVE-2025-11261)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.44.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115334">https://www.tenable.com/plugins/was/115334</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.43.x < 1.43.5 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115333</link>
            <guid>https://www.tenable.com/plugins/was/115333</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115333 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.43.x < 1.43.5 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.15, 1.43.x prior to 1.43.5 or 1.44.x prior to 1.44.2. It is, therefore, affected by a vulnerability as follows.<br /></span><span><br /></span><span>- A low severity cross-site scripting (XSS) issue in MediaWiki core affecting all active release branches, which became apparent during CheckUser extension backport corrections. (CVE-2025-11261)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115333">https://www.tenable.com/plugins/was/115333</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.39.15 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115332</link>
            <guid>https://www.tenable.com/plugins/was/115332</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115332 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.39.15 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.15, 1.43.x prior to 1.43.5 or 1.44.x prior to 1.44.2. It is, therefore, affected by a vulnerability as follows.<br /></span><span><br /></span><span>- A low severity cross-site scripting (XSS) issue in MediaWiki core affecting all active release branches, which became apparent during CheckUser extension backport corrections. (CVE-2025-11261)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.39.15 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115332">https://www.tenable.com/plugins/was/115332</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.45.x < 1.45.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115331</link>
            <guid>https://www.tenable.com/plugins/was/115331</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115331 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.45.x < 1.45.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.16, 1.43.x prior to 1.43.6, 1.44.x prior to 1.44.3 or 1.45.x prior to 1.45.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- The xslt option is enabled by default in API format=xml responses. (CVE-2025-67484)<br /></span><span><br /></span><span>- Failure to escape the word-separator message in Special:ApiSandbox. (CVE-2025-67477)<br /></span><span><br /></span><span>- Failure to escape square brackets in autocomment links. (CVE-2025-67475)<br /></span><span><br /></span><span>- The importer's IP is used in case of an external revision author, leading to information disclosure. (CVE-2025-67476)<br /></span><span><br /></span><span>- Failure to always escape commas in mail encoded-words. (CVE-2025-67478)<br /></span><span><br /></span><span>- The Sanitizer does not disallow underscore and wide underscore in data-* attribute names. (CVE-2025-67479)<br /></span><span><br /></span><span>- Missing read permission check in ApiQueryRevisionsBase enabling an access control bypass. (CVE-2025-67480)<br /></span><span><br /></span><span>- Failure to escape the 'comma-separator' between multiple protection levels. (CVE-2025-67483)<br /></span><span><br /></span><span>- The 'style' attribute is allowed in client-side messages (jqueryMsg), enabling XSS. (CVE-2025-67481)<br /></span><span><br /></span><span>- A Lua segfault in unpack() leading to a denial of service. (CVE-2025-67482)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.45.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115331">https://www.tenable.com/plugins/was/115331</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.44.x < 1.44.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115330</link>
            <guid>https://www.tenable.com/plugins/was/115330</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115330 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.44.x < 1.44.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.16, 1.43.x prior to 1.43.6, 1.44.x prior to 1.44.3 or 1.45.x prior to 1.45.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- The xslt option is enabled by default in API format=xml responses. (CVE-2025-67484)<br /></span><span><br /></span><span>- Failure to escape the word-separator message in Special:ApiSandbox. (CVE-2025-67477)<br /></span><span><br /></span><span>- Failure to escape square brackets in autocomment links. (CVE-2025-67475)<br /></span><span><br /></span><span>- The importer's IP is used in case of an external revision author, leading to information disclosure. (CVE-2025-67476)<br /></span><span><br /></span><span>- Failure to always escape commas in mail encoded-words. (CVE-2025-67478)<br /></span><span><br /></span><span>- The Sanitizer does not disallow underscore and wide underscore in data-* attribute names. (CVE-2025-67479)<br /></span><span><br /></span><span>- Missing read permission check in ApiQueryRevisionsBase enabling an access control bypass. (CVE-2025-67480)<br /></span><span><br /></span><span>- Failure to escape the 'comma-separator' between multiple protection levels. (CVE-2025-67483)<br /></span><span><br /></span><span>- The 'style' attribute is allowed in client-side messages (jqueryMsg), enabling XSS. (CVE-2025-67481)<br /></span><span><br /></span><span>- A Lua segfault in unpack() leading to a denial of service. (CVE-2025-67482)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.44.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115330">https://www.tenable.com/plugins/was/115330</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.43.x < 1.43.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115329</link>
            <guid>https://www.tenable.com/plugins/was/115329</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115329 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.43.x < 1.43.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.16, 1.43.x prior to 1.43.6, 1.44.x prior to 1.44.3 or 1.45.x prior to 1.45.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- The xslt option is enabled by default in API format=xml responses. (CVE-2025-67484)<br /></span><span><br /></span><span>- Failure to escape the word-separator message in Special:ApiSandbox. (CVE-2025-67477)<br /></span><span><br /></span><span>- Failure to escape square brackets in autocomment links. (CVE-2025-67475)<br /></span><span><br /></span><span>- The importer's IP is used in case of an external revision author, leading to information disclosure. (CVE-2025-67476)<br /></span><span><br /></span><span>- Failure to always escape commas in mail encoded-words. (CVE-2025-67478)<br /></span><span><br /></span><span>- The Sanitizer does not disallow underscore and wide underscore in data-* attribute names. (CVE-2025-67479)<br /></span><span><br /></span><span>- Missing read permission check in ApiQueryRevisionsBase enabling an access control bypass. (CVE-2025-67480)<br /></span><span><br /></span><span>- Failure to escape the 'comma-separator' between multiple protection levels. (CVE-2025-67483)<br /></span><span><br /></span><span>- The 'style' attribute is allowed in client-side messages (jqueryMsg), enabling XSS. (CVE-2025-67481)<br /></span><span><br /></span><span>- A Lua segfault in unpack() leading to a denial of service. (CVE-2025-67482)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115329">https://www.tenable.com/plugins/was/115329</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.39.16 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115328</link>
            <guid>https://www.tenable.com/plugins/was/115328</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115328 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.39.16 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.39.16, 1.43.x prior to 1.43.6, 1.44.x prior to 1.44.3 or 1.45.x prior to 1.45.1. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- The xslt option is enabled by default in API format=xml responses. (CVE-2025-67484)<br /></span><span><br /></span><span>- Failure to escape the word-separator message in Special:ApiSandbox. (CVE-2025-67477)<br /></span><span><br /></span><span>- Failure to escape square brackets in autocomment links. (CVE-2025-67475)<br /></span><span><br /></span><span>- The importer's IP is used in case of an external revision author, leading to information disclosure. (CVE-2025-67476)<br /></span><span><br /></span><span>- Failure to always escape commas in mail encoded-words. (CVE-2025-67478)<br /></span><span><br /></span><span>- The Sanitizer does not disallow underscore and wide underscore in data-* attribute names. (CVE-2025-67479)<br /></span><span><br /></span><span>- Missing read permission check in ApiQueryRevisionsBase enabling an access control bypass. (CVE-2025-67480)<br /></span><span><br /></span><span>- Failure to escape the 'comma-separator' between multiple protection levels. (CVE-2025-67483)<br /></span><span><br /></span><span>- The 'style' attribute is allowed in client-side messages (jqueryMsg), enabling XSS. (CVE-2025-67481)<br /></span><span><br /></span><span>- A Lua segfault in unpack() leading to a denial of service. (CVE-2025-67482)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.39.16 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115328">https://www.tenable.com/plugins/was/115328</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.45.x < 1.45.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115327</link>
            <guid>https://www.tenable.com/plugins/was/115327</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115327 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.45.x < 1.45.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.7, 1.44.x prior to 1.44.4 or 1.45.x prior to 1.45.2. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Block UI elements in the 'tools' sidebar reveal the presence of an autoblocked IP. (CVE-2026-34092)<br /></span><span><br /></span><span>- RecentChanges entries expose suppressed content via generated log page HTML. (CVE-2026-34088)<br /></span><span><br /></span><span>- User localization is leaked by AbuseFilter + EventStream. (CVE-2026-34091)<br /></span><span><br /></span><span>- Suggested investigations do not handle suppressed usernames. (CVE-2026-34090)<br /></span><span><br /></span><span>- The Users API leaks whether privileged users have their user groups disabled for lack of 2FA. (CVE-2026-34087)<br /></span><span><br /></span><span>- Special:UserRights allows viewing user rights from a private wiki. (CVE-2026-34093)<br /></span><span><br /></span><span>- AbuseFilter misuses ::userCanBitfield, exposing access-controlled information. (CVE-2026-34086)<br /></span><span><br /></span><span>- The customized help link for the page protection indicator is relative to the subpage name. (CVE-2026-34094)<br /></span><span><br /></span><span>- A memory leak in Scribunto causes runJobs.php to run out of memory. (CVE-2026-34089)<br /></span><span><br /></span><span>- action=raw with a Special:Mypage subpage responds with text/html on a javascript request. (CVE-2026-34095)<br /></span><span><br /></span><span>- The Notifications (Echo) API can be used by any OAuth tool. (CVE-2026-5266)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.45.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115327">https://www.tenable.com/plugins/was/115327</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.44.x < 1.44.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115326</link>
            <guid>https://www.tenable.com/plugins/was/115326</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115326 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.44.x < 1.44.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.7, 1.44.x prior to 1.44.4 or 1.45.x prior to 1.45.2. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Block UI elements in the 'tools' sidebar reveal the presence of an autoblocked IP. (CVE-2026-34092)<br /></span><span><br /></span><span>- RecentChanges entries expose suppressed content via generated log page HTML. (CVE-2026-34088)<br /></span><span><br /></span><span>- User localization is leaked by AbuseFilter + EventStream. (CVE-2026-34091)<br /></span><span><br /></span><span>- Suggested investigations do not handle suppressed usernames. (CVE-2026-34090)<br /></span><span><br /></span><span>- The Users API leaks whether privileged users have their user groups disabled for lack of 2FA. (CVE-2026-34087)<br /></span><span><br /></span><span>- Special:UserRights allows viewing user rights from a private wiki. (CVE-2026-34093)<br /></span><span><br /></span><span>- AbuseFilter misuses ::userCanBitfield, exposing access-controlled information. (CVE-2026-34086)<br /></span><span><br /></span><span>- The customized help link for the page protection indicator is relative to the subpage name. (CVE-2026-34094)<br /></span><span><br /></span><span>- A memory leak in Scribunto causes runJobs.php to run out of memory. (CVE-2026-34089)<br /></span><span><br /></span><span>- action=raw with a Special:Mypage subpage responds with text/html on a javascript request. (CVE-2026-34095)<br /></span><span><br /></span><span>- The Notifications (Echo) API can be used by any OAuth tool. (CVE-2026-5266)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.44.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115326">https://www.tenable.com/plugins/was/115326</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.43.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115325</link>
            <guid>https://www.tenable.com/plugins/was/115325</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115325 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.43.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.7, 1.44.x prior to 1.44.4 or 1.45.x prior to 1.45.2. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- Block UI elements in the 'tools' sidebar reveal the presence of an autoblocked IP. (CVE-2026-34092)<br /></span><span><br /></span><span>- RecentChanges entries expose suppressed content via generated log page HTML. (CVE-2026-34088)<br /></span><span><br /></span><span>- User localization is leaked by AbuseFilter + EventStream. (CVE-2026-34091)<br /></span><span><br /></span><span>- Suggested investigations do not handle suppressed usernames. (CVE-2026-34090)<br /></span><span><br /></span><span>- The Users API leaks whether privileged users have their user groups disabled for lack of 2FA. (CVE-2026-34087)<br /></span><span><br /></span><span>- Special:UserRights allows viewing user rights from a private wiki. (CVE-2026-34093)<br /></span><span><br /></span><span>- AbuseFilter misuses ::userCanBitfield, exposing access-controlled information. (CVE-2026-34086)<br /></span><span><br /></span><span>- The customized help link for the page protection indicator is relative to the subpage name. (CVE-2026-34094)<br /></span><span><br /></span><span>- A memory leak in Scribunto causes runJobs.php to run out of memory. (CVE-2026-34089)<br /></span><span><br /></span><span>- action=raw with a Special:Mypage subpage responds with text/html on a javascript request. (CVE-2026-34095)<br /></span><span><br /></span><span>- The Notifications (Echo) API can be used by any OAuth tool. (CVE-2026-5266)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115325">https://www.tenable.com/plugins/was/115325</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.45.x < 1.45.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115324</link>
            <guid>https://www.tenable.com/plugins/was/115324</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115324 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.45.x < 1.45.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.9, 1.44.x prior to 1.44.6 or 1.45.x prior to 1.45.4. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- LogItem insecure deserialization enabling an arbitrary file write and remote code execution (RCE) via crafted XML during log imports. (CVE-2026-58025)<br /></span><span><br /></span><span>- ApiQueryUsers leaks the status of private user conditions. (CVE-2026-58036)<br /></span><span><br /></span><span>- User JavaScript is allowed in pretty-print API responses. (CVE-2026-58028)<br /></span><span><br /></span><span>- Rev-deleted usernames are exposed in author queries. (CVE-2026-58033)<br /></span><span><br /></span><span>- API error messages with formatversion=1 are treated as text. (CVE-2026-58032)<br /></span><span><br /></span><span>- Transcluded titles are not correctly restricted to includable titles. (CVE-2026-58026)<br /></span><span><br /></span><span>- Insufficient restriction of user lookups in ApiUserrights across interwikis. (CVE-2026-58024)<br /></span><span><br /></span><span>- Insufficient editmyprivateinfo validation when editing private info. (CVE-2026-58029)<br /></span><span><br /></span><span>- The LogFormatter raw parameter outputs raw HTML. (CVE-2026-58037)<br /></span><span><br /></span><span>- AbuseFilter exposes hit counts for protected filters in the API. (CVE-2026-58027)<br /></span><span><br /></span><span>- SyntaxHighlight_GeSHi does not escape linelinks before Pygments processing. (CVE-2026-58030)<br /></span><span><br /></span><span>- EasyTimeline script injection via TextData. (CVE-2026-8857)<br /></span><span><br /></span><span>- Timeline generated SVG stored XSS. (CVE-2026-58038)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.45.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115324">https://www.tenable.com/plugins/was/115324</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki 1.44.x < 1.44.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115323</link>
            <guid>https://www.tenable.com/plugins/was/115323</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115323 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki 1.44.x < 1.44.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.9, 1.44.x prior to 1.44.6 or 1.45.x prior to 1.45.4. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- LogItem insecure deserialization enabling an arbitrary file write and remote code execution (RCE) via crafted XML during log imports. (CVE-2026-58025)<br /></span><span><br /></span><span>- ApiQueryUsers leaks the status of private user conditions. (CVE-2026-58036)<br /></span><span><br /></span><span>- User JavaScript is allowed in pretty-print API responses. (CVE-2026-58028)<br /></span><span><br /></span><span>- Rev-deleted usernames are exposed in author queries. (CVE-2026-58033)<br /></span><span><br /></span><span>- API error messages with formatversion=1 are treated as text. (CVE-2026-58032)<br /></span><span><br /></span><span>- Transcluded titles are not correctly restricted to includable titles. (CVE-2026-58026)<br /></span><span><br /></span><span>- Insufficient restriction of user lookups in ApiUserrights across interwikis. (CVE-2026-58024)<br /></span><span><br /></span><span>- Insufficient editmyprivateinfo validation when editing private info. (CVE-2026-58029)<br /></span><span><br /></span><span>- The LogFormatter raw parameter outputs raw HTML. (CVE-2026-58037)<br /></span><span><br /></span><span>- AbuseFilter exposes hit counts for protected filters in the API. (CVE-2026-58027)<br /></span><span><br /></span><span>- SyntaxHighlight_GeSHi does not escape linelinks before Pygments processing. (CVE-2026-58030)<br /></span><span><br /></span><span>- EasyTimeline script injection via TextData. (CVE-2026-8857)<br /></span><span><br /></span><span>- Timeline generated SVG stored XSS. (CVE-2026-58038)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.44.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115323">https://www.tenable.com/plugins/was/115323</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MediaWiki < 1.43.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115322</link>
            <guid>https://www.tenable.com/plugins/was/115322</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115322 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>MediaWiki < 1.43.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.9, 1.44.x prior to 1.44.6 or 1.45.x prior to 1.45.4. It is, therefore, affected by a number of vulnerabilities as follows.<br /></span><span><br /></span><span>- LogItem insecure deserialization enabling an arbitrary file write and remote code execution (RCE) via crafted XML during log imports. (CVE-2026-58025)<br /></span><span><br /></span><span>- ApiQueryUsers leaks the status of private user conditions. (CVE-2026-58036)<br /></span><span><br /></span><span>- User JavaScript is allowed in pretty-print API responses. (CVE-2026-58028)<br /></span><span><br /></span><span>- Rev-deleted usernames are exposed in author queries. (CVE-2026-58033)<br /></span><span><br /></span><span>- API error messages with formatversion=1 are treated as text. (CVE-2026-58032)<br /></span><span><br /></span><span>- Transcluded titles are not correctly restricted to includable titles. (CVE-2026-58026)<br /></span><span><br /></span><span>- Insufficient restriction of user lookups in ApiUserrights across interwikis. (CVE-2026-58024)<br /></span><span><br /></span><span>- Insufficient editmyprivateinfo validation when editing private info. (CVE-2026-58029)<br /></span><span><br /></span><span>- The LogFormatter raw parameter outputs raw HTML. (CVE-2026-58037)<br /></span><span><br /></span><span>- AbuseFilter exposes hit counts for protected filters in the API. (CVE-2026-58027)<br /></span><span><br /></span><span>- SyntaxHighlight_GeSHi does not escape linelinks before Pygments processing. (CVE-2026-58030)<br /></span><span><br /></span><span>- EasyTimeline script injection via TextData. (CVE-2026-8857)<br /></span><span><br /></span><span>- Timeline generated SVG stored XSS. (CVE-2026-58038)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MediaWiki version 1.43.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115322">https://www.tenable.com/plugins/was/115322</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Hashicorp Consul API Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/115321</link>
            <guid>https://www.tenable.com/plugins/was/115321</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115321 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Hashicorp Consul API Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>HashiCorp Consul exposes its HTTP API and Web UI without authentication. When ACLs are not enabled, a remote unauthenticated attacker can read the service catalog, nodes, and key/value store (which may contain secrets), and register or deregister services.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Hashicorp Consul API interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115321">https://www.tenable.com/plugins/was/115321</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.7.3 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115320</link>
            <guid>https://www.tenable.com/plugins/was/115320</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115320 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.7.3 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Langflow running on the remote host is prior to 1.7.3. It is, therefore, affected by a remote code execution through 'validate_code() exec()'.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.7.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115320">https://www.tenable.com/plugins/was/115320</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Oracle E-Business Suite SQLNet Log File Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115319</link>
            <guid>https://www.tenable.com/plugins/was/115319</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115319 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Oracle E-Business Suite SQLNet Log File Disclosure<br /></span>
      <h3>Description</h3>
      <span>Oracle E-Business Suite (EBS) exposes an Oracle Net (SQL*Net) log file, `sqlnet.log`, under a web-accessible `bin` directory (for example, `/OA_HTML/bin/sqlnet.log` or `/html/bin/sqlnet.log`). When this file is accessible without authentication, it discloses Oracle Net connection details such as the `DESCRIPTION=` connect descriptors and `USER=` entries, which reveal internal host names, service names, ports, and database account names.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can retrieve this file to map the internal database topology and enumerate valid account and service names. This information can be leveraged to facilitate further targeted attacks against the Oracle E-Business Suite environment and its backing database services.<br /></span>
      <h3>Solution</h3>
      <span>Restrict public access to the `sqlnet.log` file and its containing `bin` directory at the web server or reverse proxy layer, and apply Oracle's E-Business Suite security hardening guidance. Oracle Net log files should not be served from web-accessible locations; relocate them outside the document root where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115319">https://www.tenable.com/plugins/was/115319</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Oracle E-Business Suite Credentials Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115318</link>
            <guid>https://www.tenable.com/plugins/was/115318</guid>
            <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115318 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Oracle E-Business Suite Credentials Disclosure<br /></span>
      <h3>Description</h3>
      <span>Oracle E-Business Suite (EBS) exposes a JTF (Java Technology Foundation) repository descriptor file, `jtfwrepo.xml`, under the `/OA_HTML` virtual directory. When this file is accessible without authentication, it discloses repository configuration including cleartext credentials contained in the `password=` attributes of its `<PUSR_LIST>` elements.<br /></span><span><br /></span><span>An unauthenticated, remote attacker can retrieve this file to obtain valid credentials for the Oracle E-Business Suite environment. These credentials may be leveraged to authenticate to the application or backing services, leading to further sensitive information disclosure and potential compromise of the EBS instance.<br /></span>
      <h3>Solution</h3>
      <span>Restrict public access to the `/OA_HTML/jtfwrepo.xml` file at the web server or reverse proxy layer, and apply Oracle's E-Business Suite security hardening guidance. Any credentials exposed through this file must be considered compromised and rotated.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115318">https://www.tenable.com/plugins/was/115318</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 7.0.x < 7.0.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115317</link>
            <guid>https://www.tenable.com/plugins/was/115317</guid>
            <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115317 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 7.0.x < 7.0.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution<br /></span><span><br /></span><span>- Facilitated SQL injection vulnerability in the `author__not_in` parameter of `WP_Query`<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 7.0.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115317">https://www.tenable.com/plugins/was/115317</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.9.x < 6.9.5 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115316</link>
            <guid>https://www.tenable.com/plugins/was/115316</guid>
            <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115316 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.9.x < 6.9.5 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution<br /></span><span><br /></span><span>- Facilitated SQL injection vulnerability in the `author__not_in` parameter of `WP_Query`<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.9.5 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115316">https://www.tenable.com/plugins/was/115316</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.9.x < 6.9.5 / 7.0.x < 7.0.2 SQL Injection (wp2shell)]]></title>
            <link>https://www.tenable.com/plugins/was/115315</link>
            <guid>https://www.tenable.com/plugins/was/115315</guid>
            <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115315 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.9.x < 6.9.5 / 7.0.x < 7.0.2 SQL Injection (wp2shell)<br /></span>
      <h3>Description</h3>
      <span>WordPress versions 6.9.x < 6.9.5 and 7.0.x < 7.0.2 are vulnerable to a REST API batch-route confusion weakness, which combined with an SQL injection issue leads to Remote Code Execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to WordPress 6.9.5, 7.10.1 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115315">https://www.tenable.com/plugins/was/115315</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx < 1.30.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115314</link>
            <guid>https://www.tenable.com/plugins/was/115314</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115314 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx < 1.30.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Nginx running on the remote host is prior to 1.30.4 or 1.31.x prior to 1.31.3. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A heap-based buffer overflow vulnerability exists in the map directive when regex matching is used and a string expression references the map's regex capture variables before referencing the map output variable, or when a non-cacheable variable is used in a string expression under certain conditions. An unauthenticated attacker can exploit this to cause a denial of service or potential code execution on systems with ASLR disabled. (CVE-2026-42533)<br /></span><span><br /></span><span>- An uninitialized memory access vulnerability exists in the ngx_http_slice_module module when the slice directive and unnamed regex captures are configured or when a background cache update occurs. An unauthenticated attacker can exploit this to cause limited disclosure of memory or a restart of the NGINX worker process. (CVE-2026-60005)<br /></span><span><br /></span><span>- A use-after-free vulnerability exists in the ngx_http_ssi_module module when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. An attacker with man-in-the-middle ability to control responses from an upstream server can exploit this to cause limited modification of memory or a restart of the NGINX worker process. (CVE-2026-56434)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.30.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115314">https://www.tenable.com/plugins/was/115314</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx 1.31.x < 1.31.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115313</link>
            <guid>https://www.tenable.com/plugins/was/115313</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115313 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx 1.31.x < 1.31.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Nginx running on the remote host is prior to 1.30.4 or 1.31.x prior to 1.31.3. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A heap-based buffer overflow vulnerability exists in the map directive when regex matching is used and a string expression references the map's regex capture variables before referencing the map output variable, or when a non-cacheable variable is used in a string expression under certain conditions. An unauthenticated attacker can exploit this to cause a denial of service or potential code execution on systems with ASLR disabled. (CVE-2026-42533)<br /></span><span><br /></span><span>- An uninitialized memory access vulnerability exists in the ngx_http_slice_module module when the slice directive and unnamed regex captures are configured or when a background cache update occurs. An unauthenticated attacker can exploit this to cause limited disclosure of memory or a restart of the NGINX worker process. (CVE-2026-60005)<br /></span><span><br /></span><span>- A use-after-free vulnerability exists in the ngx_http_ssi_module module when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. An attacker with man-in-the-middle ability to control responses from an upstream server can exploit this to cause limited modification of memory or a restart of the NGINX worker process. (CVE-2026-56434)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.31.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115313">https://www.tenable.com/plugins/was/115313</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.5.x < 10.5.12 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115312</link>
            <guid>https://www.tenable.com/plugins/was/115312</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115312 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.5.x < 10.5.12 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A PHP object injection vulnerability exists in JSON:API where an attacker with write permissions could inject a malicious payload in certain circumstances when entity reference fields store serialized properties, potentially resulting in PHP object injection. (CVE-2026-55803)<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site, which an attacker could leverage to achieve remote code execution or other attacks if the application deserializes untrusted data. (CVE-2026-55804)<br /></span><span><br /></span><span>- The rebuild.php front controller fails to properly validate the Host header against trusted host patterns, potentially enabling cache poisoning or open redirects to attacker-controlled domains. (CVE-2026-55806)<br /></span><span><br /></span><span>- The Media module's oEmbed URL discovery mechanism can be exploited to trick Drupal into making server-side requests to arbitrary URLs, resulting in server-side request forgery (SSRF). (CVE-2026-55807)<br /></span><span><br /></span><span>- The JSON:API and REST modules validate file extensions but not MIME types during image uploads, potentially allowing files to be served with unexpected MIME types and enabling cross-site scripting (XSS) or other unexpected behavior on misconfigured servers. (CVE-2026-55808)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.5.12 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115312">https://www.tenable.com/plugins/was/115312</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.6.x < 10.6.11 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115311</link>
            <guid>https://www.tenable.com/plugins/was/115311</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115311 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.6.x < 10.6.11 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A PHP object injection vulnerability exists in JSON:API where an attacker with write permissions could inject a malicious payload in certain circumstances when entity reference fields store serialized properties, potentially resulting in PHP object injection. (CVE-2026-55803)<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site, which an attacker could leverage to achieve remote code execution or other attacks if the application deserializes untrusted data. (CVE-2026-55804)<br /></span><span><br /></span><span>- The rebuild.php front controller fails to properly validate the Host header against trusted host patterns, potentially enabling cache poisoning or open redirects to attacker-controlled domains. (CVE-2026-55806)<br /></span><span><br /></span><span>- The Media module's oEmbed URL discovery mechanism can be exploited to trick Drupal into making server-side requests to arbitrary URLs, resulting in server-side request forgery (SSRF). (CVE-2026-55807)<br /></span><span><br /></span><span>- The JSON:API and REST modules validate file extensions but not MIME types during image uploads, potentially allowing files to be served with unexpected MIME types and enabling cross-site scripting (XSS) or other unexpected behavior on misconfigured servers. (CVE-2026-55808)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.6.11 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115311">https://www.tenable.com/plugins/was/115311</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.2.x < 11.2.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115310</link>
            <guid>https://www.tenable.com/plugins/was/115310</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115310 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.2.x < 11.2.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A PHP object injection vulnerability exists in JSON:API where an attacker with write permissions could inject a malicious payload in certain circumstances when entity reference fields store serialized properties, potentially resulting in PHP object injection. (CVE-2026-55803)<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site, which an attacker could leverage to achieve remote code execution or other attacks if the application deserializes untrusted data. (CVE-2026-55804)<br /></span><span><br /></span><span>- The rebuild.php front controller fails to properly validate the Host header against trusted host patterns, potentially enabling cache poisoning or open redirects to attacker-controlled domains. (CVE-2026-55806)<br /></span><span><br /></span><span>- The Media module's oEmbed URL discovery mechanism can be exploited to trick Drupal into making server-side requests to arbitrary URLs, resulting in server-side request forgery (SSRF). (CVE-2026-55807)<br /></span><span><br /></span><span>- The JSON:API and REST modules validate file extensions but not MIME types during image uploads, potentially allowing files to be served with unexpected MIME types and enabling cross-site scripting (XSS) or other unexpected behavior on misconfigured servers. (CVE-2026-55808)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.2.14 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115310">https://www.tenable.com/plugins/was/115310</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.3.x < 11.3.12 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115309</link>
            <guid>https://www.tenable.com/plugins/was/115309</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115309 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.3.x < 11.3.12 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A PHP object injection vulnerability exists in JSON:API where an attacker with write permissions could inject a malicious payload in certain circumstances when entity reference fields store serialized properties, potentially resulting in PHP object injection. (CVE-2026-55803)<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that could be exploitable when an insecure deserialization vulnerability exists on the site, which an attacker could leverage to achieve remote code execution or other attacks if the application deserializes untrusted data. (CVE-2026-55804)<br /></span><span><br /></span><span>- The rebuild.php front controller fails to properly validate the Host header against trusted host patterns, potentially enabling cache poisoning or open redirects to attacker-controlled domains. (CVE-2026-55806)<br /></span><span><br /></span><span>- The Media module's oEmbed URL discovery mechanism can be exploited to trick Drupal into making server-side requests to arbitrary URLs, resulting in server-side request forgery (SSRF). (CVE-2026-55807)<br /></span><span><br /></span><span>- The JSON:API and REST modules validate file extensions but not MIME types during image uploads, potentially allowing files to be served with unexpected MIME types and enabling cross-site scripting (XSS) or other unexpected behavior on misconfigured servers. (CVE-2026-55808)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.3.12 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115309">https://www.tenable.com/plugins/was/115309</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.6.x < 10.6.13 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115308</link>
            <guid>https://www.tenable.com/plugins/was/115308</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115308 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.6.x < 10.6.13 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- The Image module fails to adequately validate access permissions for image style derivatives when served through non-private file streams, potentially resulting in information disclosure when Drupal is configured to use a contributed non-core file scheme. (CVE-2026-15916)<br /></span><span><br /></span><span>- The XSS filter in Drupal core fails to sufficiently sanitize certain HTMX attributes, allowing an attacker with the ability to insert HTML to trigger a cross-site scripting (XSS) attack. (CVE-2026-15917)<br /></span><span><br /></span><span>- The Layout Builder module fails to sufficiently sanitize block labels in certain scenarios where both the attacker and target have access to Layout Builder editing, which can lead to a cross-site scripting (XSS) vulnerability. (CVE-2026-55805)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.6.13 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115308">https://www.tenable.com/plugins/was/115308</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.3.x < 11.3.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115307</link>
            <guid>https://www.tenable.com/plugins/was/115307</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115307 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.3.x < 11.3.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- The Image module fails to adequately validate access permissions for image style derivatives when served through non-private file streams, potentially resulting in information disclosure when Drupal is configured to use a contributed non-core file scheme. (CVE-2026-15916)<br /></span><span><br /></span><span>- The XSS filter in Drupal core fails to sufficiently sanitize certain HTMX attributes, allowing an attacker with the ability to insert HTML to trigger a cross-site scripting (XSS) attack. (CVE-2026-15917)<br /></span><span><br /></span><span>- The Layout Builder module fails to sufficiently sanitize block labels in certain scenarios where both the attacker and target have access to Layout Builder editing, which can lead to a cross-site scripting (XSS) vulnerability. (CVE-2026-55805)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.3.14 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115307">https://www.tenable.com/plugins/was/115307</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.4.x < 11.4.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115306</link>
            <guid>https://www.tenable.com/plugins/was/115306</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115306 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.4.x < 11.4.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- The Image module fails to adequately validate access permissions for image style derivatives when served through non-private file streams, potentially resulting in information disclosure when Drupal is configured to use a contributed non-core file scheme. (CVE-2026-15916)<br /></span><span><br /></span><span>- The XSS filter in Drupal core fails to sufficiently sanitize certain HTMX attributes, allowing an attacker with the ability to insert HTML to trigger a cross-site scripting (XSS) attack. (CVE-2026-15917)<br /></span><span><br /></span><span>- The Layout Builder module fails to sufficiently sanitize block labels in certain scenarios where both the attacker and target have access to Layout Builder editing, which can lead to a cross-site scripting (XSS) vulnerability. (CVE-2026-55805)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.4.4 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115306">https://www.tenable.com/plugins/was/115306</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.120 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115305</link>
            <guid>https://www.tenable.com/plugins/was/115305</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115305 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.120 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.120, 10.1.0-M1 prior to 10.1.57 or 11.0.0-M1 prior to 11.0.24. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The requirements to securely configure the EncryptInterceptor were not clearly documented. (CVE-2026-59084)<br /></span><span><br /></span><span>- Incorrect decoding of '+' in rewritten URIs to a single space could allow security control bypass for some configurations. (CVE-2026-59083)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.120 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115305">https://www.tenable.com/plugins/was/115305</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.57 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115304</link>
            <guid>https://www.tenable.com/plugins/was/115304</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115304 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.57 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.120, 10.1.0-M1 prior to 10.1.57 or 11.0.0-M1 prior to 11.0.24. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The requirements to securely configure the EncryptInterceptor were not clearly documented. (CVE-2026-59084)<br /></span><span><br /></span><span>- Incorrect decoding of '+' in rewritten URIs to a single space could allow security control bypass for some configurations. (CVE-2026-59083)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.57 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115304">https://www.tenable.com/plugins/was/115304</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.24 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115303</link>
            <guid>https://www.tenable.com/plugins/was/115303</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115303 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.24 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.120, 10.1.0-M1 prior to 10.1.57 or 11.0.0-M1 prior to 11.0.24. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The requirements to securely configure the EncryptInterceptor were not clearly documented. (CVE-2026-59084)<br /></span><span><br /></span><span>- Incorrect decoding of '+' in rewritten URIs to a single space could allow security control bypass for some configurations. (CVE-2026-59083)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.24 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115303">https://www.tenable.com/plugins/was/115303</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JSON Web Token Signature Bypass via Unvalidated x5c Parameter]]></title>
            <link>https://www.tenable.com/plugins/was/115302</link>
            <guid>https://www.tenable.com/plugins/was/115302</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115302 with High Severity</p>
      <h3>Synopsis</h3>
      <span>JSON Web Token Signature Bypass via Unvalidated x5c Parameter<br /></span>
      <h3>Description</h3>
      <span>JSON Web Tokens can be signed to protect against data tampering. The 'x5c' (X.509 Certificate Chain) header parameter can embed the certificate whose public key must be used to verify the token signature.<br /></span><span><br /></span><span>When the application trusts the certificate embedded in the 'x5c' header instead of a key it controls, an attacker can embed a self-signed certificate in the token header and sign a forged token with the matching private key, which will be accepted by the application.<br /></span><span><br /></span><span>Depending on the token usage, attackers could leverage this vulnerability to forge valid tokens and impersonate other users, or gain further privileges.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the application validates every JSON Web Token against a trusted key it controls. Header parameters that influence key resolution (kid, jwk, jku, x5u, x5c) must never be trusted as-is: pin verification to a known key or a strict allow-list, reject tokens whose header selects an unexpected key, and sanitize any value used to look up or load a key.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115302">https://www.tenable.com/plugins/was/115302</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JSON Web Token Signature Bypass via Unvalidated jwk Parameter]]></title>
            <link>https://www.tenable.com/plugins/was/115301</link>
            <guid>https://www.tenable.com/plugins/was/115301</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115301 with High Severity</p>
      <h3>Synopsis</h3>
      <span>JSON Web Token Signature Bypass via Unvalidated jwk Parameter<br /></span>
      <h3>Description</h3>
      <span>JSON Web Tokens can be signed to protect against data tampering. The 'jwk' (JSON Web Key) header parameter can embed the public key that must be used to verify the token signature.<br /></span><span><br /></span><span>When the application trusts the key embedded in the 'jwk' header instead of a key it controls, an attacker can embed their own public key in the token header and sign a forged token with the matching private key, which will be accepted by the application.<br /></span><span><br /></span><span>Depending on the token usage, attackers could leverage this vulnerability to forge valid tokens and impersonate other users, or gain further privileges.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the application validates every JSON Web Token against a trusted key it controls. Header parameters that influence key resolution (kid, jwk, jku, x5u, x5c) must never be trusted as-is: pin verification to a known key or a strict allow-list, reject tokens whose header selects an unexpected key, and sanitize any value used to look up or load a key.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115301">https://www.tenable.com/plugins/was/115301</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JSON Web Token Signature Bypass via kid Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/115300</link>
            <guid>https://www.tenable.com/plugins/was/115300</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115300 with High Severity</p>
      <h3>Synopsis</h3>
      <span>JSON Web Token Signature Bypass via kid Path Traversal<br /></span>
      <h3>Description</h3>
      <span>JSON Web Tokens can be signed to protect against data tampering. The 'kid' (Key ID) header parameter is sometimes used by applications as a path to a file whose content is used as the key to verify the token signature.<br /></span><span><br /></span><span>When the 'kid' value is not validated, an attacker can use path traversal to point it to a predictable file with known content, such as an empty file (/dev/null). The attacker can then sign a forged token with the corresponding key (an empty key for an empty file), which will be accepted by the application.<br /></span><span><br /></span><span>Depending on the token usage, attackers could leverage this vulnerability to forge valid tokens and impersonate other users, or gain further privileges.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the application validates every JSON Web Token against a trusted key it controls. Header parameters that influence key resolution (kid, jwk, jku, x5u, x5c) must never be trusted as-is: pin verification to a known key or a strict allow-list, reject tokens whose header selects an unexpected key, and sanitize any value used to look up or load a key.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115300">https://www.tenable.com/plugins/was/115300</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JSON Web Token Signature Bypass via kid SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115299</link>
            <guid>https://www.tenable.com/plugins/was/115299</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115299 with High Severity</p>
      <h3>Synopsis</h3>
      <span>JSON Web Token Signature Bypass via kid SQL Injection<br /></span>
      <h3>Description</h3>
      <span>JSON Web Tokens can be signed to protect against data tampering. The 'kid' (Key ID) header parameter is commonly used by applications to look up the key that must be used to verify the token signature.<br /></span><span><br /></span><span>When the 'kid' value is concatenated into a SQL query without proper sanitization, an attacker can inject a payload that forces the key lookup to return a value they control. The attacker can then sign a forged token with that value, which will be accepted by the application.<br /></span><span><br /></span><span>Depending on the token usage, attackers could leverage this vulnerability to forge valid tokens and impersonate other users, or gain further privileges.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the application validates every JSON Web Token against a trusted key it controls. Header parameters that influence key resolution (kid, jwk, jku, x5u, x5c) must never be trusted as-is: pin verification to a known key or a strict allow-list, reject tokens whose header selects an unexpected key, and sanitize any value used to look up or load a key.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115299">https://www.tenable.com/plugins/was/115299</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! Balbooa Forms < 2.4.1 Arbitrary Files Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115298</link>
            <guid>https://www.tenable.com/plugins/was/115298</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115298 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! Balbooa Forms < 2.4.1 Arbitrary Files Upload<br /></span>
      <h3>Description</h3>
      <span>Balbooa Forms for Joomla! before 2.4.1 allows unauthenticated attackers to upload arbitrary files via the component's file upload functionality, leading to remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! Balbooa Forms version 2.4.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115298">https://www.tenable.com/plugins/was/115298</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! iCagenda < 4.0.8 Arbitrary Files Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115297</link>
            <guid>https://www.tenable.com/plugins/was/115297</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115297 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! iCagenda < 4.0.8 Arbitrary Files Upload<br /></span>
      <h3>Description</h3>
      <span>iCagenda for Joomla! before 4.0.8 allows unauthenticated attackers to upload arbitrary files via the component's file upload functionality, leading to remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! iCagenda version 4.0.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115297">https://www.tenable.com/plugins/was/115297</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ninja Forms - File Uploads Plugin for WordPress < 3.3.30 Unauthenticated Arbitrary File Read]]></title>
            <link>https://www.tenable.com/plugins/was/115296</link>
            <guid>https://www.tenable.com/plugins/was/115296</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115296 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Ninja Forms - File Uploads Plugin for WordPress < 3.3.30 Unauthenticated Arbitrary File Read<br /></span>
      <h3>Description</h3>
      <span>The WordPress Ninja Forms - File Uploads Plugin installed on the remote host is affected by an unauthenticated arbitrary file read via the attach_files() function.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ninja Forms - File Uploads Plugin for WordPress 3.3.30 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115296">https://www.tenable.com/plugins/was/115296</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe ColdFusion Remote Development Service Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/115295</link>
            <guid>https://www.tenable.com/plugins/was/115295</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115295 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe ColdFusion Remote Development Service Path Traversal<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe ColdFusion instance has its Remote Development Service (RDS) enabled without authentication and is affected by a path traversal vulnerability in the RDS FILEIO handler exposed through the /CFIDE/main/ide.cfm endpoint. A remote, unauthenticated attacker can leverage this issue to read and write arbitrary files on the underlying file system, ultimately leading to arbitrary code execution in the context of the ColdFusion service account.<br /></span><span><br /></span><span>Adobe ColdFusion 2025 (Update 9 and earlier) and 2023 (Update 20 and earlier) are affected.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Adobe ColdFusion 2025 Update 10, ColdFusion 2023 Update 21 or later. If RDS is not required, ensure it is disabled and password protected.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115295">https://www.tenable.com/plugins/was/115295</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 6.x < 6.1.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115294</link>
            <guid>https://www.tenable.com/plugins/was/115294</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115294 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 6.x < 6.1.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.x prior to 5.4.7, or 6.x prior to 6.1.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- An improper access check allows privileged users to overwrite media files without editing permissions in com_media webservice endpoints. (CVE-2026-48947)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in the com_contact vcf download component. (CVE-2026-48948)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in MFA method management. (CVE-2026-48949)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in com_templates. (CVE-2026-48950)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in various modalreturn layouts. (CVE-2026-48951)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in com_installer. (CVE-2026-48952)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in the generic image output layout. (CVE-2026-48953)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists through language overrides. (CVE-2026-48954)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_workflow. (CVE-2026-48955)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_modules. (CVE-2026-48956)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_privacy webservice endpoints. (CVE-2026-48957)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_fields webservice endpoints. (CVE-2026-48958)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! version 6.1.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115294">https://www.tenable.com/plugins/was/115294</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 5.x < 5.4.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115293</link>
            <guid>https://www.tenable.com/plugins/was/115293</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115293 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 5.x < 5.4.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.x prior to 5.4.7, or 6.x prior to 6.1.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- An improper access check allows privileged users to overwrite media files without editing permissions in com_media webservice endpoints. (CVE-2026-48947)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in the com_contact vcf download component. (CVE-2026-48948)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in MFA method management. (CVE-2026-48949)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in com_templates. (CVE-2026-48950)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in various modalreturn layouts. (CVE-2026-48951)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in com_installer. (CVE-2026-48952)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists in the generic image output layout. (CVE-2026-48953)<br /></span><span><br /></span><span>- A cross-site scripting (XSS) vulnerability exists through language overrides. (CVE-2026-48954)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_workflow. (CVE-2026-48955)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_modules. (CVE-2026-48956)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_privacy webservice endpoints. (CVE-2026-48957)<br /></span><span><br /></span><span>- An incorrect access control vulnerability exists in com_fields webservice endpoints. (CVE-2026-48958)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! version 5.4.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115293">https://www.tenable.com/plugins/was/115293</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! SP Page Builder < 6.6.2 Arbitrary Files Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115292</link>
            <guid>https://www.tenable.com/plugins/was/115292</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115292 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! SP Page Builder < 6.6.2 Arbitrary Files Upload<br /></span>
      <h3>Description</h3>
      <span>SP Page Builder for Joomla! before 6.6.2 allows unauthenticated attackers to upload arbitrary files via the component's file upload functionality, leading to remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Joomla! SP Page Builder version 6.6.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115292">https://www.tenable.com/plugins/was/115292</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.5.x < 8.5.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115291</link>
            <guid>https://www.tenable.com/plugins/was/115291</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115291 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.5.x < 8.5.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.32, 8.3.x prior to 8.3.32, 8.4.x to 8.4.23 or 8.5.x prior to 8.5.8. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A heap buffer overflow vulnerability exists in the OpenSSL extension due to incorrect buffer allocation in openssl_encrypt() when using the AES-WRAP-PAD cipher, causing OpenSSL to write past allocated heap memory and leading to heap corruption or application crash. (CVE-2026-14355)<br /></span><span><br /></span><span>- A segfault vulnerability exists in the Streams extension in file_get_contents() when fetching an HTTPS URL with a proxy configured. (CVE-2026-12184)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.5.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115291">https://www.tenable.com/plugins/was/115291</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft SharePoint Server 2016 < 16.0.5552.1002 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115290</link>
            <guid>https://www.tenable.com/plugins/was/115290</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115290 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Microsoft SharePoint Server 2016 < 16.0.5552.1002 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Microsoft SharePoint application running on the remote host is affected by multiple vulnerabilities.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Microsoft SharePoint Server 2016 build 16.0.5552.1002 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115290">https://www.tenable.com/plugins/was/115290</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Microsoft SharePoint Server 2019 < 16.0.10417.20128 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115289</link>
            <guid>https://www.tenable.com/plugins/was/115289</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115289 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Microsoft SharePoint Server 2019 < 16.0.10417.20128 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Microsoft SharePoint application running on the remote host is affected by multiple vulnerabilities.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Microsoft SharePoint Server 2019 build 16.0.10417.20128 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115289">https://www.tenable.com/plugins/was/115289</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.4.x < 8.4.23 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115288</link>
            <guid>https://www.tenable.com/plugins/was/115288</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115288 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.4.x < 8.4.23 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.32, 8.3.x prior to 8.3.32, 8.4.x to 8.4.23 or 8.5.x prior to 8.5.8. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A heap buffer overflow vulnerability exists in the OpenSSL extension due to incorrect buffer allocation in openssl_encrypt() when using the AES-WRAP-PAD cipher, causing OpenSSL to write past allocated heap memory and leading to heap corruption or application crash. (CVE-2026-14355)<br /></span><span><br /></span><span>- A segfault vulnerability exists in the Streams extension in file_get_contents() when fetching an HTTPS URL with a proxy configured. (CVE-2026-12184)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.4.23 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115288">https://www.tenable.com/plugins/was/115288</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.3.x < 8.3.32 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115287</link>
            <guid>https://www.tenable.com/plugins/was/115287</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115287 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.3.x < 8.3.32 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.32, 8.3.x prior to 8.3.32, 8.4.x to 8.4.23 or 8.5.x prior to 8.5.8. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A heap buffer overflow vulnerability exists in the OpenSSL extension due to incorrect buffer allocation in openssl_encrypt() when using the AES-WRAP-PAD cipher, causing OpenSSL to write past allocated heap memory and leading to heap corruption or application crash. (CVE-2026-14355)<br /></span><span><br /></span><span>- A segfault vulnerability exists in the Streams extension in file_get_contents() when fetching an HTTPS URL with a proxy configured. (CVE-2026-12184)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.3.32 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115287">https://www.tenable.com/plugins/was/115287</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.2.x < 8.2.32 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115286</link>
            <guid>https://www.tenable.com/plugins/was/115286</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115286 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.2.x < 8.2.32 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.32, 8.3.x prior to 8.3.32, 8.4.x to 8.4.23 or 8.5.x prior to 8.5.8. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A heap buffer overflow vulnerability exists in the OpenSSL extension due to incorrect buffer allocation in openssl_encrypt() when using the AES-WRAP-PAD cipher, causing OpenSSL to write past allocated heap memory and leading to heap corruption or application crash. (CVE-2026-14355)<br /></span><span><br /></span><span>- A segfault vulnerability exists in the Streams extension in file_get_contents() when fetching an HTTPS URL with a proxy configured. (CVE-2026-12184)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.2.32 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115286">https://www.tenable.com/plugins/was/115286</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx < 1.30.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115285</link>
            <guid>https://www.tenable.com/plugins/was/115285</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115285 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx < 1.30.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.30.3 or 1.31.x prior to 1.31.2. It is, therefore, affected by the following issues :<br /></span><span><br /></span><span>- A Use-After-Free in the ngx_http_v3_module module allows a remote unauthenticated attacker to send a specially crafted HTTP/3 session that reopens a QPACK encoder stream, causing a worker process restart or, on systems with ASLR disabled, arbitrary code execution. (CVE-2026-42530)<br /></span><span><br /></span><span>- A heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules allows a remote unauthenticated attacker to send large headers during upstream request creation when proxy_http_version 2 or grpc_pass is used with ignore_invalid_headers off and large_client_header_buffers configured above 2 megabytes, causing a worker process restart or, on systems with ASLR disabled, arbitrary code execution. (CVE-2026-42055)<br /></span><span><br /></span><span>- A heap buffer over-read (CWE-125) in the ngx_http_charset_module module allows a remote unauthenticated attacker to cause limited memory disclosure or a worker process restart when content is served or proxied through a location block configured with both source_charset utf-8 and a charset conversion directive. (CVE-2026-48142)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.30.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115285">https://www.tenable.com/plugins/was/115285</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx 1.31.x < 1.31.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115284</link>
            <guid>https://www.tenable.com/plugins/was/115284</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115284 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx 1.31.x < 1.31.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.30.3 or 1.31.x prior to 1.31.2. It is, therefore, affected by the following issues :<br /></span><span><br /></span><span>- A Use-After-Free in the ngx_http_v3_module module allows a remote unauthenticated attacker to send a specially crafted HTTP/3 session that reopens a QPACK encoder stream, causing a worker process restart or, on systems with ASLR disabled, arbitrary code execution. (CVE-2026-42530)<br /></span><span><br /></span><span>- A heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules allows a remote unauthenticated attacker to send large headers during upstream request creation when proxy_http_version 2 or grpc_pass is used with ignore_invalid_headers off and large_client_header_buffers configured above 2 megabytes, causing a worker process restart or, on systems with ASLR disabled, arbitrary code execution. (CVE-2026-42055)<br /></span><span><br /></span><span>- A heap buffer over-read (CWE-125) in the ngx_http_charset_module module allows a remote unauthenticated attacker to cause limited memory disclosure or a worker process restart when content is served or proxied through a location block configured with both source_charset utf-8 and a charset conversion directive. (CVE-2026-48142)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.31.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115284">https://www.tenable.com/plugins/was/115284</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.119 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115283</link>
            <guid>https://www.tenable.com/plugins/was/115283</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115283 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.119 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.119, 10.1.0-M1 prior to 10.1.56 or 11.0.0-M1 prior to 11.0.23. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- If security constraints were specified for the default servlet, any method or method omission configured as part of the constraint was ignored. (CVE-2026-55956)<br /></span><span><br /></span><span>- Contrary to the documentation, the EncryptInterceptor was not protected against replay attacks. (CVE-2026-55955)<br /></span><span><br /></span><span>- Logic errors in the effective web.xml generation meant that neither special roles nor empty authorization constraints were included in the logged effective web.xml. (CVE-2026-55276)<br /></span><span><br /></span><span>- If an FFM connector was configured with invalid CRLs, the invalid CRLs were ignored meaning invalid certificates could be accepted. (CVE-2026-53434)<br /></span><span><br /></span><span>- If a request matched the first condition in an OR chain in the RewriteValve, subsequent non-OR conditions were skipped and the rewrite succeeded. (CVE-2026-53404)<br /></span><span><br /></span><span>- The use of wildcard property mapping resulted in some properties that were intended to be internal only being exposed to clients, allowing an XSS attack. (CVE-2026-50229)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.119 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115283">https://www.tenable.com/plugins/was/115283</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.56 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115282</link>
            <guid>https://www.tenable.com/plugins/was/115282</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115282 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.56 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.119, 10.1.0-M1 prior to 10.1.56 or 11.0.0-M1 prior to 11.0.23. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- If security constraints were specified for the default servlet, any method or method omission configured as part of the constraint was ignored. (CVE-2026-55956)<br /></span><span><br /></span><span>- Contrary to the documentation, the EncryptInterceptor was not protected against replay attacks. (CVE-2026-55955)<br /></span><span><br /></span><span>- Logic errors in the effective web.xml generation meant that neither special roles nor empty authorization constraints were included in the logged effective web.xml. (CVE-2026-55276)<br /></span><span><br /></span><span>- If an FFM connector was configured with invalid CRLs, the invalid CRLs were ignored meaning invalid certificates could be accepted. (CVE-2026-53434)<br /></span><span><br /></span><span>- If a request matched the first condition in an OR chain in the RewriteValve, subsequent non-OR conditions were skipped and the rewrite succeeded. (CVE-2026-53404)<br /></span><span><br /></span><span>- The use of wildcard property mapping resulted in some properties that were intended to be internal only being exposed to clients, allowing an XSS attack. (CVE-2026-50229)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.56 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115282">https://www.tenable.com/plugins/was/115282</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.23 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115281</link>
            <guid>https://www.tenable.com/plugins/was/115281</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115281 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.23 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.119, 10.1.0-M1 prior to 10.1.56 or 11.0.0-M1 prior to 11.0.23. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- If security constraints were specified for the default servlet, any method or method omission configured as part of the constraint was ignored. (CVE-2026-55956)<br /></span><span><br /></span><span>- Contrary to the documentation, the EncryptInterceptor was not protected against replay attacks. (CVE-2026-55955)<br /></span><span><br /></span><span>- Logic errors in the effective web.xml generation meant that neither special roles nor empty authorization constraints were included in the logged effective web.xml. (CVE-2026-55276)<br /></span><span><br /></span><span>- If an FFM connector was configured with invalid CRLs, the invalid CRLs were ignored meaning invalid certificates could be accepted. (CVE-2026-53434)<br /></span><span><br /></span><span>- If a request matched the first condition in an OR chain in the RewriteValve, subsequent non-OR conditions were skipped and the rewrite succeeded. (CVE-2026-53404)<br /></span><span><br /></span><span>- The use of wildcard property mapping resulted in some properties that were intended to be internal only being exposed to clients, allowing an XSS attack. (CVE-2026-50229)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.23 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115281">https://www.tenable.com/plugins/was/115281</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Cacti Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115280</link>
            <guid>https://www.tenable.com/plugins/was/115280</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115280 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Cacti Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Cacti running on the remote host is < 1.2.31. It is, therefore, affected by multiples vulnerabilities :<br /></span><span><br /></span><span>- An Unauthenticated LFI via graph_theme and rrdtool IPC serialization hardening<br /></span><span><br /></span><span>- An Unauthenticated SQL injection via rfilter RLIKE clause in graph_view.php<br /></span><span><br /></span><span>- An Unauthenticated SQL injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Cacti version 1.2.31 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115280">https://www.tenable.com/plugins/was/115280</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Flowise < 3.1.0 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115279</link>
            <guid>https://www.tenable.com/plugins/was/115279</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115279 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Flowise < 3.1.0 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Flowise running on the remote host is < 3.1.0. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A Remote Code Execution Vulnerability through Airtable Agent<br /></span><span><br /></span><span>- A Cypher Injection in GraphCypherQAChain<br /></span><span><br /></span><span>- A Path Traversal in Vector Store basePath<br /></span><span><br /></span><span>- A Password Reset Link Sent Over Unsecured HTTP<br /></span><span><br /></span><span>- A resetPassword Authentication Bypass Vulnerability<br /></span><span><br /></span><span>- A Mass Assignment in DocumentStore Create Endpoint<br /></span><span><br /></span><span>- An SSRF Protection Bypass via Direct node-fetch<br /></span><span><br /></span><span>- A CSV Agent Prompt Injection Remote Code Execution Vulnerability<br /></span><span><br /></span><span>- A Sensitive Information Disclosure through public chatflow endpoints<br /></span><span><br /></span><span>- A Credit Abuse through an unauthenticated TTS endpoint<br /></span><span><br /></span><span>- An SSRF through Flowise Execute Flow<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Flowise version 3.1.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115279">https://www.tenable.com/plugins/was/115279</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Flowise < 3.1.2 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115278</link>
            <guid>https://www.tenable.com/plugins/was/115278</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115278 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Flowise < 3.1.2 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Flowise running on the remote host is < 3.1.2. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An hardcoded CORS wildcard on TTS endpoint enables abuse from any webpage<br /></span><span><br /></span><span>- An RCE through Flowise MCP<br /></span><span><br /></span><span>- A Mass Assignment in Chatflow Update Endpoint<br /></span><span><br /></span><span>- A Mass Assignment in Tool Update Endpoint<br /></span><span><br /></span><span>- A Mass Assignment in Assistant Update Endpoint<br /></span><span><br /></span><span>- A Mass Assignment in Variable Update Endpoint<br /></span><span><br /></span><span>- A Mass Assignment in PUT /api/v1/user<br /></span><span><br /></span><span>- An Authenticated Host RCE via POST /api/v1/node-custom-function<br /></span><span><br /></span><span>- A Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint<br /></span><span><br /></span><span>- A Credential Data Leak<br /></span><span><br /></span><span>- Vector Store No Permission Checks<br /></span><span><br /></span><span>- CustomTemplate create+update mass-assignment<br /></span><span><br /></span><span>- Assistant create+update mass-assignment allows cross-workspace assistant takeover<br /></span><span><br /></span><span>- DatasetRow create+update mass-assignment<br /></span><span><br /></span><span>- Dataset create+update mass-assignment<br /></span><span><br /></span><span>- Evaluation create+update mass-assignment<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Flowise version 3.1.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115278">https://www.tenable.com/plugins/was/115278</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.9.0 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115277</link>
            <guid>https://www.tenable.com/plugins/was/115277</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115277 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.9.0 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Langflow running on the remote host is prior to 1.9.0. It is, therefore, affected by a multiples vulnerabilities :<br /></span><span><br /></span><span>- An Authenticated Code Execution in agentic assistant validation<br /></span><span><br /></span><span>- An Unauthenticated Remote Code Execution via public flow build endpoint<br /></span><span><br /></span><span>- A Path Traversal in knowledge bases API via bulk delete endpoint<br /></span><span><br /></span><span>- An Arbitrary File Write (RCE) through the V2 API<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.9.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115277">https://www.tenable.com/plugins/was/115277</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.9.1 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115276</link>
            <guid>https://www.tenable.com/plugins/was/115276</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115276 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.9.1 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Langflow running on the remote host is prior to 1.9.1. It is, therefore, affected by a multiples vulnerabilities :<br /></span><span><br /></span><span>- An Indirect Object Reference (IDOR) in /api/v1/responses that allows authenticated attacker to access another user's Flow<br /></span><span><br /></span><span>- An Unauthenticated file upload that an lead to a Denial Of Service (DoS)and information leak<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.9.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115276">https://www.tenable.com/plugins/was/115276</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.9.2 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115275</link>
            <guid>https://www.tenable.com/plugins/was/115275</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115275 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.9.2 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Langflow running on the remote host is prior to 1.9.2. It is, therefore, affected by a multiples vulnerabilities :<br /></span><span><br /></span><span>- An Unauthenticated RCE in Shareable Playgrounds<br /></span><span><br /></span><span>- An RCE through BaseFileComponent<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.9.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115275">https://www.tenable.com/plugins/was/115275</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Popup Maker Plugin for WordPress < 1.21.0 Stored Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115274</link>
            <guid>https://www.tenable.com/plugins/was/115274</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115274 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Popup Maker Plugin for WordPress < 1.21.0 Stored Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>The WordPress Popup Maker Plugin installed on the remote host is affected by a Stored Cross-Site Scripting.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Popup Maker Plugin for WordPress 1.21.0<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115274">https://www.tenable.com/plugins/was/115274</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[RequireJS < 2.3.7 Prototype Pollution]]></title>
            <link>https://www.tenable.com/plugins/was/115273</link>
            <guid>https://www.tenable.com/plugins/was/115273</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115273 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>RequireJS < 2.3.7 Prototype Pollution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, RequireJS is prior to 2.3.7. It is, therefore, affected by a prototype pollution vulnerability in the s.contexts._.configure function. An attacker can inject arbitrary properties through a crafted configuration object containing a __proto__ property, which may lead to denial of service, remote code execution, or cross-site scripting depending on the available gadgets. (CVE-2024-38999)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to RequireJS version 2.3.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115273">https://www.tenable.com/plugins/was/115273</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lodash < 4.17.23 Prototype Pollution]]></title>
            <link>https://www.tenable.com/plugins/was/115272</link>
            <guid>https://www.tenable.com/plugins/was/115272</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115272 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Lodash < 4.17.23 Prototype Pollution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Lodash is prior to 4.17.23. It is, therefore, affected by a prototype pollution vulnerability in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. (CVE-2025-13465)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Lodash version 4.17.23 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115272">https://www.tenable.com/plugins/was/115272</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Gravity SMTP Plugin for WordPress < 2.1.5 Sensitive Information Exposure]]></title>
            <link>https://www.tenable.com/plugins/was/115271</link>
            <guid>https://www.tenable.com/plugins/was/115271</guid>
            <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115271 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Gravity SMTP Plugin for WordPress < 2.1.5 Sensitive Information Exposure<br /></span>
      <h3>Description</h3>
      <span>The WordPress Gravity SMTP Plugin installed on the remote host is affected by an unauthenticated sensitive information exposure due to a REST API endpoint registered at '/wp-json/gravitysmtp/v1/tests/mock-data' with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. This makes it possible for unauthenticated attackers to retrieve detailed system configuration data including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and any API keys/tokens configured in the plugin.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Gravity SMTP Plugin for WordPress 2.1.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115271">https://www.tenable.com/plugins/was/115271</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! JCE < 2.9.99.5 Unrestricted File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115270</link>
            <guid>https://www.tenable.com/plugins/was/115270</guid>
            <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115270 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! JCE < 2.9.99.5 Unrestricted File Upload<br /></span>
      <h3>Description</h3>
      <span>Joomla! Content Editor (JCE) is a popular WYSIWYG editor for Joomla! websites. Versions prior to 2.9.99.5 contain a critical vulnerability that allows unauthenticated users to create new editor profiles, which can lead to unrestricted file upload and remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade toJoomla! JCE version 2.9.99.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115270">https://www.tenable.com/plugins/was/115270</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Product Slider Pro for WooCommerce Plugin for WordPress < 3.5.4 Backdoor]]></title>
            <link>https://www.tenable.com/plugins/was/115269</link>
            <guid>https://www.tenable.com/plugins/was/115269</guid>
            <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115269 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Product Slider Pro for WooCommerce Plugin for WordPress < 3.5.4 Backdoor<br /></span>
      <h3>Description</h3>
      <span>The WordPress Product Slider Pro for WooCommerce Plugin installed on the remote host is affected by a Backdoor.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Product Slider Pro for WooCommerce Plugin for WordPress 3.5.4<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115269">https://www.tenable.com/plugins/was/115269</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[FortiSandbox 4.4.x < 4.4.9 / 5.0.x < 5.0.6 Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/115268</link>
            <guid>https://www.tenable.com/plugins/was/115268</guid>
            <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115268 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>FortiSandbox 4.4.x < 4.4.9 / 5.0.x < 5.0.6 Path Traversal<br /></span>
      <h3>Description</h3>
      <span>FortiSandbox version 4.4.x prior to 4.4.9 or 5.0.x prior to 5.0.6 are affected by a path traversal vulnerability. An attacker could exploit this vulnerability to gain unauthorized access to files and directories on the system, potentially leading to privilege escalation.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to FortiSandbox 4.4.9 or 5.0.6 later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115268">https://www.tenable.com/plugins/was/115268</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ivanti Sentry < 10.5.2 / 10.6.x < 10.6.2 / 10.7.x < 10.7.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115267</link>
            <guid>https://www.tenable.com/plugins/was/115267</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115267 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Ivanti Sentry < 10.5.2 / 10.6.x < 10.6.2 / 10.7.x < 10.7.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Invanti Sentry version prior to R10.5.2, R10.6.2 and R10.7.1 is vulnerable to OS Command Injection, which allows a remote unauthenticated user to achieve root-level remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ivanti Sentry 10.5.2, 10.6.2, 10.7.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115267">https://www.tenable.com/plugins/was/115267</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Splunk Enterprise < 10.0.7 / 10.2.x < 10.2.4 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115266</link>
            <guid>https://www.tenable.com/plugins/was/115266</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115266 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Splunk Enterprise < 10.0.7 / 10.2.x < 10.2.4 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>The detected Splunk Enterprise instance exposes an unauthenticated PostgreSQL sidecar service endpoint reachable through the splunkd __raw proxy. The endpoint lacks authentication controls, allowing any network-reachable, unauthenticated user to invoke file operations, which can be leveraged to achieve remote code execution. The scanner confirmed the vulnerability by interacting with the unprotected backend endpoint.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Splunk Enterprise 10.0.7, 10.2.4, or later. As a mitigation, disable the PostgreSQL sidecar service. Refer to Splunk advisory SVD-2026-0603 for details.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115266">https://www.tenable.com/plugins/was/115266</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Oracle PeopleSoft 8.61 / 8.62 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115265</link>
            <guid>https://www.tenable.com/plugins/was/115265</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115265 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Oracle PeopleSoft 8.61 / 8.62 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Oracle PeopleSoft version 8.61 and 8.62 contain a vulnerability in the Updates Environment Management component that allows remote attackers to execute arbitrary code via a crafted HTTP request.<br /></span>
      <h3>Solution</h3>
      <span>Refer to the Oracle advisory for mitigation options.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115265">https://www.tenable.com/plugins/was/115265</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[UpdraftPlus Backup Plugin for WordPress < 1.26.5 Unauthenticated Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115264</link>
            <guid>https://www.tenable.com/plugins/was/115264</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115264 with High Severity</p>
      <h3>Synopsis</h3>
      <span>UpdraftPlus Backup Plugin for WordPress < 1.26.5 Unauthenticated Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>The WordPress UpdraftPlus Backup Plugin installed on the remote host is affected by an authenticated authentication bypass.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to UpdraftPlus Backup Plugin for WordPress 1.26.5 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115264">https://www.tenable.com/plugins/was/115264</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache 2.4.x < 2.4.68 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115263</link>
            <guid>https://www.tenable.com/plugins/was/115263</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115263 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache 2.4.x < 2.4.68 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Apache running on the remote host is 2.4.x prior to 2.4.68. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration. (CVE-2026-29167)<br /></span><span><br /></span><span>- A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation when listing FTP directory contents either via forward or reverse proxy configuration. (CVE-2026-29170)<br /></span><span><br /></span><span>- A buffer overflow in mod_proxy_html in Apache HTTP Server allows an attack by an untrusted backend. (CVE-2026-34355)<br /></span><span><br /></span><span>- Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie. (CVE-2026-34356)<br /></span><span><br /></span><span>- A path handling issue in mod_dav_fs allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. (CVE-2026-42535)<br /></span><span><br /></span><span>- Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content. (CVE-2026-42536)<br /></span><span><br /></span><span>- Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. (CVE-2026-43951)<br /></span><span><br /></span><span>- Improper Privilege Management vulnerability in Apache HTTP Server allows local .htaccess authors to read files with the privileges of the httpd user. (CVE-2026-44119)<br /></span><span><br /></span><span>- Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server. (CVE-2026-44185)<br /></span><span><br /></span><span>- Loop with Unreachable Exit Condition vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. (CVE-2026-44186)<br /></span><span><br /></span><span>- Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. (CVE-2026-44631)<br /></span><span><br /></span><span>- Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. (CVE-2026-48913)<br /></span><span><br /></span><span>- Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http2 leads to denial of service via malicious HTTP requests. (CVE-2026-49975)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache version 2.4.68 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115263">https://www.tenable.com/plugins/was/115263</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.5.x < 8.5.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115262</link>
            <guid>https://www.tenable.com/plugins/was/115262</guid>
            <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115262 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.5.x < 8.5.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.5.x prior to 8.5.7. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Pointer difference truncation to int in various places (uriparser before 1.0.2). (CVE-2026-44927)<br /></span><span><br /></span><span>- The EqualsUri function family can misclassify two unequal URIs as equal (uriparser before 1.0.2). (CVE-2026-44928)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.5.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115262">https://www.tenable.com/plugins/was/115262</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Mirasvit Cache Warmer for Magento < 1.11.12 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115261</link>
            <guid>https://www.tenable.com/plugins/was/115261</guid>
            <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115261 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Mirasvit Cache Warmer for Magento < 1.11.12 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>The Mirasvit Cache Warmer extension installed on the remote Magento / Adobe Commerce host is affected by an unauthenticated PHP object injection vulnerability. A server-side plugin reads the 'CacheWarmer' cookie on every storefront request and passes part of its value to PHP's native unserialize() without restricting which classes may be instantiated. As the cookie value is client-controlled, an attacker can inject arbitrary objects and, combined with an available gadget chain, achieve remote code execution without authentication.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Mirasvit Cache Warmer 1.11.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115261">https://www.tenable.com/plugins/was/115261</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Palo Alto PAN-OS < 12.1.7 GlobalProtect Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115260</link>
            <guid>https://www.tenable.com/plugins/was/115260</guid>
            <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115260 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Palo Alto PAN-OS < 12.1.7 GlobalProtect Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Palo Alto PAN-OS versions 10.2.x < 10.2.18-h6 / 11.1.x < 11.1.15 / 11.2.x < 11.2.12 / 12.1.x < 12.1.7 is affected by an authentication bypass vulnerabilities in the GlobalProtect portal and gateway allowing an attacker to bypass security restrictions and establish an unauthorized VPN connection.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Palo Alto PAN-OS version 10.2.18-h6 or 11.1.15 or 11.2.12 or 12.1.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115260">https://www.tenable.com/plugins/was/115260</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Roundcube Webmail 1.7.x < 1.7.1 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115259</link>
            <guid>https://www.tenable.com/plugins/was/115259</guid>
            <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115259 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Roundcube Webmail 1.7.x < 1.7.1 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Roundcube Webmail is 1.6.x prior to 1.6.16 or 1.7.x prior to 1.7.1. Therefore, it may be affected by an unauthenticated SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Roundcube Webmail version 1.7.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115259">https://www.tenable.com/plugins/was/115259</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Roundcube Webmail 1.6.x < 1.6.16 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115258</link>
            <guid>https://www.tenable.com/plugins/was/115258</guid>
            <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115258 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Roundcube Webmail 1.6.x < 1.6.16 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Roundcube Webmail is 1.6.x prior to 1.6.16 or 1.7.x prior to 1.7.1. Therefore, it may be affected by an unauthenticated SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Roundcube Webmail version 1.6.16 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115258">https://www.tenable.com/plugins/was/115258</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 6.x < 6.1.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115257</link>
            <guid>https://www.tenable.com/plugins/was/115257</guid>
            <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115257 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 6.x < 6.1.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.x prior to 5.4.6, or 6.x prior to 6.1.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- An XSS in feed modules due to lack of output escaping. (CVE-2026-25900)<br /></span><span><br /></span><span>- An XSS in the multilingual associations component (com_associations). (CVE-2026-25901)<br /></span><span><br /></span><span>- An XSS in the content history component (com_contenthistory). (CVE-2026-30894)<br /></span><span><br /></span><span>- An XSS in readmore links. (CVE-2026-30895)<br /></span><span><br /></span><span>- A CSRF in the admin user activation endpoint of com_users (6.x only). (CVE-2026-35220)<br /></span><span><br /></span><span>- An authenticated blind SQL injection in the com_finder search query. (CVE-2026-35221)<br /></span><span><br /></span><span>- An authenticated blind SQL injection in com_tags due to improperly validated order clauses. (CVE-2026-35222)<br /></span><span><br /></span><span>- An improper access check in com_config webservice endpoints. (CVE-2026-35223)<br /></span><span><br /></span><span>- A local file inclusion (LFI) in the HTMLView layout parameter due to improper input validation. (CVE-2026-40383)<br /></span><span><br /></span><span>- A path traversal in the com_media webservice endpoint search parameter. (CVE-2026-40384)<br /></span><span><br /></span><span>- An MFA authentication bypass via insufficient state checks. (CVE-2026-48896)<br /></span><span><br /></span><span>- An MFA authentication bypass via incorrectly reset session states. (CVE-2026-48897)<br /></span><span><br /></span><span>- A privilege escalation through the com_users batch task. (CVE-2026-48898)<br /></span><span><br /></span><span>- A privilege escalation through the com_users group editing webservice endpoint. (CVE-2026-48904)<br /></span><span><br /></span><span>- An incorrect access control in sample data plugins. (CVE-2026-48899)<br /></span><span><br /></span><span>- An incorrect access control in com_scheduler allowing low-privileged users to modify task types. (CVE-2026-48900)<br /></span><span><br /></span><span>- An incorrect cache key construction for InputFilter objects. (CVE-2026-48901)<br /></span><span><br /></span><span>- A transport encryption downgrade for password and username reset links on HTTPS sites. (CVE-2026-48902)<br /></span><span><br /></span><span>- Inadequate content filtering in the framework checkAttribute filter leading to XSS. (CVE-2026-48903)<br /></span><span><br /></span><span>- Inadequate content filtering in the framework cleanAttributes filter leading to XSS. (CVE-2026-48905)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 6.1.1 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115257">https://www.tenable.com/plugins/was/115257</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 3.x < 5.4.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115256</link>
            <guid>https://www.tenable.com/plugins/was/115256</guid>
            <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115256 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 3.x < 5.4.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.x prior to 5.4.6, or 6.x prior to 6.1.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- An XSS in feed modules due to lack of output escaping. (CVE-2026-25900)<br /></span><span><br /></span><span>- An XSS in the multilingual associations component (com_associations). (CVE-2026-25901)<br /></span><span><br /></span><span>- An XSS in the content history component (com_contenthistory). (CVE-2026-30894)<br /></span><span><br /></span><span>- An XSS in readmore links. (CVE-2026-30895)<br /></span><span><br /></span><span>- A CSRF in the admin user activation endpoint of com_users (6.x only). (CVE-2026-35220)<br /></span><span><br /></span><span>- An authenticated blind SQL injection in the com_finder search query. (CVE-2026-35221)<br /></span><span><br /></span><span>- An authenticated blind SQL injection in com_tags due to improperly validated order clauses. (CVE-2026-35222)<br /></span><span><br /></span><span>- An improper access check in com_config webservice endpoints. (CVE-2026-35223)<br /></span><span><br /></span><span>- A local file inclusion (LFI) in the HTMLView layout parameter due to improper input validation. (CVE-2026-40383)<br /></span><span><br /></span><span>- A path traversal in the com_media webservice endpoint search parameter. (CVE-2026-40384)<br /></span><span><br /></span><span>- An MFA authentication bypass via insufficient state checks. (CVE-2026-48896)<br /></span><span><br /></span><span>- An MFA authentication bypass via incorrectly reset session states. (CVE-2026-48897)<br /></span><span><br /></span><span>- A privilege escalation through the com_users batch task. (CVE-2026-48898)<br /></span><span><br /></span><span>- A privilege escalation through the com_users group editing webservice endpoint. (CVE-2026-48904)<br /></span><span><br /></span><span>- An incorrect access control in sample data plugins. (CVE-2026-48899)<br /></span><span><br /></span><span>- An incorrect access control in com_scheduler allowing low-privileged users to modify task types. (CVE-2026-48900)<br /></span><span><br /></span><span>- An incorrect cache key construction for InputFilter objects. (CVE-2026-48901)<br /></span><span><br /></span><span>- A transport encryption downgrade for password and username reset links on HTTPS sites. (CVE-2026-48902)<br /></span><span><br /></span><span>- Inadequate content filtering in the framework checkAttribute filter leading to XSS. (CVE-2026-48903)<br /></span><span><br /></span><span>- Inadequate content filtering in the framework cleanAttributes filter leading to XSS. (CVE-2026-48905)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 5.4.6 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115256">https://www.tenable.com/plugins/was/115256</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx < 1.30.2 Buffer Overflow]]></title>
            <link>https://www.tenable.com/plugins/was/115255</link>
            <guid>https://www.tenable.com/plugins/was/115255</guid>
            <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115255 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx < 1.30.2 Buffer Overflow<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.30.2 or 1.31.0. It is, therefore, affected by a buffer overflow in ngx_http_rewrite_module module.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.30.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115255">https://www.tenable.com/plugins/was/115255</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx 1.31.0 Buffer Overflow]]></title>
            <link>https://www.tenable.com/plugins/was/115254</link>
            <guid>https://www.tenable.com/plugins/was/115254</guid>
            <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115254 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx 1.31.0 Buffer Overflow<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.30.2 or 1.31.0. It is, therefore, affected by a buffer overflow in ngx_http_rewrite_module module.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.31.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115254">https://www.tenable.com/plugins/was/115254</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MLflow < 3.11.0 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115253</link>
            <guid>https://www.tenable.com/plugins/was/115253</guid>
            <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115253 with High Severity</p>
      <h3>Synopsis</h3>
      <span>MLflow < 3.11.0 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>MLflow versions prior to 3.11.0 are vulnerable to an authentication bypass vulnerability that allows attackers to access protected resources without proper authentication. This vulnerability arises from a flaw in the authentication mechanism, which can be exploited by attackers to gain unauthorized access to sensitive data and functionalities within the MLflow platform. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to MLflow 3.11.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115253">https://www.tenable.com/plugins/was/115253</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.7.0 Account Takeover]]></title>
            <link>https://www.tenable.com/plugins/was/115252</link>
            <guid>https://www.tenable.com/plugins/was/115252</guid>
            <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115252 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.7.0 Account Takeover<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Langflow running on the remote host is prior to 1.7.0. It is, therefore, affected by an account takeover vulnerability. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with refresh tokens issued with SameSite=None allows a malicious webpage visited by an authenticated user to issue cross-origin requests, steal authentication tokens, and abuse the built-in code execution endpoint to achieve remote code execution and complete system compromise.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.7.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115252">https://www.tenable.com/plugins/was/115252</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal JSONAPI SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115251</link>
            <guid>https://www.tenable.com/plugins/was/115251</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115251 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal JSONAPI SQL Injection<br /></span>
      <h3>Description</h3>
      <span>Drupal versions 8.9.x, 9.x, 10.4.0 < 10.4.10, 10.5.0 < 10.5.10, 10.6.0 < 10.6.9, 11.0.0 < 11.1.10, 11.2.0 < 11.2.12 and 11.3.0 < 11.3.10 suffer from a SQL injection vulnerability in the database abstraction API. An unauthenticated, remote attacker can send specially crafted requests to perform arbitrary SQL injection on PostgreSQL-based sites, resulting in information disclosure, and in some cases privilege escalation or remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Drupal 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, 11.3.10 or later. Patches are available for Drupal 8.9 and 9.5.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115251">https://www.tenable.com/plugins/was/115251</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal < 10.4.10 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115250</link>
            <guid>https://www.tenable.com/plugins/was/115250</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115250 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal < 10.4.10 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by a SQL injection vulnerability. A flaw in Drupal's database abstraction API permits attackers to craft requests that result in arbitrary SQL injection on sites running PostgreSQL. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks. The vulnerability can be exploited by anonymous users. Note that this SQL injection vulnerability only affects sites using PostgreSQL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.4.10 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115250">https://www.tenable.com/plugins/was/115250</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.5.x < 10.5.10 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115249</link>
            <guid>https://www.tenable.com/plugins/was/115249</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115249 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.5.x < 10.5.10 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by a SQL injection vulnerability. A flaw in Drupal's database abstraction API permits attackers to craft requests that result in arbitrary SQL injection on sites running PostgreSQL. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks. The vulnerability can be exploited by anonymous users. Note that this SQL injection vulnerability only affects sites using PostgreSQL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.5.10 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115249">https://www.tenable.com/plugins/was/115249</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.6.x < 10.6.9 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115248</link>
            <guid>https://www.tenable.com/plugins/was/115248</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115248 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.6.x < 10.6.9 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by a SQL injection vulnerability. A flaw in Drupal's database abstraction API permits attackers to craft requests that result in arbitrary SQL injection on sites running PostgreSQL. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks. The vulnerability can be exploited by anonymous users. Note that this SQL injection vulnerability only affects sites using PostgreSQL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.6.9 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115248">https://www.tenable.com/plugins/was/115248</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.1.x < 11.1.10 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115247</link>
            <guid>https://www.tenable.com/plugins/was/115247</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115247 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.1.x < 11.1.10 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by a SQL injection vulnerability. A flaw in Drupal's database abstraction API permits attackers to craft requests that result in arbitrary SQL injection on sites running PostgreSQL. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks. The vulnerability can be exploited by anonymous users. Note that this SQL injection vulnerability only affects sites using PostgreSQL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.1.10 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115247">https://www.tenable.com/plugins/was/115247</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.2.x < 11.2.12 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115246</link>
            <guid>https://www.tenable.com/plugins/was/115246</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115246 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.2.x < 11.2.12 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by a SQL injection vulnerability. A flaw in Drupal's database abstraction API permits attackers to craft requests that result in arbitrary SQL injection on sites running PostgreSQL. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks. The vulnerability can be exploited by anonymous users. Note that this SQL injection vulnerability only affects sites using PostgreSQL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.2.12 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115246">https://www.tenable.com/plugins/was/115246</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.3.x < 11.3.10 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115245</link>
            <guid>https://www.tenable.com/plugins/was/115245</guid>
            <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115245 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.3.x < 11.3.10 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by a SQL injection vulnerability. A flaw in Drupal's database abstraction API permits attackers to craft requests that result in arbitrary SQL injection on sites running PostgreSQL. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks. The vulnerability can be exploited by anonymous users. Note that this SQL injection vulnerability only affects sites using PostgreSQL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.3.10 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115245">https://www.tenable.com/plugins/was/115245</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Burst Statistics Plugin for WordPress 3.4.x < 3.4.2 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115244</link>
            <guid>https://www.tenable.com/plugins/was/115244</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115244 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Burst Statistics Plugin for WordPress 3.4.x < 3.4.2 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>The WordPress Burst Statistics Plugin installed on the remote host is affected by an Authentication Bypass.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Burst Statistics Plugin for WordPress 3.4.2<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115244">https://www.tenable.com/plugins/was/115244</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx < 1.30.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115243</link>
            <guid>https://www.tenable.com/plugins/was/115243</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115243 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx < 1.30.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.30.1. It is, therefore, affected by the following issues :<br /></span><span><br /></span><span>- A heap-use-after-free vulnerability in the ngx_http_ssl_module module when ssl_verify_client is set to 'on' or 'optional' and ssl_ocsp is enabled with a resolver, which may allow an unauthenticated remote attacker to cause worker process restarts or limited memory modification. (CVE-2026-40701)<br /></span><span><br /></span><span>- A vulnerability in the ngx_quic_module module when HTTP/3 is enabled that allows an attacker to spoof their source IP address, potentially bypassing IP-based authorization or rate limiting. (CVE-2026-40460)<br /></span><span><br /></span><span>- A heap buffer over-read vulnerability in the ngx_http_charset_module module when charset, source_charset, charset_map, and proxy_pass with response buffering disabled are all configured, which may allow an unauthenticated remote attacker to cause limited memory disclosure or a worker process restart. (CVE-2026-42934)<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may allow an attacker with man-in-the-middle access to upstream SCGI or uWSGI responses to trigger excessive memory allocation or a data over-read, potentially disclosing worker memory or causing a restart. (CVE-2026-42946)<br /></span><span><br /></span><span>- A heap buffer overflow vulnerability in the ngx_http_rewrite_module module when a rewrite directive is followed by rewrite, if, or set with unnamed PCRE captures and a replacement string containing '?', which may allow an unauthenticated remote attacker to cause worker process restarts or, on systems without ASLR, potentially execute code. (CVE-2026-42945)<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_proxy_v2_module module when proxy_http_version 2 and proxy_set_body are used together that allows an attacker to inject HTTP/2 frame headers and payload bytes toward the upstream peer. (CVE-2026-42926)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.30.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115243">https://www.tenable.com/plugins/was/115243</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Next.js 16.0.x < 16.2.5 Server-Side Request Forgery]]></title>
            <link>https://www.tenable.com/plugins/was/115242</link>
            <guid>https://www.tenable.com/plugins/was/115242</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115242 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Next.js 16.0.x < 16.2.5 Server-Side Request Forgery<br /></span>
      <h3>Description</h3>
      <span>The version of Next.js installed on the remote host is 13.4.13 prior to 15.5.16 or 16.0.0 prior to 16.2.5. It is, therefore, affected by a Server-Side Request Forgery vulnerability in the WebSocket upgrade handler that allows unauthenticated GET-only SSRF to any host on port 80 reachable from the server.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit this issue but has instead relied only on application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Next.js version 16.2.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115242">https://www.tenable.com/plugins/was/115242</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Next.js 13.4.13 < 15.5.16 Server-Side Request Forgery]]></title>
            <link>https://www.tenable.com/plugins/was/115241</link>
            <guid>https://www.tenable.com/plugins/was/115241</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115241 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Next.js 13.4.13 < 15.5.16 Server-Side Request Forgery<br /></span>
      <h3>Description</h3>
      <span>The version of Next.js installed on the remote host is 13.4.13 prior to 15.5.16 or 16.0.0 prior to 16.2.5. It is, therefore, affected by a Server-Side Request Forgery vulnerability in the WebSocket upgrade handler that allows unauthenticated GET-only SSRF to any host on port 80 reachable from the server.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit this issue but has instead relied only on application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Next.js version 15.5.16 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115241">https://www.tenable.com/plugins/was/115241</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.118 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115240</link>
            <guid>https://www.tenable.com/plugins/was/115240</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115240 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.118 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.118, 10.1.0-M1 prior to 10.1.55 or 11.0.0-M1 prior to 11.0.22. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied. (CVE-2026-43515)<br /></span><span><br /></span><span>- The AJP secret was compared in non-constant time allowing an attacker on the local network to mount a timing attack to determine the AJP secret. (CVE-2026-43514)<br /></span><span><br /></span><span>- The LockOut Realm treated user names as case sensitive, reducing effectiveness at blocking brute force attacks against a user's password in Realms where the user name was case insensitive. (CVE-2026-43513)<br /></span><span><br /></span><span>- When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password 'null'. (CVE-2026-43512)<br /></span><span><br /></span><span>- If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host. (CVE-2026-42498)<br /></span><span><br /></span><span>- HTTP/2 request headers were not validated, which may trigger unexpected application behavior if the application assumed header values exposed through the Servlet API would be specification compliant. (CVE-2026-41293)<br /></span><span><br /></span><span>- No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests available to unauthenticated users. (CVE-2026-41284)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.118 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115240">https://www.tenable.com/plugins/was/115240</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.55 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115239</link>
            <guid>https://www.tenable.com/plugins/was/115239</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115239 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.55 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.118, 10.1.0-M1 prior to 10.1.55 or 11.0.0-M1 prior to 11.0.22. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied. (CVE-2026-43515)<br /></span><span><br /></span><span>- The AJP secret was compared in non-constant time allowing an attacker on the local network to mount a timing attack to determine the AJP secret. (CVE-2026-43514)<br /></span><span><br /></span><span>- The LockOut Realm treated user names as case sensitive, reducing effectiveness at blocking brute force attacks against a user's password in Realms where the user name was case insensitive. (CVE-2026-43513)<br /></span><span><br /></span><span>- When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password 'null'. (CVE-2026-43512)<br /></span><span><br /></span><span>- If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host. (CVE-2026-42498)<br /></span><span><br /></span><span>- HTTP/2 request headers were not validated, which may trigger unexpected application behavior if the application assumed header values exposed through the Servlet API would be specification compliant. (CVE-2026-41293)<br /></span><span><br /></span><span>- No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests available to unauthenticated users. (CVE-2026-41284)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.55 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115239">https://www.tenable.com/plugins/was/115239</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.22 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115238</link>
            <guid>https://www.tenable.com/plugins/was/115238</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115238 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.22 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.118, 10.1.0-M1 prior to 10.1.55 or 11.0.0-M1 prior to 11.0.22. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied. (CVE-2026-43515)<br /></span><span><br /></span><span>- The AJP secret was compared in non-constant time allowing an attacker on the local network to mount a timing attack to determine the AJP secret. (CVE-2026-43514)<br /></span><span><br /></span><span>- The LockOut Realm treated user names as case sensitive, reducing effectiveness at blocking brute force attacks against a user's password in Realms where the user name was case insensitive. (CVE-2026-43513)<br /></span><span><br /></span><span>- When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password 'null'. (CVE-2026-43512)<br /></span><span><br /></span><span>- If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host. (CVE-2026-42498)<br /></span><span><br /></span><span>- HTTP/2 request headers were not validated, which may trigger unexpected application behavior if the application assumed header values exposed through the Servlet API would be specification compliant. (CVE-2026-41293)<br /></span><span><br /></span><span>- No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests available to unauthenticated users. (CVE-2026-41284)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.22 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115238">https://www.tenable.com/plugins/was/115238</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.2.x < 8.2.31 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115237</link>
            <guid>https://www.tenable.com/plugins/was/115237</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115237 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.2.x < 8.2.31 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.31, 8.3.x prior to 8.3.31, 8.4.x prior to 8.4.21, or 8.5.x prior to 8.5.6. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS(). (CVE-2026-7263)<br /></span><span><br /></span><span>- Cross-Site Scripting (XSS) within FPM status endpoint. (CVE-2026-6735)<br /></span><span><br /></span><span>- Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init(). (CVE-2026-7259)<br /></span><span><br /></span><span>- Out-of-bounds access in mbfl_name2encoding_ex(). (CVE-2026-6104)<br /></span><span><br /></span><span>- SQL injection via NUL bytes in quoted strings in PDO_Firebird. (CVE-2025-14179)<br /></span><span><br /></span><span>- Stale SOAP_GLOBAL(ref_map) pointer with Apache Map. (CVE-2026-6722)<br /></span><span><br /></span><span>- Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION. (CVE-2026-7261)<br /></span><span><br /></span><span>- Broken Apache map value NULL check in SOAP. (CVE-2026-7262)<br /></span><span><br /></span><span>- Signed integer overflow of char array offset. (CVE-2026-7568)<br /></span><span><br /></span><span>- Inconsistent unsigned char usage with ctype.h functions. (CVE-2026-7258)<br /></span><span><br /></span><span>- Numeric truncation in uriparser text range comparison (uriparser before 1.0.1). (CVE-2026-42371)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.2.31 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115237">https://www.tenable.com/plugins/was/115237</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.3.x < 8.3.31 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115236</link>
            <guid>https://www.tenable.com/plugins/was/115236</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115236 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.3.x < 8.3.31 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.31, 8.3.x prior to 8.3.31, 8.4.x prior to 8.4.21, or 8.5.x prior to 8.5.6. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS(). (CVE-2026-7263)<br /></span><span><br /></span><span>- Cross-Site Scripting (XSS) within FPM status endpoint. (CVE-2026-6735)<br /></span><span><br /></span><span>- Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init(). (CVE-2026-7259)<br /></span><span><br /></span><span>- Out-of-bounds access in mbfl_name2encoding_ex(). (CVE-2026-6104)<br /></span><span><br /></span><span>- SQL injection via NUL bytes in quoted strings in PDO_Firebird. (CVE-2025-14179)<br /></span><span><br /></span><span>- Stale SOAP_GLOBAL(ref_map) pointer with Apache Map. (CVE-2026-6722)<br /></span><span><br /></span><span>- Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION. (CVE-2026-7261)<br /></span><span><br /></span><span>- Broken Apache map value NULL check in SOAP. (CVE-2026-7262)<br /></span><span><br /></span><span>- Signed integer overflow of char array offset. (CVE-2026-7568)<br /></span><span><br /></span><span>- Inconsistent unsigned char usage with ctype.h functions. (CVE-2026-7258)<br /></span><span><br /></span><span>- Numeric truncation in uriparser text range comparison (uriparser before 1.0.1). (CVE-2026-42371)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.3.31 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115236">https://www.tenable.com/plugins/was/115236</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.4.x < 8.4.21 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115235</link>
            <guid>https://www.tenable.com/plugins/was/115235</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115235 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.4.x < 8.4.21 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.31, 8.3.x prior to 8.3.31, 8.4.x prior to 8.4.21, or 8.5.x prior to 8.5.6. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS(). (CVE-2026-7263)<br /></span><span><br /></span><span>- Cross-Site Scripting (XSS) within FPM status endpoint. (CVE-2026-6735)<br /></span><span><br /></span><span>- Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init(). (CVE-2026-7259)<br /></span><span><br /></span><span>- Out-of-bounds access in mbfl_name2encoding_ex(). (CVE-2026-6104)<br /></span><span><br /></span><span>- SQL injection via NUL bytes in quoted strings in PDO_Firebird. (CVE-2025-14179)<br /></span><span><br /></span><span>- Stale SOAP_GLOBAL(ref_map) pointer with Apache Map. (CVE-2026-6722)<br /></span><span><br /></span><span>- Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION. (CVE-2026-7261)<br /></span><span><br /></span><span>- Broken Apache map value NULL check in SOAP. (CVE-2026-7262)<br /></span><span><br /></span><span>- Signed integer overflow of char array offset. (CVE-2026-7568)<br /></span><span><br /></span><span>- Inconsistent unsigned char usage with ctype.h functions. (CVE-2026-7258)<br /></span><span><br /></span><span>- Numeric truncation in uriparser text range comparison (uriparser before 1.0.1). (CVE-2026-42371)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.4.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115235">https://www.tenable.com/plugins/was/115235</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.5.x < 8.5.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115234</link>
            <guid>https://www.tenable.com/plugins/was/115234</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115234 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.5.x < 8.5.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.31, 8.3.x prior to 8.3.31, 8.4.x prior to 8.4.21, or 8.5.x prior to 8.5.6. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS(). (CVE-2026-7263)<br /></span><span><br /></span><span>- Cross-Site Scripting (XSS) within FPM status endpoint. (CVE-2026-6735)<br /></span><span><br /></span><span>- Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init(). (CVE-2026-7259)<br /></span><span><br /></span><span>- Out-of-bounds access in mbfl_name2encoding_ex(). (CVE-2026-6104)<br /></span><span><br /></span><span>- SQL injection via NUL bytes in quoted strings in PDO_Firebird. (CVE-2025-14179)<br /></span><span><br /></span><span>- Stale SOAP_GLOBAL(ref_map) pointer with Apache Map. (CVE-2026-6722)<br /></span><span><br /></span><span>- Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION. (CVE-2026-7261)<br /></span><span><br /></span><span>- Broken Apache map value NULL check in SOAP. (CVE-2026-7262)<br /></span><span><br /></span><span>- Signed integer overflow of char array offset. (CVE-2026-7568)<br /></span><span><br /></span><span>- Inconsistent unsigned char usage with ctype.h functions. (CVE-2026-7258)<br /></span><span><br /></span><span>- Numeric truncation in uriparser text range comparison (uriparser before 1.0.1). (CVE-2026-42371)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.5.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115234">https://www.tenable.com/plugins/was/115234</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Breeze Cache Plugin for WordPress < 2.4.5 Unauthenticated Arbitrary File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115233</link>
            <guid>https://www.tenable.com/plugins/was/115233</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115233 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Breeze Cache Plugin for WordPress < 2.4.5 Unauthenticated Arbitrary File Upload<br /></span>
      <h3>Description</h3>
      <span>The WordPress Breeze Cache Plugin installed on the remote host is affected by an unauthenticated Arbitrary File Upload via the fetch_gravatar_from_remote function.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Breeze Cache Plugin for WordPress 2.4.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115233">https://www.tenable.com/plugins/was/115233</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache 2.4.x < 2.4.67 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115232</link>
            <guid>https://www.tenable.com/plugins/was/115232</guid>
            <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115232 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache 2.4.x < 2.4.67 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Apache running on the remote host is 2.4.x prior to 2.4.67. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- A Double Free and possible Remote Code Execution vulnerability exists in Apache HTTP Server when using the HTTP/2 protocol. (CVE-2026-23918)<br /></span><span><br /></span><span>- Local .htaccess authors can read files with the privileges of the httpd user through an elevation of privileges via ap_expr in mod_rewrite. (CVE-2026-24072)<br /></span><span><br /></span><span>- A heap-based buffer overflow exists in mod_proxy_ajp via ajp_msg_check_header(). A malicious AJP server can send a malicious AJP message causing 4 attacker-controlled bytes to be written after the end of a heap buffer. (CVE-2026-28780)<br /></span><span><br /></span><span>- Unrestricted OCSP response data handling in mod_md allows allocation of resources without limits or throttling. (CVE-2026-29168)<br /></span><span><br /></span><span>- A NULL pointer dereference in mod_dav_lock may allow denial of service with malicious requests. (CVE-2026-29169)<br /></span><span><br /></span><span>- A timing attack against mod_auth_digest allows bypass of Digest authentication by a remote attacker. (CVE-2026-33006)<br /></span><span><br /></span><span>- A NULL pointer dereference in mod_authn_socache allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. (CVE-2026-33007)<br /></span><span><br /></span><span>- An HTTP response splitting vulnerability exists in multiple modules when untrusted or compromised backend servers forward malicious status lines. (CVE-2026-33523)<br /></span><span><br /></span><span>- An out-of-bounds read vulnerability exists in mod_proxy_ajp getter functions. (CVE-2026-33857)<br /></span><span><br /></span><span>- A heap buffer over-read due to missing null-termination check exists in ajp_msg_get_string() in mod_proxy_ajp. (CVE-2026-34032)<br /></span><span><br /></span><span>- A heap over-read and memory disclosure vulnerability exists in ajp_parse_data() in mod_proxy_ajp. (CVE-2026-34059)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache version 2.4.67 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115232">https://www.tenable.com/plugins/was/115232</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[cPanel Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115231</link>
            <guid>https://www.tenable.com/plugins/was/115231</guid>
            <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115231 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>cPanel Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>cPanel versions greather than 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to cPanel version 11.86.0.41 or 11.110.0.97 or 11.118.0.63 or 11.126.0.54 or 11.130.0.19 or 11.132.0.29 or 11.136.0.5 or 11.134.0.20 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115231">https://www.tenable.com/plugins/was/115231</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Supabase Cloud API Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115230</link>
            <guid>https://www.tenable.com/plugins/was/115230</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115230 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Supabase Cloud API Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected an external Supabase instance.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115230">https://www.tenable.com/plugins/was/115230</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[LiteLLM < 1.83.7 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115229</link>
            <guid>https://www.tenable.com/plugins/was/115229</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115229 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>LiteLLM < 1.83.7 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of LiteLLM running on the remote web server is prior to 1.83.7. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An SQL Injection in the Proxy API Key verification flow.<br /></span><span><br /></span><span>- An Authenticated command execution via MCP stdio test endpoints<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to LiteLLM version 1.83.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115229">https://www.tenable.com/plugins/was/115229</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Supabase Studio Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115228</link>
            <guid>https://www.tenable.com/plugins/was/115228</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115228 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Supabase Studio Detected<br /></span>
      <h3>Description</h3>
      <span>A publicly accessible Supabase Studio instance has been detected. Supabase Studio is a web-based interface for managing Supabase projects, and its presence may indicate potential security risks if not properly secured. Attackers may target exposed Supabase Studio instances to gain unauthorized access to sensitive data or perform malicious activities.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to Supabase Studio using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115228">https://www.tenable.com/plugins/was/115228</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Hermes Agent Dashboard Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115227</link>
            <guid>https://www.tenable.com/plugins/was/115227</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115227 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Hermes Agent Dashboard Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected a publicly accessible Hermes Agent Dashboard instance on the target application. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>If the application is not expected to be public, restrict access using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115227">https://www.tenable.com/plugins/was/115227</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MCP Server Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115226</link>
            <guid>https://www.tenable.com/plugins/was/115226</guid>
            <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115226 with High Severity</p>
      <h3>Synopsis</h3>
      <span>MCP Server Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Model Context Protocol (MCP) servers may expose tools, prompts and resources that require authentication to be accessed. An authentication bypass occurs when the MCP server does not properly enforce authentication on requests, allowing unauthenticated users to invoke tools, read prompts or access resources that should be restricted. This can lead to unauthorized access to sensitive data or actions on behalf of legitimate users.<br /></span><span><br /></span><span>This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the MCP server properly enforces authentication on all endpoints exposing tools, prompts and resources. Review the authentication and authorization implementation to guarantee that unauthenticated requests are rejected and that access controls cannot be bypassed.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115226">https://www.tenable.com/plugins/was/115226</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.5.x < 10.5.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115225</link>
            <guid>https://www.tenable.com/plugins/was/115225</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115225 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.5.x < 10.5.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a Cross-Site Scripting (XSS) vulnerability.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This "gadget chain" can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.<br /></span><span><br /></span><span>- Drupal 11.3 includes support for completing entity suggestions when adding a link to CKEditor 5. These suggestions are not sufficiently sanitized, allowing a malicious user to trigger a stored Cross-Site Scripting (XSS) attack against other users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.5.9 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115225">https://www.tenable.com/plugins/was/115225</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.6.x < 10.6.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115224</link>
            <guid>https://www.tenable.com/plugins/was/115224</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115224 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.6.x < 10.6.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a Cross-Site Scripting (XSS) vulnerability.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This "gadget chain" can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.<br /></span><span><br /></span><span>- Drupal 11.3 includes support for completing entity suggestions when adding a link to CKEditor 5. These suggestions are not sufficiently sanitized, allowing a malicious user to trigger a stored Cross-Site Scripting (XSS) attack against other users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.6.7 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115224">https://www.tenable.com/plugins/was/115224</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.2.x < 11.2.11 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115223</link>
            <guid>https://www.tenable.com/plugins/was/115223</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115223 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.2.x < 11.2.11 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a Cross-Site Scripting (XSS) vulnerability.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This "gadget chain" can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.<br /></span><span><br /></span><span>- Drupal 11.3 includes support for completing entity suggestions when adding a link to CKEditor 5. These suggestions are not sufficiently sanitized, allowing a malicious user to trigger a stored Cross-Site Scripting (XSS) attack against other users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.2.11 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115223">https://www.tenable.com/plugins/was/115223</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.3.x < 11.3.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115222</link>
            <guid>https://www.tenable.com/plugins/was/115222</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115222 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.3.x < 11.3.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Drupal core's jQuery integration for AJAX modal dialog boxes does not sufficiently sanitize certain options, which can lead to a Cross-Site Scripting (XSS) vulnerability.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This "gadget chain" can be used to achieve remote code execution or SQL injection if the application deserializes untrusted data due to another vulnerability.<br /></span><span><br /></span><span>- Drupal 11.3 includes support for completing entity suggestions when adding a link to CKEditor 5. These suggestions are not sufficiently sanitized, allowing a malicious user to trigger a stored Cross-Site Scripting (XSS) attack against other users.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.3.7 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115222">https://www.tenable.com/plugins/was/115222</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ninja Forms - File Uploads Plugin for WordPress < 3.3.27 Arbitrary File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115221</link>
            <guid>https://www.tenable.com/plugins/was/115221</guid>
            <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115221 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Ninja Forms - File Uploads Plugin for WordPress < 3.3.27 Arbitrary File Upload<br /></span>
      <h3>Description</h3>
      <span>The WordPress Ninja Forms - File Uploads Plugin installed on the remote host is affected by an Arbitrary File Upload leading to Remote Code Execution.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ninja Forms - File Uploads Plugin for WordPress 3.3.27 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115221">https://www.tenable.com/plugins/was/115221</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.116 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115220</link>
            <guid>https://www.tenable.com/plugins/was/115220</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115220 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.116 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.116, 10.1.0-M1 prior to 10.1.53 or 11.0.0-M1 prior to 11.0.20. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The EncryptInterceptor used CBC by default which is vulnerable to a padding Oracle attack. (CVE-2026-29146)<br /></span><span><br /></span><span>- The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed. This is an incomplete fix for CVE-2025-66614. (CVE-2026-32990)<br /></span><span><br /></span><span>- CLIENT_CERT authentication did not fail OCSP checks as expected for some scenarios when soft fail was disabled. (CVE-2026-29145)<br /></span><span><br /></span><span>- The addition of the ability to configure TLS 1.3 cipher suites did not preserve the order of the configured cipher suites and ciphers. (CVE-2026-29129)<br /></span><span><br /></span><span>- When a Tomcat node in a cluster with the LoadBalancerDrainingValve was in the disabled (draining) state, a specially crafted URL could be used to trigger a redirect to a URI of the attacker's choice. (CVE-2026-25854)<br /></span><span><br /></span><span>- Tomcat did not validate the contents of HTTP/1.1 chunk extensions. This enabled a request smuggling attack if a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension. (CVE-2026-24880)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.116 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115220">https://www.tenable.com/plugins/was/115220</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.53 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115219</link>
            <guid>https://www.tenable.com/plugins/was/115219</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115219 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.53 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.116, 10.1.0-M1 prior to 10.1.53 or 11.0.0-M1 prior to 11.0.20. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The EncryptInterceptor used CBC by default which is vulnerable to a padding Oracle attack. (CVE-2026-29146)<br /></span><span><br /></span><span>- The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed. This is an incomplete fix for CVE-2025-66614. (CVE-2026-32990)<br /></span><span><br /></span><span>- CLIENT_CERT authentication did not fail OCSP checks as expected for some scenarios when soft fail was disabled. (CVE-2026-29145)<br /></span><span><br /></span><span>- The addition of the ability to configure TLS 1.3 cipher suites did not preserve the order of the configured cipher suites and ciphers. (CVE-2026-29129)<br /></span><span><br /></span><span>- When a Tomcat node in a cluster with the LoadBalancerDrainingValve was in the disabled (draining) state, a specially crafted URL could be used to trigger a redirect to a URI of the attacker's choice. (CVE-2026-25854)<br /></span><span><br /></span><span>- Tomcat did not validate the contents of HTTP/1.1 chunk extensions. This enabled a request smuggling attack if a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension. (CVE-2026-24880)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.53 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115219">https://www.tenable.com/plugins/was/115219</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.20 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115218</link>
            <guid>https://www.tenable.com/plugins/was/115218</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115218 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.20 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.116, 10.1.0-M1 prior to 10.1.53 or 11.0.0-M1 prior to 11.0.20. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- The EncryptInterceptor used CBC by default which is vulnerable to a padding Oracle attack. (CVE-2026-29146)<br /></span><span><br /></span><span>- The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed. This is an incomplete fix for CVE-2025-66614. (CVE-2026-32990)<br /></span><span><br /></span><span>- CLIENT_CERT authentication did not fail OCSP checks as expected for some scenarios when soft fail was disabled. (CVE-2026-29145)<br /></span><span><br /></span><span>- The addition of the ability to configure TLS 1.3 cipher suites did not preserve the order of the configured cipher suites and ciphers. (CVE-2026-29129)<br /></span><span><br /></span><span>- When a Tomcat node in a cluster with the LoadBalancerDrainingValve was in the disabled (draining) state, a specially crafted URL could be used to trigger a redirect to a URI of the attacker's choice. (CVE-2026-25854)<br /></span><span><br /></span><span>- Tomcat did not validate the contents of HTTP/1.1 chunk extensions. This enabled a request smuggling attack if a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension. (CVE-2026-24880)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.20 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115218">https://www.tenable.com/plugins/was/115218</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.13 < 9.0.117 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115217</link>
            <guid>https://www.tenable.com/plugins/was/115217</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115217 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.13 < 9.0.117 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.13 prior to 9.0.117, 10.1.0-M1 prior to 10.1.54 or 11.0.0-M1 prior to 11.0.21. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed. (CVE-2026-34486)<br /></span><span><br /></span><span>- CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used. (CVE-2026-34500)<br /></span><span><br /></span><span>- The cloud membership for clustering component exposed the Kubernetes bearer token in log messages. (CVE-2026-34487)<br /></span><span><br /></span><span>- Incomplete escaping when non-default values were used for the Connector attributes relaxedPathChars and/or relaxedQueryChars allowed the injection of arbitrary JSON into the JSON access log. (CVE-2026-34483)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.117 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115217">https://www.tenable.com/plugins/was/115217</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.54 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115216</link>
            <guid>https://www.tenable.com/plugins/was/115216</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115216 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.54 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.13 prior to 9.0.117, 10.1.0-M1 prior to 10.1.54 or 11.0.0-M1 prior to 11.0.21. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed. (CVE-2026-34486)<br /></span><span><br /></span><span>- CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used. (CVE-2026-34500)<br /></span><span><br /></span><span>- The cloud membership for clustering component exposed the Kubernetes bearer token in log messages. (CVE-2026-34487)<br /></span><span><br /></span><span>- Incomplete escaping when non-default values were used for the Connector attributes relaxedPathChars and/or relaxedQueryChars allowed the injection of arbitrary JSON into the JSON access log. (CVE-2026-34483)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.54 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115216">https://www.tenable.com/plugins/was/115216</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.21 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115215</link>
            <guid>https://www.tenable.com/plugins/was/115215</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115215 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.21 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.13 prior to 9.0.117, 10.1.0-M1 prior to 10.1.54 or 11.0.0-M1 prior to 11.0.21. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An error in the fix for CVE-2026-29146 allowed the EncryptInterceptor to be bypassed. (CVE-2026-34486)<br /></span><span><br /></span><span>- CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used. (CVE-2026-34500)<br /></span><span><br /></span><span>- The cloud membership for clustering component exposed the Kubernetes bearer token in log messages. (CVE-2026-34487)<br /></span><span><br /></span><span>- Incomplete escaping when non-default values were used for the Connector attributes relaxedPathChars and/or relaxedQueryChars allowed the injection of arbitrary JSON into the JSON access log. (CVE-2026-34483)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.21 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115215">https://www.tenable.com/plugins/was/115215</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Axios < 1.15.0 Header Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115214</link>
            <guid>https://www.tenable.com/plugins/was/115214</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115214 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Axios < 1.15.0 Header Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Axios application running on the remote host is prior to 1.15.0. It is, therefore, affected by a Header Injection vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Axios version 1.15.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115214">https://www.tenable.com/plugins/was/115214</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Fortinet Forticlient EMS 7.4.5 < 7.4.7 Improper Access Control]]></title>
            <link>https://www.tenable.com/plugins/was/115213</link>
            <guid>https://www.tenable.com/plugins/was/115213</guid>
            <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115213 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Fortinet Forticlient EMS 7.4.5 < 7.4.7 Improper Access Control<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Fortinet Forticlient EMS running on the remote host is 7.4.5 prior to 7.4.7. It is, therefore, affected by an Improper Access Control that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Fortinet FortiClientEMS version 7.4.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115213">https://www.tenable.com/plugins/was/115213</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx UI < 2.3.5 Unauthenticated MCP Endpoint]]></title>
            <link>https://www.tenable.com/plugins/was/115212</link>
            <guid>https://www.tenable.com/plugins/was/115212</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115212 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx UI < 2.3.5 Unauthenticated MCP Endpoint<br /></span>
      <h3>Description</h3>
      <span>Nginx UI version below 2.3.5 contains an unauthenticated access vulnerability in the MCP (Model Context Protocol) integration. The /mcp_message endpoint is protected only by IP whitelisting, and the default configuration allows all IPs, enabling attackers to execute critical actions such as restarting nginx, modifying configuration files, and triggering automatic reloads without authentication.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Nginx UI version 2.3.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115212">https://www.tenable.com/plugins/was/115212</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[LiteLLM 1.82.7 <= 1.82.8 Supply Chain Attack]]></title>
            <link>https://www.tenable.com/plugins/was/115211</link>
            <guid>https://www.tenable.com/plugins/was/115211</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115211 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>LiteLLM 1.82.7 <= 1.82.8 Supply Chain Attack<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of LiteLLM running on the remote web server is 1.82.7 or 1.82.8. It is, therefore, affected by a Supply Chain Attack.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to LiteLLM version 1.83.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115211">https://www.tenable.com/plugins/was/115211</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Progress ShareFile < 5.12.4 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115210</link>
            <guid>https://www.tenable.com/plugins/was/115210</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115210 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Progress ShareFile < 5.12.4 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Progress ShareFile versions prior to 5.12.4 are vulnerable to an authentication bypass vulnerability that could allow an unauthenticated attacker to execute arbitrary code on the affected system.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Progress ShareFile version 5.12.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115210">https://www.tenable.com/plugins/was/115210</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Axios 0.30.4 Malicious Version Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115209</link>
            <guid>https://www.tenable.com/plugins/was/115209</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115209 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Axios 0.30.4 Malicious Version Detected<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Axios is 1.14.1 or 0.30.4. Therefore, it may be affected by an embedded malicious code vulnerability due to a supply chain compromise of the axios npm package. The malicious versions contain unauthorized code that may exfiltrate sensitive data from the host environment.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Downgrade to version 0.30.3 or upgrade to latest official version available. Conduct a thorough security review of the application to identify and mitigate any potential impacts of the malicious code.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115209">https://www.tenable.com/plugins/was/115209</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Axios 1.14.1 Malicious Version Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115208</link>
            <guid>https://www.tenable.com/plugins/was/115208</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115208 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Axios 1.14.1 Malicious Version Detected<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Axios is 1.14.1 or 0.30.4. Therefore, it may be affected by an embedded malicious code vulnerability due to a supply chain compromise of the axios npm package. The malicious versions contain unauthorized code that may exfiltrate sensitive data from the host environment.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Downgrade to version 1.14.0 or upgrade to latest official version available. Conduct a thorough security review of the application to identify and mitigate any potential impacts of the malicious code.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115208">https://www.tenable.com/plugins/was/115208</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 6.x < 6.0.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115207</link>
            <guid>https://www.tenable.com/plugins/was/115207</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115207 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 6.x < 6.0.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.x prior to 5.4.4, or 6.x prior to 6.0.3. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- An ACL hardening in com_ajax, the ajax component was excluded from the default logged-in-user check in the administrative area.<br /></span><span><br /></span><span>- An SQL injection in com_content articles webservice endpoint<br /></span><span><br /></span><span>- An XSS vector in com_associations comparison view<br /></span><span><br /></span><span>- An XSS vectors in various article title outputs<br /></span><span><br /></span><span>- An Arbitrary file deletion in com_joomlaupdate<br /></span><span><br /></span><span>- An Improper access check in webservice endpoints<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 6.0.3 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115207">https://www.tenable.com/plugins/was/115207</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 3.x < 5.4.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115206</link>
            <guid>https://www.tenable.com/plugins/was/115206</guid>
            <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115206 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 3.x < 5.4.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.x prior to 5.4.4, or 6.x prior to 6.0.3. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- An ACL hardening in com_ajax, the ajax component was excluded from the default logged-in-user check in the administrative area.<br /></span><span><br /></span><span>- An SQL injection in com_content articles webservice endpoint<br /></span><span><br /></span><span>- An XSS vector in com_associations comparison view<br /></span><span><br /></span><span>- An XSS vectors in various article title outputs<br /></span><span><br /></span><span>- An Arbitrary file deletion in com_joomlaupdate<br /></span><span><br /></span><span>- An Improper access check in webservice endpoints<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 5.4.4 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115206">https://www.tenable.com/plugins/was/115206</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Fortinet Forticlient EMS 7.4.4 SQL Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115205</link>
            <guid>https://www.tenable.com/plugins/was/115205</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115205 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Fortinet Forticlient EMS 7.4.4 SQL Injection<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Fortinet Forticlient EMS running on the remote host is 7.4.4. It is, therefore, affected by an SQL Injection in administrative interface.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Fortinet FortiClientEMS version 7.4.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115205">https://www.tenable.com/plugins/was/115205</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Smart Slider 3 Plugin for WordPress < 3.5.1.34 Arbitrary File Read]]></title>
            <link>https://www.tenable.com/plugins/was/115204</link>
            <guid>https://www.tenable.com/plugins/was/115204</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115204 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Smart Slider 3 Plugin for WordPress < 3.5.1.34 Arbitrary File Read<br /></span>
      <h3>Description</h3>
      <span>The WordPress Smart Slider 3 Plugin installed on the remote host is affected by an Arbitrary File Read.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Smart Slider 3 Plugin for WordPress 3.5.1.34<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115204">https://www.tenable.com/plugins/was/115204</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OAuth 2.0 Authentication Failed]]></title>
            <link>https://www.tenable.com/plugins/was/115203</link>
            <guid>https://www.tenable.com/plugins/was/115203</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115203 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>OAuth 2.0 Authentication Failed<br /></span>
      <h3>Description</h3>
      <span>This plugin is raised when the scanner has not been able to authenticate against the web application using the provided OAuth 2.0 credentials.<br /></span><span><br /></span><span>Check the output of the plugin to get an explanation of the issue encountered by the scan.<br /></span>
      <h3>Solution</h3>
      <span>Edit scan policy and update the OAuth 2.0 credentials using the information provided in the plugin output.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115203">https://www.tenable.com/plugins/was/115203</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OAuth 2.0 Authentication Succeeded]]></title>
            <link>https://www.tenable.com/plugins/was/115202</link>
            <guid>https://www.tenable.com/plugins/was/115202</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115202 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>OAuth 2.0 Authentication Succeeded<br /></span>
      <h3>Description</h3>
      <span>This is an informational notice that the scanner was able to successfully authenticate using the provided OAuth 2.0 Credentials.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115202">https://www.tenable.com/plugins/was/115202</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Citrix Netscaler / Gateway ADC Memory Leak]]></title>
            <link>https://www.tenable.com/plugins/was/115201</link>
            <guid>https://www.tenable.com/plugins/was/115201</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115201 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Citrix Netscaler / Gateway ADC Memory Leak<br /></span>
      <h3>Description</h3>
      <span>Citrix Netscaler / Gateway ADC 13.1.x < 13.1-37.262 / 14.1-x < 14.1-60.58 and ADC (FIPS/NDcPP) < 13.1-37.262 are vulnerable to a memory leak vulnerability when configured as a SAML IDP. An unauthenticated attacker can exploit this vulnerability by sending specially crafted requests to the vulnerable system, which can lead to a memory leak.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Citrix ADC or Gateway 13.1-37.262, 14.1-60.58 or later. For FIPS / NDcPP versions, upgrade to version 13.1-37.262 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115201">https://www.tenable.com/plugins/was/115201</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.3.x < 12.3.0 Incorrect Privilege Assignment]]></title>
            <link>https://www.tenable.com/plugins/was/115200</link>
            <guid>https://www.tenable.com/plugins/was/115200</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115200 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.3.x < 12.3.0 Incorrect Privilege Assignment<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.6, or 12.1.x prior to 12.1.3, or 12.2.x prior to 12.2.1, or 12.3.x prior to 12.3.0. It is, therefore, affected by an incorrect privilege assignment vulnerability.<br /></span><span><br /></span><span>- In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override internal user IDs and lead to impersonation or privilege escalation.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.3.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115200">https://www.tenable.com/plugins/was/115200</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.2.x < 12.2.1 Incorrect Privilege Assignment]]></title>
            <link>https://www.tenable.com/plugins/was/115199</link>
            <guid>https://www.tenable.com/plugins/was/115199</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115199 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.2.x < 12.2.1 Incorrect Privilege Assignment<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.6, or 12.1.x prior to 12.1.3, or 12.2.x prior to 12.2.1, or 12.3.x prior to 12.3.0. It is, therefore, affected by an incorrect privilege assignment vulnerability.<br /></span><span><br /></span><span>- In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override internal user IDs and lead to impersonation or privilege escalation.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.2.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115199">https://www.tenable.com/plugins/was/115199</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.1.x < 12.1.3 Incorrect Privilege Assignment]]></title>
            <link>https://www.tenable.com/plugins/was/115198</link>
            <guid>https://www.tenable.com/plugins/was/115198</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115198 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.1.x < 12.1.3 Incorrect Privilege Assignment<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.6, or 12.1.x prior to 12.1.3, or 12.2.x prior to 12.2.1, or 12.3.x prior to 12.3.0. It is, therefore, affected by an incorrect privilege assignment vulnerability.<br /></span><span><br /></span><span>- In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override internal user IDs and lead to impersonation or privilege escalation.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.1.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115198">https://www.tenable.com/plugins/was/115198</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 12.0.6 Incorrect Privilege Assignment]]></title>
            <link>https://www.tenable.com/plugins/was/115197</link>
            <guid>https://www.tenable.com/plugins/was/115197</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115197 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 12.0.6 Incorrect Privilege Assignment<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.6, or 12.1.x prior to 12.1.3, or 12.2.x prior to 12.2.1, or 12.3.x prior to 12.3.0. It is, therefore, affected by an incorrect privilege assignment vulnerability.<br /></span><span><br /></span><span>- In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override internal user IDs and lead to impersonation or privilege escalation.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.0.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115197">https://www.tenable.com/plugins/was/115197</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.3.x < 12.3.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115196</link>
            <guid>https://www.tenable.com/plugins/was/115196</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115196 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.3.x < 12.3.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.9, or 12.0.x prior to 12.0.8, or 12.1.x prior to 12.1.5, or 12.2.x prior to 12.2.3, or 12.3.x prior to 12.3.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- The platform supports users having their own avatars, which can be sourced from the Gravatar service API. This uses a cache, to ensure that we don't overload the service. If these requests time out after 3 seconds, a Goroutine is left running forever. This can cause a denial of service (DoS) if an attacker repeats these requests.<br /></span><span><br /></span><span>- If a user has permission management rights on one dashboard, they could edit the permissions of any other dashboard.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.3.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115196">https://www.tenable.com/plugins/was/115196</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.2.x < 12.2.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115195</link>
            <guid>https://www.tenable.com/plugins/was/115195</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115195 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.2.x < 12.2.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.9, or 12.0.x prior to 12.0.8, or 12.1.x prior to 12.1.5, or 12.2.x prior to 12.2.3, or 12.3.x prior to 12.3.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- The platform supports users having their own avatars, which can be sourced from the Gravatar service API. This uses a cache, to ensure that we don't overload the service. If these requests time out after 3 seconds, a Goroutine is left running forever. This can cause a denial of service (DoS) if an attacker repeats these requests.<br /></span><span><br /></span><span>- If a user has permission management rights on one dashboard, they could edit the permissions of any other dashboard.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.2.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115195">https://www.tenable.com/plugins/was/115195</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.1.x < 12.1.5 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115194</link>
            <guid>https://www.tenable.com/plugins/was/115194</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115194 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.1.x < 12.1.5 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.9, or 12.0.x prior to 12.0.8, or 12.1.x prior to 12.1.5, or 12.2.x prior to 12.2.3, or 12.3.x prior to 12.3.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- The platform supports users having their own avatars, which can be sourced from the Gravatar service API. This uses a cache, to ensure that we don't overload the service. If these requests time out after 3 seconds, a Goroutine is left running forever. This can cause a denial of service (DoS) if an attacker repeats these requests.<br /></span><span><br /></span><span>- If a user has permission management rights on one dashboard, they could edit the permissions of any other dashboard.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.1.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115194">https://www.tenable.com/plugins/was/115194</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.0.x < 12.0.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115193</link>
            <guid>https://www.tenable.com/plugins/was/115193</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115193 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.0.x < 12.0.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.9, or 12.0.x prior to 12.0.8, or 12.1.x prior to 12.1.5, or 12.2.x prior to 12.2.3, or 12.3.x prior to 12.3.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- The platform supports users having their own avatars, which can be sourced from the Gravatar service API. This uses a cache, to ensure that we don't overload the service. If these requests time out after 3 seconds, a Goroutine is left running forever. This can cause a denial of service (DoS) if an attacker repeats these requests.<br /></span><span><br /></span><span>- If a user has permission management rights on one dashboard, they could edit the permissions of any other dashboard.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.0.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115193">https://www.tenable.com/plugins/was/115193</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 11.6.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115192</link>
            <guid>https://www.tenable.com/plugins/was/115192</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115192 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 11.6.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.9, or 12.0.x prior to 12.0.8, or 12.1.x prior to 12.1.5, or 12.2.x prior to 12.2.3, or 12.3.x prior to 12.3.1. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- The platform supports users having their own avatars, which can be sourced from the Gravatar service API. This uses a cache, to ensure that we don't overload the service. If these requests time out after 3 seconds, a Goroutine is left running forever. This can cause a denial of service (DoS) if an attacker repeats these requests.<br /></span><span><br /></span><span>- If a user has permission management rights on one dashboard, they could edit the permissions of any other dashboard.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.6.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115192">https://www.tenable.com/plugins/was/115192</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.3.x < 12.3.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115191</link>
            <guid>https://www.tenable.com/plugins/was/115191</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115191 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.3.x < 12.3.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.2.4, or 12.3.x prior to 12.3.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.<br /></span><span><br /></span><span>- Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.3.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115191">https://www.tenable.com/plugins/was/115191</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 12.2.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115190</link>
            <guid>https://www.tenable.com/plugins/was/115190</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115190 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 12.2.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.2.4, or 12.3.x prior to 12.3.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.<br /></span><span><br /></span><span>- Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.2.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115190">https://www.tenable.com/plugins/was/115190</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.3.x < 12.3.3 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115189</link>
            <guid>https://www.tenable.com/plugins/was/115189</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115189 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.3.x < 12.3.3 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.9, or 12.1.x prior to 12.1.6, or 12.2.x prior to 12.2.4, or 12.3.x prior to 12.3.3. It is, therefore, affected by a cross-tenant legacy correlation disclosure and deletion vulnerability.<br /></span><span><br /></span><span>- Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.3.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115189">https://www.tenable.com/plugins/was/115189</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.2.x < 12.2.4 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115188</link>
            <guid>https://www.tenable.com/plugins/was/115188</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115188 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.2.x < 12.2.4 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.9, or 12.1.x prior to 12.1.6, or 12.2.x prior to 12.2.4, or 12.3.x prior to 12.3.3. It is, therefore, affected by a cross-tenant legacy correlation disclosure and deletion vulnerability.<br /></span><span><br /></span><span>- Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.2.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115188">https://www.tenable.com/plugins/was/115188</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.1.x < 12.1.6 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115187</link>
            <guid>https://www.tenable.com/plugins/was/115187</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115187 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.1.x < 12.1.6 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.9, or 12.1.x prior to 12.1.6, or 12.2.x prior to 12.2.4, or 12.3.x prior to 12.3.3. It is, therefore, affected by a cross-tenant legacy correlation disclosure and deletion vulnerability.<br /></span><span><br /></span><span>- Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.1.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115187">https://www.tenable.com/plugins/was/115187</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 12.0.9 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115186</link>
            <guid>https://www.tenable.com/plugins/was/115186</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115186 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 12.0.9 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 12.0.9, or 12.1.x prior to 12.1.6, or 12.2.x prior to 12.2.4, or 12.3.x prior to 12.3.3. It is, therefore, affected by a cross-tenant legacy correlation disclosure and deletion vulnerability.<br /></span><span><br /></span><span>- Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.0.9 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115186">https://www.tenable.com/plugins/was/115186</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.3.x < 12.3.6 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115185</link>
            <guid>https://www.tenable.com/plugins/was/115185</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115185 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.3.x < 12.3.6 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6. It is, therefore, affected by a missing protected-field authorization vulnerability.<br /></span><span><br /></span><span>- A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.3.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115185">https://www.tenable.com/plugins/was/115185</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.2.x < 12.2.8 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115184</link>
            <guid>https://www.tenable.com/plugins/was/115184</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115184 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.2.x < 12.2.8 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6. It is, therefore, affected by a missing protected-field authorization vulnerability.<br /></span><span><br /></span><span>- A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.2.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115184">https://www.tenable.com/plugins/was/115184</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.1.x < 12.1.10 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115183</link>
            <guid>https://www.tenable.com/plugins/was/115183</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115183 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.1.x < 12.1.10 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6. It is, therefore, affected by a missing protected-field authorization vulnerability.<br /></span><span><br /></span><span>- A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.1.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115183">https://www.tenable.com/plugins/was/115183</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 11.6.14 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/115182</link>
            <guid>https://www.tenable.com/plugins/was/115182</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115182 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 11.6.14 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6. It is, therefore, affected by a missing protected-field authorization vulnerability.<br /></span><span><br /></span><span>- A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.6.14 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115182">https://www.tenable.com/plugins/was/115182</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.4.x < 12.4.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115181</link>
            <guid>https://www.tenable.com/plugins/was/115181</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115181 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.4.x < 12.4.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6, or 12.4.x prior to 12.4.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. A vulnerability in this feature allows arbitrary file write enabling remote code execution.<br /></span><span><br /></span><span>- Grafana's OpenFeature feature flag validation endpoints do not require authentication and accept unbounded user input, leading to an unauthenticated denial-of-service.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.4.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115181">https://www.tenable.com/plugins/was/115181</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.3.x < 12.3.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115180</link>
            <guid>https://www.tenable.com/plugins/was/115180</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115180 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.3.x < 12.3.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6, or 12.4.x prior to 12.4.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. A vulnerability in this feature allows arbitrary file write enabling remote code execution.<br /></span><span><br /></span><span>- Grafana's OpenFeature feature flag validation endpoints do not require authentication and accept unbounded user input, leading to an unauthenticated denial-of-service.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.3.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115180">https://www.tenable.com/plugins/was/115180</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.2.x < 12.2.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115179</link>
            <guid>https://www.tenable.com/plugins/was/115179</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115179 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.2.x < 12.2.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6, or 12.4.x prior to 12.4.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. A vulnerability in this feature allows arbitrary file write enabling remote code execution.<br /></span><span><br /></span><span>- Grafana's OpenFeature feature flag validation endpoints do not require authentication and accept unbounded user input, leading to an unauthenticated denial-of-service.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.2.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115179">https://www.tenable.com/plugins/was/115179</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.1.x < 12.1.10 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115178</link>
            <guid>https://www.tenable.com/plugins/was/115178</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115178 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.1.x < 12.1.10 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6, or 12.4.x prior to 12.4.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. A vulnerability in this feature allows arbitrary file write enabling remote code execution.<br /></span><span><br /></span><span>- Grafana's OpenFeature feature flag validation endpoints do not require authentication and accept unbounded user input, leading to an unauthenticated denial-of-service.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.1.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115178">https://www.tenable.com/plugins/was/115178</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 11.6.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115177</link>
            <guid>https://www.tenable.com/plugins/was/115177</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115177 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 11.6.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.14, or 12.1.x prior to 12.1.10, or 12.2.x prior to 12.2.8, or 12.3.x prior to 12.3.6, or 12.4.x prior to 12.4.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Grafana's SQL expressions feature enables transforming query data with familiar SQL syntax. A vulnerability in this feature allows arbitrary file write enabling remote code execution.<br /></span><span><br /></span><span>- Grafana's OpenFeature feature flag validation endpoints do not require authentication and accept unbounded user input, leading to an unauthenticated denial-of-service.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.6.14 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115177">https://www.tenable.com/plugins/was/115177</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.8.2 Unauthenticated Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115176</link>
            <guid>https://www.tenable.com/plugins/was/115176</guid>
            <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115176 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.8.2 Unauthenticated Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Langflow versions before 1.8.2 allow unauthenticated remote code execution via the '/api/v1/build_public_tmp/{flow_id}/flow' endpoint. Attacker-supplied flow data with arbitrary Python code in node definitions is passed to exec() without sandboxing, enabling code execution without authentication. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.8.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115176">https://www.tenable.com/plugins/was/115176</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Langflow < 1.7.1 Monitor API Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115175</link>
            <guid>https://www.tenable.com/plugins/was/115175</guid>
            <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115175 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Langflow < 1.7.1 Monitor API Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Langlow versions before 1.7.1 lack of authentication on multiple API monitor endpoints, allowing unauthenticated access to sensitive conversation data, transaction histories, and destructive operations such as message deletion. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Langflow version 1.7.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115175">https://www.tenable.com/plugins/was/115175</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx < 1.28.3 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115174</link>
            <guid>https://www.tenable.com/plugins/was/115174</guid>
            <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115174 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx < 1.28.3 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.28.3 or 1.29.x prior to 1.29.7. It is, therefore, affected by the following issues :<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process. (CVE-2026-27654)<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination. (CVE-2026-27784)<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. (CVE-2026-32647)<br /></span><span><br /></span><span>- When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. (CVE-2026-27651)<br /></span><span><br /></span><span>- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. (CVE-2026-28753)<br /></span><span><br /></span><span>- A vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked. (CVE-2026-28755)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.28.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115174">https://www.tenable.com/plugins/was/115174</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx 1.29.x < 1.29.7 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115173</link>
            <guid>https://www.tenable.com/plugins/was/115173</guid>
            <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115173 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx 1.29.x < 1.29.7 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is prior to 1.28.3 or 1.29.x prior to 1.29.7. It is, therefore, affected by the following issues :<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process. (CVE-2026-27654)<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination. (CVE-2026-27784)<br /></span><span><br /></span><span>- A vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. (CVE-2026-32647)<br /></span><span><br /></span><span>- When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. (CVE-2026-27651)<br /></span><span><br /></span><span>- NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. (CVE-2026-28753)<br /></span><span><br /></span><span>- A vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked. (CVE-2026-28755)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.29.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115173">https://www.tenable.com/plugins/was/115173</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N8n 0.211.0 < 1.120.4 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115172</link>
            <guid>https://www.tenable.com/plugins/was/115172</guid>
            <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115172 with High Severity</p>
      <h3>Synopsis</h3>
      <span>N8n 0.211.0 < 1.120.4 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of n8n running on the remote host is 0.211.0 or later and before 1.120.4 or 1.121.x < 1.121.1. It is, therefore, affected by an Expression Language Injection which can leads to remote code execution.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to n8n version 1.120.4, 1.121.1, 1.122.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115172">https://www.tenable.com/plugins/was/115172</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N8n 1.121.0 < 1.121.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115171</link>
            <guid>https://www.tenable.com/plugins/was/115171</guid>
            <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115171 with High Severity</p>
      <h3>Synopsis</h3>
      <span>N8n 1.121.0 < 1.121.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of n8n running on the remote host is 0.211.0 or later and before 1.120.4 or 1.121.x < 1.121.1. It is, therefore, affected by an Expression Language Injection which can leads to remote code execution.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to n8n version 1.120.4, 1.121.1, 1.122.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115171">https://www.tenable.com/plugins/was/115171</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.4.x < 6.4.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115170</link>
            <guid>https://www.tenable.com/plugins/was/115170</guid>
            <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115170 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.4.x < 6.4.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A blind Server-Side Request Forgery (SSRF)<br /></span><span><br /></span><span>- A PoP-chain weakness in the HTML API and Block Registry<br /></span><span><br /></span><span>- A regex Denial of Service (DoS) weakness in numeric character references<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) in nav menus<br /></span><span><br /></span><span>- An AJAX query-attachments authorization bypass<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) via the data-wp-bind directive<br /></span><span><br /></span><span>- An Cross-Site Scripting (XSS) that allows overridding client-side templates in the admin area<br /></span><span><br /></span><span>- A PclZip path traversal issue<br /></span><span><br /></span><span>- An authorization bypass on the Notes feature<br /></span><span><br /></span><span>- An XML External Entity (XXE) issue in the external getID3 library<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.4.8 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115170">https://www.tenable.com/plugins/was/115170</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.5.x < 6.5.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115169</link>
            <guid>https://www.tenable.com/plugins/was/115169</guid>
            <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115169 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.5.x < 6.5.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A blind Server-Side Request Forgery (SSRF)<br /></span><span><br /></span><span>- A PoP-chain weakness in the HTML API and Block Registry<br /></span><span><br /></span><span>- A regex Denial of Service (DoS) weakness in numeric character references<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) in nav menus<br /></span><span><br /></span><span>- An AJAX query-attachments authorization bypass<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) via the data-wp-bind directive<br /></span><span><br /></span><span>- An Cross-Site Scripting (XSS) that allows overridding client-side templates in the admin area<br /></span><span><br /></span><span>- A PclZip path traversal issue<br /></span><span><br /></span><span>- An authorization bypass on the Notes feature<br /></span><span><br /></span><span>- An XML External Entity (XXE) issue in the external getID3 library<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.5.8 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115169">https://www.tenable.com/plugins/was/115169</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.6.x < 6.6.5 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115168</link>
            <guid>https://www.tenable.com/plugins/was/115168</guid>
            <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115168 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.6.x < 6.6.5 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A blind Server-Side Request Forgery (SSRF)<br /></span><span><br /></span><span>- A PoP-chain weakness in the HTML API and Block Registry<br /></span><span><br /></span><span>- A regex Denial of Service (DoS) weakness in numeric character references<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) in nav menus<br /></span><span><br /></span><span>- An AJAX query-attachments authorization bypass<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) via the data-wp-bind directive<br /></span><span><br /></span><span>- An Cross-Site Scripting (XSS) that allows overridding client-side templates in the admin area<br /></span><span><br /></span><span>- A PclZip path traversal issue<br /></span><span><br /></span><span>- An authorization bypass on the Notes feature<br /></span><span><br /></span><span>- An XML External Entity (XXE) issue in the external getID3 library<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.6.5 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115168">https://www.tenable.com/plugins/was/115168</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.7.x < 6.7.5 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115167</link>
            <guid>https://www.tenable.com/plugins/was/115167</guid>
            <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115167 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.7.x < 6.7.5 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A blind Server-Side Request Forgery (SSRF)<br /></span><span><br /></span><span>- A PoP-chain weakness in the HTML API and Block Registry<br /></span><span><br /></span><span>- A regex Denial of Service (DoS) weakness in numeric character references<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) in nav menus<br /></span><span><br /></span><span>- An AJAX query-attachments authorization bypass<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) via the data-wp-bind directive<br /></span><span><br /></span><span>- An Cross-Site Scripting (XSS) that allows overridding client-side templates in the admin area<br /></span><span><br /></span><span>- A PclZip path traversal issue<br /></span><span><br /></span><span>- An authorization bypass on the Notes feature<br /></span><span><br /></span><span>- An XML External Entity (XXE) issue in the external getID3 library<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.7.5 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115167">https://www.tenable.com/plugins/was/115167</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.8.x < 6.8.5 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115166</link>
            <guid>https://www.tenable.com/plugins/was/115166</guid>
            <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115166 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.8.x < 6.8.5 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A blind Server-Side Request Forgery (SSRF)<br /></span><span><br /></span><span>- A PoP-chain weakness in the HTML API and Block Registry<br /></span><span><br /></span><span>- A regex Denial of Service (DoS) weakness in numeric character references<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) in nav menus<br /></span><span><br /></span><span>- An AJAX query-attachments authorization bypass<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) via the data-wp-bind directive<br /></span><span><br /></span><span>- An Cross-Site Scripting (XSS) that allows overridding client-side templates in the admin area<br /></span><span><br /></span><span>- A PclZip path traversal issue<br /></span><span><br /></span><span>- An authorization bypass on the Notes feature<br /></span><span><br /></span><span>- An XML External Entity (XXE) issue in the external getID3 library<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.8.5 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115166">https://www.tenable.com/plugins/was/115166</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[WordPress 6.9.x < 6.9.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115165</link>
            <guid>https://www.tenable.com/plugins/was/115165</guid>
            <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115165 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>WordPress 6.9.x < 6.9.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected WordPress application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A blind Server-Side Request Forgery (SSRF)<br /></span><span><br /></span><span>- A PoP-chain weakness in the HTML API and Block Registry<br /></span><span><br /></span><span>- A regex Denial of Service (DoS) weakness in numeric character references<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) in nav menus<br /></span><span><br /></span><span>- An AJAX query-attachments authorization bypass<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) via the data-wp-bind directive<br /></span><span><br /></span><span>- An Cross-Site Scripting (XSS) that allows overridding client-side templates in the admin area<br /></span><span><br /></span><span>- A PclZip path traversal issue<br /></span><span><br /></span><span>- An authorization bypass on the Notes feature<br /></span><span><br /></span><span>- An XML External Entity (XXE) issue in the external getID3 library<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to WordPress version 6.9.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115165">https://www.tenable.com/plugins/was/115165</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CKEditor < 43.1.1 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115164</link>
            <guid>https://www.tenable.com/plugins/was/115164</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115164 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>CKEditor < 43.1.1 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the CKEditor application running on the remote host is 5.40.x prior to 5.41.3.2 or 5.43.1.x prior to 5.43.1.1. It is, therefore, affected by a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to CKEditor version 5.43.1.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115164">https://www.tenable.com/plugins/was/115164</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CKEditor 5.40.0.x < 5.41.3.2 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115163</link>
            <guid>https://www.tenable.com/plugins/was/115163</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115163 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>CKEditor 5.40.0.x < 5.41.3.2 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the CKEditor application running on the remote host is 5.40.x prior to 5.41.3.2 or 5.43.1.x prior to 5.43.1.1. It is, therefore, affected by a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to CKEditor version 5.41.3.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115163">https://www.tenable.com/plugins/was/115163</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CKEditor 5.42.0.x < 5.44.2.1 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115162</link>
            <guid>https://www.tenable.com/plugins/was/115162</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115162 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>CKEditor 5.42.0.x < 5.44.2.1 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the CKEditor application running on the remote host is 5.44.2.x prior to 5.44.2.1. It is, therefore, affected by a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 real-time collaboration package.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to CKEditor version 5.44.2.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115162">https://www.tenable.com/plugins/was/115162</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CKEditor 5.46.0.2 < 5.46.0.3 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115161</link>
            <guid>https://www.tenable.com/plugins/was/115161</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115161 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>CKEditor 5.46.0.2 < 5.46.0.3 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the CKEditor application running on the remote host is 5.44.2.x prior to 5.45.2.2 or 5.46.0.2 prior to 5.46.0.3. It is, therefore, affected by a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to CKEditor version 5.46.0.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115161">https://www.tenable.com/plugins/was/115161</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CKEditor 5.44.2.x < 5.45.2.2 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115160</link>
            <guid>https://www.tenable.com/plugins/was/115160</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115160 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>CKEditor 5.44.2.x < 5.45.2.2 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the CKEditor application running on the remote host is 5.44.2.x prior to 5.45.2.2 or 5.46.0.2 prior to 5.46.0.3. It is, therefore, affected by a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to CKEditor version 5.45.2.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115160">https://www.tenable.com/plugins/was/115160</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CKEditor < 5.47.6.0 Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115159</link>
            <guid>https://www.tenable.com/plugins/was/115159</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115159 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>CKEditor < 5.47.6.0 Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the CKEditor application running on the remote host is prior to 5.47.6.0. It is, therefore, affected by a Cross-Site Scripting (XSS) vulnerability in the General HTML Support feature.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to CKEditor version 5.47.6.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115159">https://www.tenable.com/plugins/was/115159</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx UI < 2.3.3 Sensitive Information Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115158</link>
            <guid>https://www.tenable.com/plugins/was/115158</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115158 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx UI < 2.3.3 Sensitive Information Disclosure<br /></span>
      <h3>Description</h3>
      <span>Nginx UI version below 2.3.3 contains a critical sensitive information disclosure vulnerability that allows unauthenticated attackers to access the /api/backup endpoint and retrieve encryption keys from the X-Backup-Security response header. This enables attackers to download and decrypt full system backups, exposing sensitive data such as user credentials, session tokens, SSL private keys, and Nginx configurations.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Nginx UI version 2.3.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115158">https://www.tenable.com/plugins/was/115158</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Validated Secret Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115118</link>
            <guid>https://www.tenable.com/plugins/was/115118</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115118 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Validated Secret Detected<br /></span>
      <h3>Description</h3>
      <span>The scanner identified a hard-coded secret within the web application and validated that it is active and exploitable, allowing an attacker to authenticate to the associated service, access sensitive data, or perform unauthorized actions.<br /></span><span><br /></span><span>Secrets such as API keys, access tokens, and service credentials are often inadvertently exposed in client-side JavaScript, HTML comments, configuration files, or application responses.<br /></span><span><br /></span><span>Immediate action is required to revoke and rotate the exposed secret.<br /></span>
      <h3>Solution</h3>
      <span>Remove the secret exposure by identifying the root cause of the issue (for example manual data insertion in the code, environment variables being bundled in front-end JavaScript). Rotate the secrets to avoid further reuse in case it has been previously retrieved by a malicious actor.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115118">https://www.tenable.com/plugins/was/115118</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SolarWinds WHD < 2026.1 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115157</link>
            <guid>https://www.tenable.com/plugins/was/115157</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115157 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>SolarWinds WHD < 2026.1 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>SolarWinds WHD version prior to 2026.1 contains a critical authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access to the system, potentially leading to data breaches and system compromise.<br /></span>
      <h3>Solution</h3>
      <span>Apply the available 12.8.8 Hotfix 1 or upgrade to SolarWinds WHD version 2026.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115157">https://www.tenable.com/plugins/was/115157</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SolarWinds WHD < 2026.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115156</link>
            <guid>https://www.tenable.com/plugins/was/115156</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115156 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>SolarWinds WHD < 2026.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of SolarWinds WHD installed on the remote host is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A Security Control Bypass that could allow an unauthenticated attacker to gain access to certain restricted functionality (CVE-2025-40536)<br /></span><span><br /></span><span>- An Unauthenticated JNDI Injection that allow remote unauthenticated attackers can exploit JNDI injection via the Apache Xalan JNDIConnectionPool class to achieve remote code execution (CVE-2025-40551)<br /></span><span><br /></span><span>- An Authentication Bypass that allow remote unauthenticated attackers to execute protected actions without authentication (CVE-2025-40552)<br /></span><span><br /></span><span>- An Authentication Bypass that allow a remote unauthenticated attacker to access to privileged administrative functions (CVE-2025-40554)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Apply the available 12.8.8 Hotfix 1 or upgrade to SolarWinds WHD version 2026.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115156">https://www.tenable.com/plugins/was/115156</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[TLS 1.3 Not Supported Protocol]]></title>
            <link>https://www.tenable.com/plugins/was/115155</link>
            <guid>https://www.tenable.com/plugins/was/115155</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115155 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>TLS 1.3 Not Supported Protocol<br /></span>
      <h3>Description</h3>
      <span>The remote server does not offer TLS 1.3 protocol which is required to provide good encryption security.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115155">https://www.tenable.com/plugins/was/115155</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.113 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115154</link>
            <guid>https://www.tenable.com/plugins/was/115154</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115154 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.113 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.113, 10.1.0-M1 prior to 10.1.50 or 11.0.0-M1 prior to 11.0.15. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. (CVE-2026-24733)<br /></span><span><br /></span><span>- If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. (CVE-2025-66614)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.113 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115154">https://www.tenable.com/plugins/was/115154</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.50 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115153</link>
            <guid>https://www.tenable.com/plugins/was/115153</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115153 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.50 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.113, 10.1.0-M1 prior to 10.1.50 or 11.0.0-M1 prior to 11.0.15. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. (CVE-2026-24733)<br /></span><span><br /></span><span>- If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. (CVE-2025-66614)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.50 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115153">https://www.tenable.com/plugins/was/115153</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.15 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115152</link>
            <guid>https://www.tenable.com/plugins/was/115152</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115152 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.15 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.113, 10.1.0-M1 prior to 10.1.50 or 11.0.0-M1 prior to 11.0.15. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. (CVE-2026-24733)<br /></span><span><br /></span><span>- If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. (CVE-2025-66614)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.15 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115152">https://www.tenable.com/plugins/was/115152</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.83 < 9.0.115 Incomplete OCSP Verification Checks]]></title>
            <link>https://www.tenable.com/plugins/was/115151</link>
            <guid>https://www.tenable.com/plugins/was/115151</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115151 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.83 < 9.0.115 Incomplete OCSP Verification Checks<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.83 prior to 9.0.115, 10.1.0-M7 prior to 10.1.52 or 11.0.0-M1 prior to 11.0.18. It is, therefore, affected by a incomplete OCSP verification checks. When using an OCSP responder, Tomcat's FFM integration with OpenSSL did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.115 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115151">https://www.tenable.com/plugins/was/115151</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M7 < 10.1.52 Incomplete OCSP Verification Checks]]></title>
            <link>https://www.tenable.com/plugins/was/115150</link>
            <guid>https://www.tenable.com/plugins/was/115150</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115150 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M7 < 10.1.52 Incomplete OCSP Verification Checks<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.83 prior to 9.0.115, 10.1.0-M7 prior to 10.1.52 or 11.0.0-M1 prior to 11.0.18. It is, therefore, affected by a incomplete OCSP verification checks. When using an OCSP responder, Tomcat's FFM integration with OpenSSL did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.52 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115150">https://www.tenable.com/plugins/was/115150</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.18 Incomplete OCSP Verification Checks]]></title>
            <link>https://www.tenable.com/plugins/was/115149</link>
            <guid>https://www.tenable.com/plugins/was/115149</guid>
            <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115149 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.18 Incomplete OCSP Verification Checks<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.83 prior to 9.0.115, 10.1.0-M7 prior to 10.1.52 or 11.0.0-M1 prior to 11.0.18. It is, therefore, affected by a incomplete OCSP verification checks. When using an OCSP responder, Tomcat's FFM integration with OpenSSL did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.18 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115149">https://www.tenable.com/plugins/was/115149</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Git Credentials Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115148</link>
            <guid>https://www.tenable.com/plugins/was/115148</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115148 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Git Credentials Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>A Git Credentials configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115148">https://www.tenable.com/plugins/was/115148</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115147</link>
            <guid>https://www.tenable.com/plugins/was/115147</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115147 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>A configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115147">https://www.tenable.com/plugins/was/115147</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Claude Code Settings File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115146</link>
            <guid>https://www.tenable.com/plugins/was/115146</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115146 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Claude Code Settings File Detected<br /></span>
      <h3>Description</h3>
      <span>Claude Code is an agentic coding tool developed by Anthropic that operates directly in the terminal. It uses configuration files named settings.json or settings.local.json to store its settings, including API keys, model preferences, and custom permissions.<br /></span><span><br /></span><span>If an attacker can access these settings files, they may be able to gather sensitive information such as API keys, allowed tools, MCP server configurations, and other security-sensitive settings.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115146">https://www.tenable.com/plugins/was/115146</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Wgetrc Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115145</link>
            <guid>https://www.tenable.com/plugins/was/115145</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115145 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Wgetrc Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>A Wgetrc configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115145">https://www.tenable.com/plugins/was/115145</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MSMTPRC Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115144</link>
            <guid>https://www.tenable.com/plugins/was/115144</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115144 with High Severity</p>
      <h3>Synopsis</h3>
      <span>MSMTPRC Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>A MSMTPRC configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115144">https://www.tenable.com/plugins/was/115144</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[eSMTPRC Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115143</link>
            <guid>https://www.tenable.com/plugins/was/115143</guid>
            <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115143 with High Severity</p>
      <h3>Synopsis</h3>
      <span>eSMTPRC Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>An eSMTPRC configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115143">https://www.tenable.com/plugins/was/115143</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ruby Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115142</link>
            <guid>https://www.tenable.com/plugins/was/115142</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115142 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Ruby Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>A Ruby configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115142">https://www.tenable.com/plugins/was/115142</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nginx 1.3.0 < 1.29.5 SSL Upstream Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115141</link>
            <guid>https://www.tenable.com/plugins/was/115141</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115141 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Nginx 1.3.0 < 1.29.5 SSL Upstream Injection<br /></span>
      <h3>Description</h3>
      <span>According to its Server response header, the installed version of nginx is from 1.3.0 to 1.29.4. It is, therefore, affected by a vulnerability when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side-along with conditions beyond the attacker's control-may be able to inject plain text data into the response from an upstream proxied server.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to nginx version 1.29.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115141">https://www.tenable.com/plugins/was/115141</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Mura CMS < 10.0.580 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115140</link>
            <guid>https://www.tenable.com/plugins/was/115140</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115140 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Mura CMS < 10.0.580 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Mura CMS versions prior to < 10.0.580 suffers from an authentication bypass vulnerability via a specially forged request.<br /></span>
      <h3>Solution</h3>
      <span>Update the affected Mura CMS instance to versions 7.2.5, 7.3.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115140">https://www.tenable.com/plugins/was/115140</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Roundcube Webmail 1.6.x < 1.6.11 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115139</link>
            <guid>https://www.tenable.com/plugins/was/115139</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115139 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Roundcube Webmail 1.6.x < 1.6.11 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Roundcube Webmail is prior to 1.5.10 or 1.6.x prior to 1.6.11. Therefore, it may be affected by a Remote code execution vulnerability by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization (CVE-2025-49113).<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Roundcube Webmail version 1.6.11 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115139">https://www.tenable.com/plugins/was/115139</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Roundcube Webmail < 1.5.10 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115138</link>
            <guid>https://www.tenable.com/plugins/was/115138</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115138 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Roundcube Webmail < 1.5.10 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Roundcube Webmail is prior to 1.5.10 or 1.6.x prior to 1.6.11. Therefore, it may be affected by a Remote code execution vulnerability by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization (CVE-2025-49113).<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Roundcube Webmail version 1.5.10 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115138">https://www.tenable.com/plugins/was/115138</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Roundcube Webmail 1.6.x < 1.6.12 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115137</link>
            <guid>https://www.tenable.com/plugins/was/115137</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115137 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Roundcube Webmail 1.6.x < 1.6.12 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Roundcube Webmail is prior to 1.5.12 or 1.6.x prior to 1.6.12. Therefore, it may be affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An Information disclosure vulnerability in the HTML style sanitizer.<br /></span><span><br /></span><span>- A Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Roundcube Webmail version 1.6.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115137">https://www.tenable.com/plugins/was/115137</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Roundcube Webmail < 1.5.12 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115136</link>
            <guid>https://www.tenable.com/plugins/was/115136</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115136 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Roundcube Webmail < 1.5.12 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Roundcube Webmail is prior to 1.5.12 or 1.6.x prior to 1.6.12. Therefore, it may be affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An Information disclosure vulnerability in the HTML style sanitizer.<br /></span><span><br /></span><span>- A Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Roundcube Webmail version 1.5.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115136">https://www.tenable.com/plugins/was/115136</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OpenCMS <= 15.0 Arbitrary File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115135</link>
            <guid>https://www.tenable.com/plugins/was/115135</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115135 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>OpenCMS <= 15.0 Arbitrary File Upload<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected OpenCMS application is affected by an arbitrary file upload vulnerability :<br /></span><span><br /></span><span>- An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to OpenCMS 16.0.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115135">https://www.tenable.com/plugins/was/115135</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OpenCMS 14.0.0 < 16.0.0 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115134</link>
            <guid>https://www.tenable.com/plugins/was/115134</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115134 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>OpenCMS 14.0.0 < 16.0.0 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected OpenCMS application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An Open redirect vulnerability due to the fact that there is no proper sanitization of the 'URI' parameter.<br /></span><span><br /></span><span>- A Cross-site scripting (XSS) vulnerability in the 'Mercury' template.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to OpenCMS 16.0.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115134">https://www.tenable.com/plugins/was/115134</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OpenCMS < 17.0.0 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115133</link>
            <guid>https://www.tenable.com/plugins/was/115133</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115133 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>OpenCMS < 17.0.0 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected OpenCMS application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- A Cross-Site Scripting which could allow a user having the roles of gallery editor or VFS resource manager will have the permission to upload images in the .svg format containing JavaScript code.<br /></span><span><br /></span><span>- A Cross-Site Scripting which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the "title" field.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to OpenCMS 17.0.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115133">https://www.tenable.com/plugins/was/115133</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OpenCMS <= 18.0.0 Multiple Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115132</link>
            <guid>https://www.tenable.com/plugins/was/115132</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115132 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>OpenCMS <= 18.0.0 Multiple Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected OpenCMS application is affected by multiple Cross-Site Scripting (XSS) vulnerabilities :<br /></span><span><br /></span><span>- A Cross-Site Scripting vulnerability allows a remote attacker to inject a javascript payload via the image title sub-field in the image field.<br /></span><span><br /></span><span>- A Stored Cross-Site Scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter.<br /></span><span><br /></span><span>- A stored Cross-Site Scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to OpenCMS 18.0.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115132">https://www.tenable.com/plugins/was/115132</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Airflow Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115131</link>
            <guid>https://www.tenable.com/plugins/was/115131</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115131 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Airflow Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>Apache Airflow is an open-source platform to programmatically author, schedule, and monitor workflows. By default, Apache Airflow uses a configuration file named airflow.cfg to store its configuration settings.<br /></span><span><br /></span><span>If an attacker can access the airflow.cfg file, they may be able to gather sensitive information about the Airflow instance, such as database connection details, authentication credentials, and other configuration settings.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115131">https://www.tenable.com/plugins/was/115131</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ansible Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115130</link>
            <guid>https://www.tenable.com/plugins/was/115130</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115130 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Ansible Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>Ansible is an open-source automation tool used for configuration management, application deployment, and task automation. Ansible uses a configuration file (ansible.cfg) to define settings and options for its operation.<br /></span><span><br /></span><span>The presence of the Ansible configuration file on a system can pose a security risk if it contains sensitive information such as passwords, API keys, or other credentials.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115130">https://www.tenable.com/plugins/was/115130</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115129</link>
            <guid>https://www.tenable.com/plugins/was/115129</guid>
            <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115129 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>Apache configuration files may contain sensitive information about the web server and its environment. If an attacker is able to access these files, they may be able to gather information that could be used to exploit vulnerabilities in the web server or its applications.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115129">https://www.tenable.com/plugins/was/115129</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ivanti Endpoint Manager Mobile < 12.8.0.0 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115128</link>
            <guid>https://www.tenable.com/plugins/was/115128</guid>
            <pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115128 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Ivanti Endpoint Manager Mobile < 12.8.0.0 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.8.0.0 are affected by a vulnerability allowing an unauthenticated remote attacker to execute arbitrary code on the affected system through a specially crafted request.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Ivanti Endpoint Manager Mobile version 12.8.0.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115128">https://www.tenable.com/plugins/was/115128</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Kubernetes Kustomization Configuration Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115127</link>
            <guid>https://www.tenable.com/plugins/was/115127</guid>
            <pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115127 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Kubernetes Kustomization Configuration Detected<br /></span>
      <h3>Description</h3>
      <span>`kustomization.yml` is a configuration file used by Kustomize, a tool for customizing Kubernetes resource configurations. This file can contain sensitive information such as resource definitions, patches, and overlays that could be exploited by attackers if exposed publicly.<br /></span><span><br /></span><span>If an attacker gains access to the `kustomization.yml` file, they could potentially manipulate Kubernetes resources, leading to unauthorized access, data breaches, or service disruptions within the Kubernetes cluster.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the `kustomization.yml` configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it. If sensitive information like credentials are leaked in the exposed file, they should be revoked and reset on the affected assets.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115127">https://www.tenable.com/plugins/was/115127</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[CodeDeploy Appspec Configuration Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115126</link>
            <guid>https://www.tenable.com/plugins/was/115126</guid>
            <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115126 with High Severity</p>
      <h3>Synopsis</h3>
      <span>CodeDeploy Appspec Configuration Detected<br /></span>
      <h3>Description</h3>
      <span>CodeDeploy `appspec.yml` is a configuration file used in AWS CodeDeploy deployments to define how application files should be copied and what lifecycle event hooks should be executed during the deployment process.<br /></span><span><br /></span><span>This plugin checks for the presence of the `appspec.yml` file in web applications. If this file is publicly accessible, it can lead to the exposure of sensitive information that could be exploited by attackers.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the `appspec.yml` configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it. If sensitive information like credentials are leaked in the exposed file, they should be revoked and reset on the affected assets.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115126">https://www.tenable.com/plugins/was/115126</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Parameters YML Configuration Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115125</link>
            <guid>https://www.tenable.com/plugins/was/115125</guid>
            <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115125 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Parameters YML Configuration Detected<br /></span>
      <h3>Description</h3>
      <span>`parameters.yml` is a configuration file commonly used in Symfony-based web applications to store various settings, including database credentials, API keys, and other sensitive information.<br /></span><span><br /></span><span>This plugin checks for the presence of the `parameters.yml` file in web applications. If this file is publicly accessible, it can lead to the exposure of sensitive information that could be exploited by attackers.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the `parameters.yml` configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it. If sensitive information like credentials are leaked in the exposed file, they should be revoked and reset on the affected assets.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115125">https://www.tenable.com/plugins/was/115125</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Firebase Configuration Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115124</link>
            <guid>https://www.tenable.com/plugins/was/115124</guid>
            <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115124 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Firebase Configuration Detected<br /></span>
      <h3>Description</h3>
      <span>Firebase is a platform developed by Google for creating mobile and web applications. It provides various services, including real-time databases, authentication, and hosting.<br /></span><span><br /></span><span>This plugin checks for the presence of Firebase configuration files in web applications. These files often contain sensitive information such as API keys, project IDs, and other configuration details that could be exploited by attackers if exposed publicly.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the firebase configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it. If sensitive information like credentials are leaked in the exposed file, they should be revoked and reset on the affected assets.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115124">https://www.tenable.com/plugins/was/115124</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OpenClaw Gateway Dashboard Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115123</link>
            <guid>https://www.tenable.com/plugins/was/115123</guid>
            <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115123 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>OpenClaw Gateway Dashboard Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected a publicly accessible OpenClaw Gateway Dashboard instance on the target application. OpenClaw is your own personal AI assistant. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>If the application is not expected to be public, restrict access using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115123">https://www.tenable.com/plugins/was/115123</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Versa Concerto 11.4.x < 12.1.2 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115121</link>
            <guid>https://www.tenable.com/plugins/was/115121</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115121 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Versa Concerto 11.4.x < 12.1.2 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Versa Concerto version 11.4.x prior to 12.1.2 is affected by an authentication bypass vulnerability. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized access to the internal Actuator endpoint.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Versa Concerto version 12.1.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115121">https://www.tenable.com/plugins/was/115121</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Vite < 4.5.11 / 5.0.x < 5.4.16 / 6.0.x < 6.0.13 / 6.1.x < 6.1.3 / 6.2.x < 6.2.4 Arbitrary File Read]]></title>
            <link>https://www.tenable.com/plugins/was/115120</link>
            <guid>https://www.tenable.com/plugins/was/115120</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115120 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Vite < 4.5.11 / 5.0.x < 5.4.16 / 6.0.x < 6.0.13 / 6.1.x < 6.1.3 / 6.2.x < 6.2.4 Arbitrary File Read<br /></span>
      <h3>Description</h3>
      <span>Vite version prior to 4.5.11, 5.0.x prior to 5.4.16, 6.0.x prior to 6.0.13, 6.1.x prior to 6.1.3 or 6.2.x prior to 6.2.4 are affected by a vulnerability allowing unauthenticated remote attackers to read arbitrary files on the affected host when the app is exposing the Vite dev server to the network.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Vite 4.5.11, 5.4.16, 6.0.13, 6.1.3, 6.2.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115120">https://www.tenable.com/plugins/was/115120</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Redis Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115119</link>
            <guid>https://www.tenable.com/plugins/was/115119</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115119 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Redis Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>A Redis configuration file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the config file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115119">https://www.tenable.com/plugins/was/115119</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SmarterMail < build 9413 Unrestricted File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115117</link>
            <guid>https://www.tenable.com/plugins/was/115117</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115117 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>SmarterMail < build 9413 Unrestricted File Upload<br /></span>
      <h3>Description</h3>
      <span>SmarterMail version prior to build 9413 are affected by an Unrestricted File Upload vulnerability. An unauthenticated attacker can exploit this issue to upload arbitrary files to the server, which could lead to remote code execution.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to SmarterMail build 9413 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115117">https://www.tenable.com/plugins/was/115117</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[OpenAssistantGPT Chatbot Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115116</link>
            <guid>https://www.tenable.com/plugins/was/115116</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115116 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>OpenAssistantGPT Chatbot Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected a publicly accessible OpenAssistantGPT chatbot on the target application. OpenAssistantGPT is community open-Source SaaS for crafting/building/creating chatbots with OpenAI's assistant API that you can add to your website. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115116">https://www.tenable.com/plugins/was/115116</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Zimbra Collaboration 10.0.x < 10.0.18 / 10.1.x < 10.1.13 Local File Inclusion]]></title>
            <link>https://www.tenable.com/plugins/was/115122</link>
            <guid>https://www.tenable.com/plugins/was/115122</guid>
            <pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115122 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Zimbra Collaboration 10.0.x < 10.0.18 / 10.1.x < 10.1.13 Local File Inclusion<br /></span>
      <h3>Description</h3>
      <span>Zimbra Collaboration versions prior to 10.0.18 and 10.1.13 are vulnerable to Local File Inclusion (LFI) in the Webmail Classic UI due to improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can exploit this vulnerability by crafting requests to the /h/rest endpoint, which can lead to the inclusion of arbitrary files from the WebRoot directory.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Zimbra 10.0.18 or 10.1.13 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115122">https://www.tenable.com/plugins/was/115122</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Deep Chat Chatbot Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115115</link>
            <guid>https://www.tenable.com/plugins/was/115115</guid>
            <pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115115 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Deep Chat Chatbot Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected a publicly accessible Deep Chat chatbot on the target application. Deep Chat is an open-source framework for building AI chatbots that can be integrated into websites and applications. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115115">https://www.tenable.com/plugins/was/115115</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SSH Known Hosts File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115114</link>
            <guid>https://www.tenable.com/plugins/was/115114</guid>
            <pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115114 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>SSH Known Hosts File Detected<br /></span>
      <h3>Description</h3>
      <span>A SSH Known Hosts file have been detected on the target web application. These files may contain sensitive information which could assist an attack to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the SSH known hosts file or locate it outside the public webroot where possible.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115114">https://www.tenable.com/plugins/was/115114</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Livewire 3.x < 3.6.4 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115113</link>
            <guid>https://www.tenable.com/plugins/was/115113</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115113 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Livewire 3.x < 3.6.4 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Livewire is a full-stack framework for Laravel that makes building dynamic interfaces simple, without leaving the comfort of Laravel.<br /></span><span><br /></span><span>A remote code execution vulnerability exists in Livewire versions prior to 3.6.4 due to improper handling of serialized data during the component hydration process. An attacker can exploit this vulnerability by sending a specially crafted request containing malicious serialized data to the server, which is then deserialized and executed, allowing the attacker to execute arbitrary code on the server.<br /></span><span><br /></span><span>Note: Depending on the identified version of Livewire, the plugin indicates that the website is **potentially** vulnerable if it uses version 3.6.3 (vulnerable) or 3.6.4 (patched).<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Livewire version 3.6.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115113">https://www.tenable.com/plugins/was/115113</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Livewire Request Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115112</link>
            <guid>https://www.tenable.com/plugins/was/115112</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115112 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Livewire Request Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected the usage of the Livewire framework in the target web application. Livewire is a full-stack framework for Laravel that makes building dynamic interfaces simple, without leaving the comfort of Laravel.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115112">https://www.tenable.com/plugins/was/115112</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Private Key File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115111</link>
            <guid>https://www.tenable.com/plugins/was/115111</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115111 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Private Key File Detected<br /></span>
      <h3>Description</h3>
      <span>Private keys are cryptographic credentials used for secure communications in protocols like SSL/TLS, SSH, and JWT signing. If exposed, an attacker can impersonate the server, decrypt sensitive communications, or forge authentication tokens to gain unauthorized access to systems and data.<br /></span>
      <h3>Solution</h3>
      <span>Immediately rotate and revoke the exposed private key. Remove the private key file from the publicly accessible location and store it in a secure vault or secrets management system (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault). Restrict file system permissions to prevent unauthorized access. Audit logs to identify potential unauthorized use of the compromised key.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115111">https://www.tenable.com/plugins/was/115111</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JetBrains TeamCity Guest Access Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115110</link>
            <guid>https://www.tenable.com/plugins/was/115110</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115110 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>JetBrains TeamCity Guest Access Detected<br /></span>
      <h3>Description</h3>
      <span>JetBrains TeamCity is a continuous integration and build management system that allows guest access if the feature is enabled. If guest login is enabled, an attacker can access the TeamCity server without authentication, potentially leading to unauthorized access to sensitive information and system functionalities.<br /></span>
      <h3>Solution</h3>
      <span>If guest login is not required, disable the guest login feature in the TeamCity administration interface to prevent unauthorized access.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115110">https://www.tenable.com/plugins/was/115110</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JetBrains TeamCity Registration Enabled]]></title>
            <link>https://www.tenable.com/plugins/was/115109</link>
            <guid>https://www.tenable.com/plugins/was/115109</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115109 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>JetBrains TeamCity Registration Enabled<br /></span>
      <h3>Description</h3>
      <span>JetBrains TeamCity is a continuous integration and build management system. By default, TeamCity allows users to self-register for an account. If the self-registration feature is enabled, an attacker can create an account without any authorization, potentially leading to unauthorized access to the TeamCity server.<br /></span>
      <h3>Solution</h3>
      <span>Disable the self-registration feature in the TeamCity administration interface to prevent unauthorized account creation.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115109">https://www.tenable.com/plugins/was/115109</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[SAP NetWeaver ICM Info Sensitive Information Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115108</link>
            <guid>https://www.tenable.com/plugins/was/115108</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115108 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>SAP NetWeaver ICM Info Sensitive Information Disclosure<br /></span>
      <h3>Description</h3>
      <span>SAP NetWeaver Internet Communication Manager (ICM) includes an information page that can disclose sensitive information about the SAP platform, such as operating system version, SAP version, IP address, and other details. If this page is accessible without proper authentication, it can expose information that could be leveraged by attackers to plan further attacks against the system.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to administrative functionality, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115108">https://www.tenable.com/plugins/was/115108</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Ambassador API Gateway Diagnostics Sensitive Information Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115107</link>
            <guid>https://www.tenable.com/plugins/was/115107</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115107 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Ambassador API Gateway Diagnostics Sensitive Information Disclosure<br /></span>
      <h3>Description</h3>
      <span>Ambassador API Gateway includes a diagnostics portal that provides detailed information about the API Gateway's configuration and operation. If this portal is accessible without proper authentication, it can expose sensitive information such as service mappings, API endpoints, routing configurations, and internal cluster information. An attacker could leverage this information to plan further attacks against the system.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to administrative functionality, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115107">https://www.tenable.com/plugins/was/115107</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Shibboleth SSO Open Redirect]]></title>
            <link>https://www.tenable.com/plugins/was/115106</link>
            <guid>https://www.tenable.com/plugins/was/115106</guid>
            <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115106 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Shibboleth SSO Open Redirect<br /></span>
      <h3>Description</h3>
      <span>Shibboleth Service Provider (SP) contains an open redirect vulnerability. An attacker can exploit this vulnerability to redirect users to malicious websites, potentially leading to phishing attacks or other malicious activities. This issue arises when the 'redirectLimit' configuration option is not properly set.<br /></span>
      <h3>Solution</h3>
      <span>Configure the 'redirectLimit' option in the Shibboleth Service Provider configuration to prevents the injection of redirect locations.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115106">https://www.tenable.com/plugins/was/115106</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N8n < 1.121.0 Remote Code Execution (Ni8mare)]]></title>
            <link>https://www.tenable.com/plugins/was/115105</link>
            <guid>https://www.tenable.com/plugins/was/115105</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115105 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>N8n < 1.121.0 Remote Code Execution (Ni8mare)<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of n8n running on the remote host is before 1.121.0. It is, therefore, affected by an unauthentcated file access vulnerability which can leads to remote code execution.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to n8n version 1.121.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115105">https://www.tenable.com/plugins/was/115105</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N8n < 1.121.3 Arbitrary File Write]]></title>
            <link>https://www.tenable.com/plugins/was/115104</link>
            <guid>https://www.tenable.com/plugins/was/115104</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115104 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>N8n < 1.121.3 Arbitrary File Write<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of n8n running on the remote host is after 0.123.0 and before 1.121.3. It is, therefore, affected by an authenticated arbitrary file write.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to n8n version 1.121.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115104">https://www.tenable.com/plugins/was/115104</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N8n < 2.0.0 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115103</link>
            <guid>https://www.tenable.com/plugins/was/115103</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115103 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>N8n < 2.0.0 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of n8n running on the remote host is 1.0.0 or later and before 2.0.0. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- An authenticated arbitrary file read and file write vulnerability<br /></span><span><br /></span><span>- An authenticated arbitrary command execution vulnerability in Pyodide based Python code node<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to n8n version 2.0.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115103">https://www.tenable.com/plugins/was/115103</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[N8n < 2.2.2 Unauthenticated Forged Webhooks]]></title>
            <link>https://www.tenable.com/plugins/was/115102</link>
            <guid>https://www.tenable.com/plugins/was/115102</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115102 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>N8n < 2.2.2 Unauthenticated Forged Webhooks<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of n8n running on the remote host is 0.150 or later and before 2.2.2. It is, therefore, affected by an authentication bypass in the Stripe trigger, allowing unauthenticated parties to trigger workflows by sending forget Stripe webhook events.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to n8n version 2.2.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115102">https://www.tenable.com/plugins/was/115102</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 6.x < 6.0.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115101</link>
            <guid>https://www.tenable.com/plugins/was/115101</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115101 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 6.x < 6.0.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.9.x prior to 5.4.2, or 6.x prior to 6.0.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. (CVE-2025-63082)<br /></span><span><br /></span><span>- Lack of output escaping leads to a XSS vector in the pagebreak and pagenavigation plugins. (CVE-2025-63083)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 6.0.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115101">https://www.tenable.com/plugins/was/115101</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 3.9.x < 5.4.2 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115100</link>
            <guid>https://www.tenable.com/plugins/was/115100</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115100 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 3.9.x < 5.4.2 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 3.9.x prior to 5.4.2, or 6.x prior to 6.0.2. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. (CVE-2025-63082)<br /></span><span><br /></span><span>- Lack of output escaping leads to a XSS vector in the pagebreak and pagenavigation plugins. (CVE-2025-63083)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 5.4.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115100">https://www.tenable.com/plugins/was/115100</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Next.js Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115098</link>
            <guid>https://www.tenable.com/plugins/was/115098</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115098 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Next.js Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>Next.js is a popular React framework for building web applications. By default, Next.js applications may include a configuration file named next.config.js, which contains various settings and options for the application. If this configuration file is accessible via the web server, it can expose sensitive information about the application's structure, environment variables, and other configurations that could be exploited by attackers.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115098">https://www.tenable.com/plugins/was/115098</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Sitecore Debug Page Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115097</link>
            <guid>https://www.tenable.com/plugins/was/115097</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115097 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Sitecore Debug Page Detected<br /></span>
      <h3>Description</h3>
      <span>Sitecore is a popular web content management system (WCMS) used for building and managing websites. When the debug page is accessible, it can expose sensitive information about the application's configuration, environment, and code structure. This information can be exploited by attackers to identify vulnerabilities and launch targeted attacks against the application.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the '/sitecore/' directory or ensure debug mode is disabled in production environments.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115097">https://www.tenable.com/plugins/was/115097</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Commvault CommandCenter < 11.36.60 Unauthorized API Access]]></title>
            <link>https://www.tenable.com/plugins/was/115096</link>
            <guid>https://www.tenable.com/plugins/was/115096</guid>
            <pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115096 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Commvault CommandCenter < 11.36.60 Unauthorized API Access<br /></span>
      <h3>Description</h3>
      <span>Commvault CommandCenter versions prior to 11.36.60 contain a vulnerability in a known login mechanism that allows unauthenticated attackers to execute API calls without requiring user credentials.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Commvault CommandCenter version 11.36.60 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115096">https://www.tenable.com/plugins/was/115096</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Symfony Conflicting Headers Information Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115099</link>
            <guid>https://www.tenable.com/plugins/was/115099</guid>
            <pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115099 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Symfony Conflicting Headers Information Disclosure<br /></span>
      <h3>Description</h3>
      <span>The remote web application is using Symfony, a PHP framework. It is affected by an information disclosure vulnerability arising from conflicting proxy headers.<br /></span><span><br /></span><span>When both 'Forwarded' and 'X-Forwarded-*' headers are present in a request, a misconfiguration in Symfony's trusted proxy settings can trigger a 'ConflictingHeadersException'. If the application is running with debug mode enabled in a production environment, this exception can expose sensitive environment details, such as SMTP credentials, internal application paths, and system configuration.<br /></span>
      <h3>Solution</h3>
      <span>Disable debug mode in production environments. Review and update the application's 'trusted_proxies' configuration to ensure it correctly handles incoming headers. Configure the application to prioritize or strictly define which proxy headers (standard 'Forwarded' vs 'X-Forwarded-*') are accepted, preventing conflicts.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115099">https://www.tenable.com/plugins/was/115099</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[JFrog Artifactory Artifacts Repository Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115095</link>
            <guid>https://www.tenable.com/plugins/was/115095</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115095 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>JFrog Artifactory Artifacts Repository Detected<br /></span>
      <h3>Description</h3>
      <span>JFrog Artifactory is a popular repository management tool used to store and manage software artifacts. If the Artifacts repository is detected and accessible, it may expose sensitive information or allow unauthorized access to stored artifacts.<br /></span>
      <h3>Solution</h3>
      <span>If the application is not expected to be public, disable anonymous access in the Artifactory administration settings. Alternatively, restrict access using network access controls (ACLs) or web server configuration (e.g., .htaccess for Apache, allow/deny for Nginx) to limit access to known IP addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115095">https://www.tenable.com/plugins/was/115095</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Nexus Repository Anonymous Access]]></title>
            <link>https://www.tenable.com/plugins/was/115094</link>
            <guid>https://www.tenable.com/plugins/was/115094</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115094 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Nexus Repository Anonymous Access<br /></span>
      <h3>Description</h3>
      <span>Nexus Repository Manager is a popular repository management tool used to store and manage software artifacts. If anonymous access is enabled, unauthenticated users can list and browse repositories, potentially exposing private artifacts such as source code, packages, and Docker images.<br /></span>
      <h3>Solution</h3>
      <span>Disable anonymous access in the Nexus Repository Manager settings.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115094">https://www.tenable.com/plugins/was/115094</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.1.x < 8.1.34 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115093</link>
            <guid>https://www.tenable.com/plugins/was/115093</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115093 with High Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.1.x < 8.1.34 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.30, 8.3.x prior to 8.3.29, 8.4.x prior to 8.4.16, or 8.5.x prior to 8.5.1. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Information leak of memory in getimagesize. (CVE-2025-14177)<br /></span><span><br /></span><span>- Heap buffer overflow in array_merge(). (CVE-2025-14178)<br /></span><span><br /></span><span>- PDO quoting result null dereference. (CVE-2025-14180)<br /></span><span><br /></span><span>- Unbounded recursion and stack consumption. (CVE-2025-67899)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.1.34 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115093">https://www.tenable.com/plugins/was/115093</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Behat Configuration File Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115092</link>
            <guid>https://www.tenable.com/plugins/was/115092</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115092 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Behat Configuration File Detected<br /></span>
      <h3>Description</h3>
      <span>Behat is a Behavior Driven Development (BDD) framework for PHP. It allows the execution of feature documentation written in business-facing text. Behat uses a configuration file named behat.yml to set up various options and parameters for running tests.<br /></span><span><br /></span><span>The presence of the behat.yml configuration file on a web server may expose sensitive information, such as database credentials, API keys, or other configuration details that could be exploited by an attacker.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the configuration file is not deployed with the application or, at least, is not exposed in a web server directory by setting proper permissions on it.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115092">https://www.tenable.com/plugins/was/115092</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.2.x < 8.2.30 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115091</link>
            <guid>https://www.tenable.com/plugins/was/115091</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115091 with High Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.2.x < 8.2.30 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.30, 8.3.x prior to 8.3.29, 8.4.x prior to 8.4.16, or 8.5.x prior to 8.5.1. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Information leak of memory in getimagesize. (CVE-2025-14177)<br /></span><span><br /></span><span>- Heap buffer overflow in array_merge(). (CVE-2025-14178)<br /></span><span><br /></span><span>- PDO quoting result null dereference. (CVE-2025-14180)<br /></span><span><br /></span><span>- Unbounded recursion and stack consumption. (CVE-2025-67899)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.2.30 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115091">https://www.tenable.com/plugins/was/115091</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.3.x < 8.3.29 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115090</link>
            <guid>https://www.tenable.com/plugins/was/115090</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115090 with High Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.3.x < 8.3.29 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.30, 8.3.x prior to 8.3.29, 8.4.x prior to 8.4.16, or 8.5.x prior to 8.5.1. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Information leak of memory in getimagesize. (CVE-2025-14177)<br /></span><span><br /></span><span>- Heap buffer overflow in array_merge(). (CVE-2025-14178)<br /></span><span><br /></span><span>- PDO quoting result null dereference. (CVE-2025-14180)<br /></span><span><br /></span><span>- Unbounded recursion and stack consumption. (CVE-2025-67899)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.3.29 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115090">https://www.tenable.com/plugins/was/115090</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.4.x < 8.4.16 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115089</link>
            <guid>https://www.tenable.com/plugins/was/115089</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115089 with High Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.4.x < 8.4.16 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.30, 8.3.x prior to 8.3.29, 8.4.x prior to 8.4.16, or 8.5.x prior to 8.5.1. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Information leak of memory in getimagesize. (CVE-2025-14177)<br /></span><span><br /></span><span>- Heap buffer overflow in array_merge(). (CVE-2025-14178)<br /></span><span><br /></span><span>- PDO quoting result null dereference. (CVE-2025-14180)<br /></span><span><br /></span><span>- Unbounded recursion and stack consumption. (CVE-2025-67899)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.4.16 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115089">https://www.tenable.com/plugins/was/115089</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PHP 8.5.x < 8.5.1 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115088</link>
            <guid>https://www.tenable.com/plugins/was/115088</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115088 with High Severity</p>
      <h3>Synopsis</h3>
      <span>PHP 8.5.x < 8.5.1 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of PHP installed on the remote host is 8.2.x prior to 8.2.30, 8.3.x prior to 8.3.29, 8.4.x prior to 8.4.16, or 8.5.x prior to 8.5.1. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Information leak of memory in getimagesize. (CVE-2025-14177)<br /></span><span><br /></span><span>- Heap buffer overflow in array_merge(). (CVE-2025-14178)<br /></span><span><br /></span><span>- PDO quoting result null dereference. (CVE-2025-14180)<br /></span><span><br /></span><span>- Unbounded recursion and stack consumption. (CVE-2025-67899)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to PHP version 8.5.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115088">https://www.tenable.com/plugins/was/115088</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[PostgREST API Server Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115087</link>
            <guid>https://www.tenable.com/plugins/was/115087</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115087 with High Severity</p>
      <h3>Synopsis</h3>
      <span>PostgREST API Server Detected<br /></span>
      <h3>Description</h3>
      <span>PostgREST is a standalone web server that turns your PostgreSQL database directly into a RESTful API. By default, PostgREST does not implement any authentication or access control mechanisms, which can lead to unauthorized access to sensitive data if the server is exposed to untrusted networks without proper safeguards in place.<br /></span><span><br /></span><span>An attacker who discovers an exposed PostgREST server could potentially retrieve, modify, or delete data from the underlying PostgreSQL database, depending on the database permissions configured for the PostgREST user. This could lead to data breaches, data loss, or unauthorized data manipulation.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115087">https://www.tenable.com/plugins/was/115087</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[FreeBPX 17.0.x < 17.0.23 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115086</link>
            <guid>https://www.tenable.com/plugins/was/115086</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115086 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>FreeBPX 17.0.x < 17.0.23 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the FreePBOX application running on the remote host is prior to 16.0.44 or 17.x prior to 17.0.23. It is, therefore, affected by an authentication bypass when providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to FreeBPX version 17.0.23 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115086">https://www.tenable.com/plugins/was/115086</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[FreeBPX < 16.0.44 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115085</link>
            <guid>https://www.tenable.com/plugins/was/115085</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115085 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>FreeBPX < 16.0.44 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the FreePBOX application running on the remote host is prior to 16.0.44 or 17.x prior to 17.0.23. It is, therefore, affected by an authentication bypass when providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to FreeBPX version 16.0.44 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115085">https://www.tenable.com/plugins/was/115085</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[FreeBPX 17.0.x < 17.0.6 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115084</link>
            <guid>https://www.tenable.com/plugins/was/115084</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115084 with High Severity</p>
      <h3>Synopsis</h3>
      <span>FreeBPX 17.0.x < 17.0.6 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the FreePBOX application running on the remote host is prior to 16.0.92 or 17.x prior to 17.0.6. It is, therefore, affected by multiples vulnerabilities :<br /></span><span><br /></span><span>- An arbitrary file upload vulnerability in the FreePBX Endpoint Management module affecting the fwbrand parameter.<br /></span><span><br /></span><span>- SQL injection vulnerabilities exist in the FreePBX Endpoint Management module affecting multiple parameters.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to FreeBPX version 17.0.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115084">https://www.tenable.com/plugins/was/115084</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[FreeBPX < 16.0.92 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115083</link>
            <guid>https://www.tenable.com/plugins/was/115083</guid>
            <pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115083 with High Severity</p>
      <h3>Synopsis</h3>
      <span>FreeBPX < 16.0.92 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the FreePBOX application running on the remote host is prior to 16.0.92 or 17.x prior to 17.0.6. It is, therefore, affected by multiples vulnerabilities :<br /></span><span><br /></span><span>- An arbitrary file upload vulnerability in the FreePBX Endpoint Management module affecting the fwbrand parameter.<br /></span><span><br /></span><span>- SQL injection vulnerabilities exist in the FreePBX Endpoint Management module affecting multiple parameters.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to FreeBPX version 16.0.92 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115083">https://www.tenable.com/plugins/was/115083</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Astro < 5.15.8 Reflected Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115082</link>
            <guid>https://www.tenable.com/plugins/was/115082</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115082 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Astro < 5.15.8 Reflected Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>Astro framework versions prior to 5.15.8 are vulnerable to a Reflected Cross-Site Scripting ...<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Astro 5.15.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115082">https://www.tenable.com/plugins/was/115082</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Jira 11.x < 11.2.0 XML External Entity Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115081</link>
            <guid>https://www.tenable.com/plugins/was/115081</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115081 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Jira 11.x < 11.2.0 XML External Entity Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Jira application running on the remote host is 10.3.x prior to 10.3.13 or 11.x prior to 11.2.0. It is, therefore, affected by a XML External Entity Injection (XXE) vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Jira version 11.2.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115081">https://www.tenable.com/plugins/was/115081</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Jira 10.3.x < 10.3.13 XML External Entity Injection]]></title>
            <link>https://www.tenable.com/plugins/was/115080</link>
            <guid>https://www.tenable.com/plugins/was/115080</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115080 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Jira 10.3.x < 10.3.13 XML External Entity Injection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Jira application running on the remote host is 10.3.x prior to 10.3.13 or 11.x prior to 11.2.0. It is, therefore, affected by a XML External Entity Injection (XXE) vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Jira version 10.3.13 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115080">https://www.tenable.com/plugins/was/115080</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Kubernetes Configuration Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115079</link>
            <guid>https://www.tenable.com/plugins/was/115079</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115079 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Kubernetes Configuration Detected<br /></span>
      <h3>Description</h3>
      <span>Kubernetes is an open-source container orchestration platform used to automate the deployment, scaling, and management of containerized applications. Kubernetes configuration files, such as YAML manifests, define resources like Deployments, Services, ConfigMaps, and Secrets.\n\nWhen exposed with the web application, these configuration files can be used by an attacker to gain access to sensitive information, including cluster architecture details, environment variables, and potentially secrets or credentials.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that Kubernetes configuration files (such as YAML manifests defining Deployments, Services, ConfigMaps, and Secrets) are not deployed with the application or exposed in a web server directory. Set proper permissions to restrict access to these files. If sensitive information like credentials or secrets are leaked in the exposed configuration, they should be revoked and reset on the affected assets.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115079">https://www.tenable.com/plugins/was/115079</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Gladinet CentreStack / Triofox < 16.12.10420.56791 Hardcoded Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/115078</link>
            <guid>https://www.tenable.com/plugins/was/115078</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115078 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Gladinet CentreStack / Triofox < 16.12.10420.56791 Hardcoded Credentials<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Gladinet CentreStack / Triofox running on the remote host is prior to 16.12.10420.56791. It is, therefore, affected by an arbitrary local file inclusion due to the CentreStack / Triofox portal's use hardcoded values for their implementation of the AES cryptoscheme.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Gladinet CentreStack / Triofox version 16.12.10420.56791 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115078">https://www.tenable.com/plugins/was/115078</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Gladinet CentreStack < 16.4.10315.56368 Insecure Deserialization]]></title>
            <link>https://www.tenable.com/plugins/was/115077</link>
            <guid>https://www.tenable.com/plugins/was/115077</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115077 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Gladinet CentreStack < 16.4.10315.56368 Insecure Deserialization<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Gladinet CentreStack running on the remote host is prior to 16.4.10315.56368. It is, therefore, affected by an Insecure Deserialization due to the CentreStack portal's use an hardcoded machineKey.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Gladinet CentreStack version 16.4.10315.56368 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115077">https://www.tenable.com/plugins/was/115077</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Gladinet Triofox < 16.7.10368.56560 Improper Access Control]]></title>
            <link>https://www.tenable.com/plugins/was/115076</link>
            <guid>https://www.tenable.com/plugins/was/115076</guid>
            <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115076 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Gladinet Triofox < 16.7.10368.56560 Improper Access Control<br /></span>
      <h3>Description</h3>
      <span>Gladinet Triofox version prior to 16.7.10368.56560 are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.<br /></span>
      <h3>Solution</h3>
      <span>Update to Gladinet Triofox version 16.7.10368.56560 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115076">https://www.tenable.com/plugins/was/115076</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GeoServer < 2.25.6 / 2.26.x < 2.26.2 XML External Entity]]></title>
            <link>https://www.tenable.com/plugins/was/115075</link>
            <guid>https://www.tenable.com/plugins/was/115075</guid>
            <pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115075 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>GeoServer < 2.25.6 / 2.26.x < 2.26.2 XML External Entity<br /></span>
      <h3>Description</h3>
      <span>GeoServer versions prior to < 2.25.6, 2.26.x < 2.26.2 are affected by an XML External Entity (XXE) vulnerability. An attacker could exploit this vulnerability by sending a specially crafted XML request to the GeoServer instance, which could lead to unauthorized access to sensitive data, server-side request forgery (SSRF), or denial of service (DoS) attacks.<br /></span>
      <h3>Solution</h3>
      <span>Update to GeoServer version 2.25.6 or 2.26.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115075">https://www.tenable.com/plugins/was/115075</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal JSON:API User Enumeration]]></title>
            <link>https://www.tenable.com/plugins/was/115074</link>
            <guid>https://www.tenable.com/plugins/was/115074</guid>
            <pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115074 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal JSON:API User Enumeration<br /></span>
      <h3>Description</h3>
      <span>The remote Drupal site has the JSON:API module enabled. By default, this module may allow an unauthenticated, remote attacker to enumerate usernames by sending requests to the JSON:API endpoint. An attacker can leverage this information to conduct further attacks, such as brute-force password guessing.<br /></span>
      <h3>Solution</h3>
      <span>Disable the JSON:API module if is not required or restrict access to the user list with a module like 'JSON:API Permission Access' module or a similar access control module. You can also restrict access to the JSON:API endpoint at the web server level.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115074">https://www.tenable.com/plugins/was/115074</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tika < 3.2.2 XML External Entity]]></title>
            <link>https://www.tenable.com/plugins/was/115073</link>
            <guid>https://www.tenable.com/plugins/was/115073</guid>
            <pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115073 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tika < 3.2.2 XML External Entity<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Apache Tika running on the remote host is prior to 3.2.2. It is, therefore, affected by an XML External Entity (XXE) vulnerability via a crafted XFA file inside of a PDF.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Apache Tika version 3.2.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115073">https://www.tenable.com/plugins/was/115073</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Forms Login Panel Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115072</link>
            <guid>https://www.tenable.com/plugins/was/115072</guid>
            <pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115072 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Forms Login Panel Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) Forms Login panel on a web application.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115072">https://www.tenable.com/plugins/was/115072</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache 2.4.x < 2.4.66 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115071</link>
            <guid>https://www.tenable.com/plugins/was/115071</guid>
            <pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115071 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache 2.4.x < 2.4.66 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Apache running on the remote host is 2.4.x prior to 2.4.66. It is, therefore, affected by multiple vulnerabilities:<br /></span><span><br /></span><span>- Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content. (CVE-2025-59775)<br /></span><span><br /></span><span>- A security bypass vulnerability exists involving the interaction between mod_userdir and suexec. Users with access to use the RequestHeader directive in .htaccess via AllowOverride FileInfo can bypass restrictions and cause some CGI scripts to run under an unexpected userid. (CVE-2025-66200)<br /></span><span><br /></span><span>- An integer overflow in mod_md (ACME) in Apache HTTP Server allows for unintended retry intervals. In the case of failed ACME certificate renewal, the backoff timer can become 0, causing attempts to renew the certificate to repeat without delays (infinite loop) until success. (CVE-2025-55753)<br /></span><span><br /></span><span>- A vulnerability in mod_cgid allows for the injection of query strings into command executions. Apache HTTP Server with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. (CVE-2025-58098)<br /></span><span><br /></span><span>- Improper Neutralization of Escape, Meta, or Control Sequences in Apache HTTP Server allows environment variables set via the Apache configuration to unexpectedly supersede variables calculated by the server for CGI programs. (CVE-2025-65082)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache version 2.4.66 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115071">https://www.tenable.com/plugins/was/115071</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) < 6.5.23.0 XML External Entity]]></title>
            <link>https://www.tenable.com/plugins/was/115070</link>
            <guid>https://www.tenable.com/plugins/was/115070</guid>
            <pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115070 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) < 6.5.23.0 XML External Entity<br /></span>
      <h3>Description</h3>
      <span>Adobe Experience Manager (AEM) versions prior to 6.5.23.0 are affected by an XML External Entity (XXE) vulnerability. An attacker could exploit this vulnerability by sending a specially crafted XML request to the affected system, which could lead to unauthorized access to sensitive information or system compromise.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Adobe Experience Manager version 6.5.23.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115070">https://www.tenable.com/plugins/was/115070</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[React Server Components 19.0 / 19.1.0 / 19.1.1 / 19.2.0 Remote Code Execution (React2Shell)]]></title>
            <link>https://www.tenable.com/plugins/was/115069</link>
            <guid>https://www.tenable.com/plugins/was/115069</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115069 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>React Server Components 19.0 / 19.1.0 / 19.1.1 / 19.2.0 Remote Code Execution (React2Shell)<br /></span>
      <h3>Description</h3>
      <span>React Server Components react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0 are vulnerable to an Unauthenticated Remote Code Execution. An attacker can exploit a flaw in how React decodes payloads sent to React Server Function endpoints through specially crafted requests.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade the React Server Components to 19.0.1 or 19.1.2 or 19.2.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115069">https://www.tenable.com/plugins/was/115069</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Groovy Console]]></title>
            <link>https://www.tenable.com/plugins/was/115068</link>
            <guid>https://www.tenable.com/plugins/was/115068</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115068 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Groovy Console<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) expose a Groovy console that allows users to execute arbitrary Groovy scripts on the server. This can lead to remote code execution and complete compromise of the AEM instance and the underlying server.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115068">https://www.tenable.com/plugins/was/115068</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Unauthenticated Cache Purge]]></title>
            <link>https://www.tenable.com/plugins/was/115067</link>
            <guid>https://www.tenable.com/plugins/was/115067</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115067 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Unauthenticated Cache Purge<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) Dispatcher cache purge functionality that is accessible without authentication. An unauthenticated cache purge can allow an attacker to clear cached content, leading to potential service disruption or performance degradation.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115067">https://www.tenable.com/plugins/was/115067</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Merge Metadata Servlet Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115066</link>
            <guid>https://www.tenable.com/plugins/was/115066</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115066 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Merge Metadata Servlet Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) Merge Metadata Servlet. The Merge Metadata Servlet is used to merge metadata from different sources within the AEM environment.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115066">https://www.tenable.com/plugins/was/115066</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) QueryBuilder JCR Hashed Password Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115065</link>
            <guid>https://www.tenable.com/plugins/was/115065</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115065 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) QueryBuilder JCR Hashed Password Disclosure<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) QueryBuilder Servlet is prone to an information disclosure vulnerability. An unauthenticated attacker can exploit this issue to retrieve the hashed passwords of users in the AEM instance by sending a specially crafted HTTP request to the QueryBuilder Servlet endpoint.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115065">https://www.tenable.com/plugins/was/115065</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) QueryBuilder JCR Role Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115064</link>
            <guid>https://www.tenable.com/plugins/was/115064</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115064 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) QueryBuilder JCR Role Disclosure<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) QueryBuilder Servlet is prone to an information disclosure vulnerability. An unauthenticated attacker can exploit this issue to retrieve the JCR roles of the AEM instance by sending a specially crafted HTTP request to the QueryBuilder Servlet endpoint.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115064">https://www.tenable.com/plugins/was/115064</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[AI Service Secret Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115063</link>
            <guid>https://www.tenable.com/plugins/was/115063</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115063 with High Severity</p>
      <h3>Synopsis</h3>
      <span>AI Service Secret Disclosure<br /></span>
      <h3>Description</h3>
      <span>Most of the web applications rely on various public services to provide features to their users. In secure designs, consuming these private or cloud services will require authentication like API and private keys, username and password based credentials and similar sensitive data.<br /></span><span><br /></span><span>Developers sometimes hard code such data in various places of their applications, without realizing that it could become publicly available in client-side JavaScript or, for example, HTML comments. By leveraging these sensitive information, a remote and unauthenticated attacker could gain access to an external AI service used by the web application and the organization.<br /></span><span><br /></span><span>It is recommended to enable the secret validation option in the scan configuration to help identify critically exposed secrets.<br /></span>
      <h3>Solution</h3>
      <span>Remove the secret exposure by identifying the root cause of the issue (for example manual data insertion in the code, environment variables being bundled in front-end JavaScript). Rotate the secrets to avoid further reuse in case it has been previously retrieved by a malicious actor.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115063">https://www.tenable.com/plugins/was/115063</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Third-Party Service Secret Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115062</link>
            <guid>https://www.tenable.com/plugins/was/115062</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115062 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Third-Party Service Secret Disclosure<br /></span>
      <h3>Description</h3>
      <span>Most of the web applications rely on various public services to provide features to their users. In secure designs, consuming these private or cloud services will require authentication like API and private keys, username and password based credentials and similar sensitive data.<br /></span><span><br /></span><span>Developers sometimes hard code such data in various places of their applications, without realizing that it could become publicly available in client-side JavaScript or, for example, HTML comments. By leveraging these sensitive information, a remote and unauthenticated attacker could gain access to an external AI service used by the web application and the organization.<br /></span><span><br /></span><span>It is recommended to enable the secret validation option in the scan configuration to help identify critically exposed secrets.<br /></span>
      <h3>Solution</h3>
      <span>Remove the secret exposure by identifying the root cause of the issue (for example manual data insertion in the code, environment variables being bundled in front-end JavaScript). Rotate the secrets to avoid further reuse in case it has been previously retrieved by a malicious actor.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115062">https://www.tenable.com/plugins/was/115062</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Dispatcher Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115061</link>
            <guid>https://www.tenable.com/plugins/was/115061</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115061 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Dispatcher Bypass<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) is affected by a dispatcher misconfiguration that allows for security filter bypass. By sending a specially crafted request, an unauthenticated, remote attacker can access internal endpoints, such as the QueryBuilder JSON API. A successful exploit could lead to unauthorized access and information disclosure).<br /></span>
      <h3>Solution</h3>
      <span>It is recommended to review and strengthen the AEM Dispatcher's filter rules to follow a 'deny by default' approach. Ensure that access to sensitive administrative and internal endpoints, such as `/bin/querybuilder.json`, is explicitly denied. Consult the Adobe Experience Manager Dispatcher Security Checklist for comprehensive guidance on securing the dispatcher configuration.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115061">https://www.tenable.com/plugins/was/115061</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) CRX Content Explorer]]></title>
            <link>https://www.tenable.com/plugins/was/115060</link>
            <guid>https://www.tenable.com/plugins/was/115060</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115060 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) CRX Content Explorer<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) CRX Content Explorer interface. The CRX Content Explorer is a web-based interface used to manage and interact with the content repository of Adobe Experience Manager.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115060">https://www.tenable.com/plugins/was/115060</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Felix Console Default Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/115059</link>
            <guid>https://www.tenable.com/plugins/was/115059</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115059 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Felix Console Default Credentials<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) Felix Console is configured with default or predictable credentials, which could allow an attacker to gain unauthorized access to the application and potentially compromise the underlying system.<br /></span>
      <h3>Solution</h3>
      <span>The application should not be configured with accounts using default or predictable credentials. A complex password policy should be defined and enforced on every account available in the application to prevent attackers from guessing it and have unauthorized access to the application.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115059">https://www.tenable.com/plugins/was/115059</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Debugging Client Libraries Exposure]]></title>
            <link>https://www.tenable.com/plugins/was/115058</link>
            <guid>https://www.tenable.com/plugins/was/115058</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115058 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Debugging Client Libraries Exposure<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) Debugging Client Libraries on a web server. These libraries are intended for development and debugging purposes and should not be exposed in a production environment, as they may contain sensitive information or functionality that could be exploited by attackers.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115058">https://www.tenable.com/plugins/was/115058</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Querybuilder Internal Path Read]]></title>
            <link>https://www.tenable.com/plugins/was/115057</link>
            <guid>https://www.tenable.com/plugins/was/115057</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115057 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Querybuilder Internal Path Read<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) server is configured to allow unauthenticated users to access internal paths using the Querybuilder endpoint. This may allow an attacker to read sensitive files from the server.<br /></span><span><br /></span><span>The Querybuilder endpoint is typically located at /bin/querybuilder.json and allows users to perform searches on the AEM repository. By specifying certain parameters, an attacker can potentially access internal paths that should not be publicly accessible.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115057">https://www.tenable.com/plugins/was/115057</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Sling User Information Servlet Exposure]]></title>
            <link>https://www.tenable.com/plugins/was/115056</link>
            <guid>https://www.tenable.com/plugins/was/115056</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115056 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Sling User Information Servlet Exposure<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) Sling User Information Servlet is prone to information disclosure vulnerabilities. An attacker can exploit this issue to gather information about user accounts, including usernames and other details, which could be used in subsequent attacks such as brute-force password guessing or social engineering.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115056">https://www.tenable.com/plugins/was/115056</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) CRX Search Endpoint Exposure]]></title>
            <link>https://www.tenable.com/plugins/was/115055</link>
            <guid>https://www.tenable.com/plugins/was/115055</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115055 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) CRX Search Endpoint Exposure<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) CRX search endpoint is accessible. These endpoints provide potential attackers with access to search functionalities, which could be exploited to discover sensitive internal resources.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115055">https://www.tenable.com/plugins/was/115055</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Custom Scripts Listing Detection]]></title>
            <link>https://www.tenable.com/plugins/was/115054</link>
            <guid>https://www.tenable.com/plugins/was/115054</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115054 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Custom Scripts Listing Detection<br /></span>
      <h3>Description</h3>
      <span>The remote Adobe Experience Manager (AEM) instance allows for the listing of custom scripts. An unauthenticated, remote attacker can exploit this to enumerate custom scripts, which could lead to information disclosure about the application.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to the endpoint using a .htaccess file, limiting access to known IP Addresses<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115054">https://www.tenable.com/plugins/was/115054</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) QueryBuilder Feed Servlet Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115053</link>
            <guid>https://www.tenable.com/plugins/was/115053</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115053 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) QueryBuilder Feed Servlet Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) QueryBuilder Feed Servlet on a web application. The QueryBuilder Feed Servlet is part of AEM's QueryBuilder API, which allows developers to construct and execute queries against the AEM repository to retrieve content based on specific criteria.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115053">https://www.tenable.com/plugins/was/115053</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) CRX Namespace Editor Panel Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115052</link>
            <guid>https://www.tenable.com/plugins/was/115052</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115052 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) CRX Namespace Editor Panel Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) CRX Namespace Editor panel on a web application. The CRX Namespace Editor panel is part of the AEM's content repository management interface, allowing administrators to manage namespaces and node types within the repository. Unauthorized access to this panel can lead to potential security risks, including unauthorized modifications to the content repository structure.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to administrative functionality using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115052">https://www.tenable.com/plugins/was/115052</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Sneeit Framework Plugin for WordPress < 8.4 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115051</link>
            <guid>https://www.tenable.com/plugins/was/115051</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115051 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Sneeit Framework Plugin for WordPress < 8.4 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>The WordPress Sneeit Framework Plugin installed on the remote host is affected by a Remote Code Execution vulnerability due to insufficient input validation in the sneeit_articles_pagination_callback() function, which accepts user input and passes it through the call_user_func() function. This allows unauthenticated attackers to execute arbitrary code on the server.<br /></span>
      <h3>Solution</h3>
      <span>Update to Sneeit Framework Plugin for WordPress version 8.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115051">https://www.tenable.com/plugins/was/115051</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Sling Login Panel Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115050</link>
            <guid>https://www.tenable.com/plugins/was/115050</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115050 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Sling Login Panel Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) Sling Login panel on a web application. The Sling Login panel is part of the Apache Sling framework used by AEM for content delivery and management, providing authentication and access control features.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115050">https://www.tenable.com/plugins/was/115050</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) CRX Package Manager Panel Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115049</link>
            <guid>https://www.tenable.com/plugins/was/115049</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115049 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) CRX Package Manager Panel Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) CRX Package Manager panel on a web application. The CRX Package Manager is a tool used to manage packages in AEM, allowing users to install, uninstall, and manage content packages.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115049">https://www.tenable.com/plugins/was/115049</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Experience Manager (AEM) Login Panel Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115048</link>
            <guid>https://www.tenable.com/plugins/was/115048</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115048 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Experience Manager (AEM) Login Panel Detected<br /></span>
      <h3>Description</h3>
      <span>This plugin detects the presence of the Adobe Experience Manager (AEM) login panel on a web application. AEM is a comprehensive content management solution for building websites, mobile apps, and forms.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115048">https://www.tenable.com/plugins/was/115048</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GFI KerioControl < 9.4.5 HTTP Response Splitting]]></title>
            <link>https://www.tenable.com/plugins/was/115047</link>
            <guid>https://www.tenable.com/plugins/was/115047</guid>
            <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115047 with High Severity</p>
      <h3>Synopsis</h3>
      <span>GFI KerioControl < 9.4.5 HTTP Response Splitting<br /></span>
      <h3>Description</h3>
      <span>GFI KerioControl version prior to 9.4.5 is affected by an HTTP Response Splitting vulnerability. Due to a not properly sanitized GET parameter used to generate a Location HTTP header in a 302 HTTP response an attacker can exploit this vulnerability to perform an Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS).<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to GFI KerioControl version 9.4.5 Patch 1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115047">https://www.tenable.com/plugins/was/115047</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Liferay Portal GraphQL Schema Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115046</link>
            <guid>https://www.tenable.com/plugins/was/115046</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115046 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Liferay Portal GraphQL Schema Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected that the target Liferay instance publicly exposes its GraphQL schema.<br /></span>
      <h3>Solution</h3>
      <span>If the GraphQL schema is not expected to be public, restrict their access.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115046">https://www.tenable.com/plugins/was/115046</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Oracle Identity Manager < 12.2.1.4.0 / < 14.1.2.1.0 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115045</link>
            <guid>https://www.tenable.com/plugins/was/115045</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115045 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Oracle Identity Manager < 12.2.1.4.0 / < 14.1.2.1.0 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Oracle Identity Manager versions prior to 12.2.1.4.0 or prior to 14.1.2.1.0 are vulnerable to a Remote Code Execution through the REST WebServices component. An unauthenticated attacker can achieve remote code execution on the underlying server via a crafted REST request.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Oracle Identity Manager version 12.2.1.4.0 or 14.1.2.1.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115045">https://www.tenable.com/plugins/was/115045</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Liferay Portal License Manager Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115044</link>
            <guid>https://www.tenable.com/plugins/was/115044</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115044 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Liferay Portal License Manager Detected<br /></span>
      <h3>Description</h3>
      <span>The target Liferay portal instance exposes information about the license state and the server. An unauthenticated attacked could leverage these information, such as server internal IP addresse and hostname, liferay version and license owner to conduct further attacks.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that the license manager route is not publicly accessible or restrict access to authorized users only.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115044">https://www.tenable.com/plugins/was/115044</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Liferay Portal JSON Web Services Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115043</link>
            <guid>https://www.tenable.com/plugins/was/115043</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115043 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Liferay Portal JSON Web Services Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected that the target Liferay instance publicly exposes the JSON web services.<br /></span>
      <h3>Solution</h3>
      <span>If the JSON web services are not expected to be public, restrict their access.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115043">https://www.tenable.com/plugins/was/115043</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Wazuh 4.4x < 4.9.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115042</link>
            <guid>https://www.tenable.com/plugins/was/115042</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115042 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Wazuh 4.4x < 4.9.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to the self-reported version in its response header, the version of Wazuh hosted on the remote web server is 4.4.x prior to 4.9.1. It is, therefore, affected by a Remote Code Execution through an unsafe deserialization by anybody with API access.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Wazuh version 4.9.1 Patch Level 1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115042">https://www.tenable.com/plugins/was/115042</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Liferay Portal API Explorer Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115041</link>
            <guid>https://www.tenable.com/plugins/was/115041</guid>
            <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115041 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Liferay Portal API Explorer Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected that the target Liferay instance publicly expose the API explorer.<br /></span>
      <h3>Solution</h3>
      <span>If the API explorer is not expected to public, restrict its access.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115041">https://www.tenable.com/plugins/was/115041</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee 5.4.x < 5.4.3.2 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115039</link>
            <guid>https://www.tenable.com/plugins/was/115039</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115039 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee 5.4.x < 5.4.3.2 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Lodash is prior to 5.3.12.1 or 5.4.x prior to 5.4.3.2. It is, therefore, affected by a Remote Code Execution via an XML XXE attack in the Lucee REST endpoint.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Lucee version 5.4.3.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115039">https://www.tenable.com/plugins/was/115039</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee < 5.3.12.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115038</link>
            <guid>https://www.tenable.com/plugins/was/115038</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115038 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee < 5.3.12.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, Lodash is prior to 5.3.12.1 or 5.4.x prior to 5.4.3.2. It is, therefore, affected by a Remote Code Execution via an XML XXE attack in the Lucee REST endpoint.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Lucee version 5.3.12.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115038">https://www.tenable.com/plugins/was/115038</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Telerik UI for ASP.NET AJAX Unsafe Reflection]]></title>
            <link>https://www.tenable.com/plugins/was/115037</link>
            <guid>https://www.tenable.com/plugins/was/115037</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115037 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Telerik UI for ASP.NET AJAX Unsafe Reflection<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the version of Telerik UI for ASP.NET AJAX is affected by an unsafe reflection vulnerability resulting in denial of service and advanced attacks scenarios.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Telerik UI for ASP.NET AJAX version 2025 Q1 SP2 (2025.1.416) or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115037">https://www.tenable.com/plugins/was/115037</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 8.0.x < 10.4.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115036</link>
            <guid>https://www.tenable.com/plugins/was/115036</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115036 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 8.0.x < 10.4.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Drupal Core has a rarely used feature, provided by an underlying library, which allows certain attributes of incoming HTTP requests to be overridden.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site.<br /></span><span><br /></span><span>- By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.<br /></span><span><br /></span><span>- The core system module handles downloads of private and temporary files.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.4.9 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115036">https://www.tenable.com/plugins/was/115036</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 10.5.x < 10.5.6 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115035</link>
            <guid>https://www.tenable.com/plugins/was/115035</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115035 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 10.5.x < 10.5.6 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Drupal Core has a rarely used feature, provided by an underlying library, which allows certain attributes of incoming HTTP requests to be overridden.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site.<br /></span><span><br /></span><span>- By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.<br /></span><span><br /></span><span>- The core system module handles downloads of private and temporary files.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 10.5.6 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115035">https://www.tenable.com/plugins/was/115035</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.0.x < 11.1.9 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115034</link>
            <guid>https://www.tenable.com/plugins/was/115034</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115034 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.0.x < 11.1.9 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Drupal Core has a rarely used feature, provided by an underlying library, which allows certain attributes of incoming HTTP requests to be overridden.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site.<br /></span><span><br /></span><span>- By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.<br /></span><span><br /></span><span>- The core system module handles downloads of private and temporary files.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.1.9 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115034">https://www.tenable.com/plugins/was/115034</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Drupal 11.2.x < 11.2.8 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115033</link>
            <guid>https://www.tenable.com/plugins/was/115033</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115033 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Drupal 11.2.x < 11.2.8 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the detected Drupal application is affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Drupal Core has a rarely used feature, provided by an underlying library, which allows certain attributes of incoming HTTP requests to be overridden.<br /></span><span><br /></span><span>- Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site.<br /></span><span><br /></span><span>- By generating and tricking a user into visiting a malicious URL, an attacker can perform site defacement.<br /></span><span><br /></span><span>- The core system module handles downloads of private and temporary files.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Drupal version 11.2.8 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115033">https://www.tenable.com/plugins/was/115033</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee < 6.0.1.59 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115032</link>
            <guid>https://www.tenable.com/plugins/was/115032</guid>
            <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115032 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee < 6.0.1.59 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Lucee versions prior to 6.0.1.59 are vulnerable to Remote Code Execution (RCE) via crafted cookies. An attacker can exploit this vulnerability by sending a specially crafted cookie to the server, which can lead to arbitrary code execution on the server hosting the Lucee application.<br /></span>
      <h3>Solution</h3>
      <span>Update to Lucee version 6.0.1.59 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115032">https://www.tenable.com/plugins/was/115032</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Fortinet FortiWeb Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115040</link>
            <guid>https://www.tenable.com/plugins/was/115040</guid>
            <pubDate>Fri, 14 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115040 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Fortinet FortiWeb Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>Fortinet FortiWeb versions 7.0.x < 7.0.12, 7.2.x < 7.2.12, 7.4.x < 7.4.10, 7.6.x < 7.6.5, 8.0.x < 8.0.2 suffer from an authentication bypass vulnerability. By crafting a specific request, a remote and unauthenticated attacker can create a new user account and compromise the affected system.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to FortiWeb version 7.0.12, 7.2.12, 7.4.10, 7.6.5, 8.0.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115040">https://www.tenable.com/plugins/was/115040</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee Unset Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/155029</link>
            <guid>https://www.tenable.com/plugins/was/155029</guid>
            <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 155029 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee Unset Credentials<br /></span>
      <h3>Description</h3>
      <span>Lucee web application server may be configured with no credentials. If an attacker setup the default accounts, they could gain unauthorized access to the application and perform arbitrary actions on it.<br /></span>
      <h3>Solution</h3>
      <span>The application should not be configured with accounts using default or predictable credentials. A complex password policy should be defined and enforced on every account available in the application to prevent attackers from guessing it and have unauthorized access to the application.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/155029">https://www.tenable.com/plugins/was/155029</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[DotNetNuke < 10.1.1 Unrestricted File Upload]]></title>
            <link>https://www.tenable.com/plugins/was/115031</link>
            <guid>https://www.tenable.com/plugins/was/115031</guid>
            <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115031 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>DotNetNuke < 10.1.1 Unrestricted File Upload<br /></span>
      <h3>Description</h3>
      <span>DotNetNuke CMS versions prior to 10.1.1 are affected by an unrestricted file upload vulnerability due to improper validation of uploaded files in the default HTML editor provider. This vulnerability allows unauthenticated users to upload files without proper restrictions, potentially leading to overwriting existing files on the server.<br /></span><span><br /></span><span>An attacker could exploit this vulnerability by uploading malicious files, which could lead to website defacement or, when combined with other vulnerabilities, the execution of cross-site scripting (XSS) payloads.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to DNN Platform 10.1.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115031">https://www.tenable.com/plugins/was/115031</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Gladinet CentreStack/Triofox < 16.10.10408.56683 Local File Inclusion]]></title>
            <link>https://www.tenable.com/plugins/was/115030</link>
            <guid>https://www.tenable.com/plugins/was/115030</guid>
            <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115030 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Gladinet CentreStack/Triofox < 16.10.10408.56683 Local File Inclusion<br /></span>
      <h3>Description</h3>
      <span>Gladinet CentreStack/Triofox versions prior to 16.10.10408.56683 are vulnerable to a Local File Inclusion (LFI) vulnerability. An unauthenticated attacker could exploit this issue to read arbitrary files on the affected system, potentially leading to information disclosure.<br /></span><span><br /></span><span>The vulnerability exists due to insufficient validation of user-supplied input in the file inclusion functionality. An attacker could manipulate the input to include files from the local file system, such as configuration files or sensitive data.<br /></span><span><br /></span><span>Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information, which could be used for further attacks against the system or network.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Gladinet CentreStack/Triofox version 16.10.10408.56683 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115030">https://www.tenable.com/plugins/was/115030</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee Unset Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/115029</link>
            <guid>https://www.tenable.com/plugins/was/115029</guid>
            <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115029 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee Unset Credentials<br /></span>
      <h3>Description</h3>
      <span>Lucee web application server may be configured with no credentials. If an attacker setup the default accounts, they could gain unauthorized access to the application and perform arbitrary actions on it.<br /></span>
      <h3>Solution</h3>
      <span>The application should not be configured with accounts using default or predictable credentials. A complex password policy should be defined and enforced on every account available in the application to prevent attackers from guessing it and have unauthorized access to the application.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115029">https://www.tenable.com/plugins/was/115029</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee Default Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/115028</link>
            <guid>https://www.tenable.com/plugins/was/115028</guid>
            <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115028 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee Default Credentials<br /></span>
      <h3>Description</h3>
      <span>Lucee web application server may be configured with default or predictable credentials for its accounts. If an attacker can guess the credentials, they may be able to gain unauthorized access to the application and perform arbitrary actions on it.<br /></span>
      <h3>Solution</h3>
      <span>The application should not be configured with accounts using default or predictable credentials. A complex password policy should be defined and enforced on every account available in the application to prevent attackers from guessing it and have unauthorized access to the application.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115028">https://www.tenable.com/plugins/was/115028</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lucee Administration Panel Login Form Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115027</link>
            <guid>https://www.tenable.com/plugins/was/115027</guid>
            <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115027 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Lucee Administration Panel Login Form Detected<br /></span>
      <h3>Description</h3>
      <span>Lucee Administration Panel has been detected on the target web application.<br /></span><span><br /></span><span>This may present an attacker with an exploit vector which could be leveraged using other techniques, such as a Brute-Force or Dictionary Attack, allowing an attacker to gain access to administrative functionality.<br /></span>
      <h3>Solution</h3>
      <span>Restrict access to administrative functionality using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115027">https://www.tenable.com/plugins/was/115027</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.109 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115026</link>
            <guid>https://www.tenable.com/plugins/was/115026</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115026 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.109 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.109, 10.1.0-M1 prior to 10.1.45 or 11.0.0-M1 prior to 11.0.11. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Console manipulation via escape sequences in log messages. (CVE-2025-55754)<br /></span><span><br /></span><span>- Directory traversal via Rewrite Valve with possible remote code execution if PUT is enabled. (CVE-2025-55752)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.109 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115026">https://www.tenable.com/plugins/was/115026</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.45 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115025</link>
            <guid>https://www.tenable.com/plugins/was/115025</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115025 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.45 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.109, 10.1.0-M1 prior to 10.1.45 or 11.0.0-M1 prior to 11.0.11. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Console manipulation via escape sequences in log messages. (CVE-2025-55754)<br /></span><span><br /></span><span>- Directory traversal via Rewrite Valve with possible remote code execution if PUT is enabled. (CVE-2025-55752)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.45 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115025">https://www.tenable.com/plugins/was/115025</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.11 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/115024</link>
            <guid>https://www.tenable.com/plugins/was/115024</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115024 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.11 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.109, 10.1.0-M1 prior to 10.1.45 or 11.0.0-M1 prior to 11.0.11. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- Console manipulation via escape sequences in log messages. (CVE-2025-55754)<br /></span><span><br /></span><span>- Directory traversal via Rewrite Valve with possible remote code execution if PUT is enabled. (CVE-2025-55752)<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.11 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115024">https://www.tenable.com/plugins/was/115024</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 9.0.0-M1 < 9.0.110 Denial of Service]]></title>
            <link>https://www.tenable.com/plugins/was/115023</link>
            <guid>https://www.tenable.com/plugins/was/115023</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115023 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 9.0.0-M1 < 9.0.110 Denial of Service<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.110, 10.1.0-M1 prior to 10.1.47 or 11.0.0-M1 prior to 11.0.12. It is, therefore, affected by a denial of service vulnerability due to delayed cleaning of multipart upload temporary files.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 9.0.110 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115023">https://www.tenable.com/plugins/was/115023</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 10.1.0-M1 < 10.1.47 Denial of Service]]></title>
            <link>https://www.tenable.com/plugins/was/115022</link>
            <guid>https://www.tenable.com/plugins/was/115022</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115022 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 10.1.0-M1 < 10.1.47 Denial of Service<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.110, 10.1.0-M1 prior to 10.1.47 or 11.0.0-M1 prior to 11.0.12. It is, therefore, affected by a denial of service vulnerability due to delayed cleaning of multipart upload temporary files.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 10.1.47 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115022">https://www.tenable.com/plugins/was/115022</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Tomcat 11.0.0-M1 < 11.0.12 Denial of Service]]></title>
            <link>https://www.tenable.com/plugins/was/115021</link>
            <guid>https://www.tenable.com/plugins/was/115021</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115021 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Tomcat 11.0.0-M1 < 11.0.12 Denial of Service<br /></span>
      <h3>Description</h3>
      <span>The version of Apache Tomcat installed on the remote host is 9.0.0-M1 prior to 9.0.110, 10.1.0-M1 prior to 10.1.47 or 11.0.0-M1 prior to 11.0.12. It is, therefore, affected by a denial of service vulnerability due to delayed cleaning of multipart upload temporary files.<br /></span><span><br /></span><span>Note that the scanner has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Apache Tomcat version 11.0.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115021">https://www.tenable.com/plugins/was/115021</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Squid < 7.2 Information Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115020</link>
            <guid>https://www.tenable.com/plugins/was/115020</guid>
            <pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115020 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Squid < 7.2 Information Disclosure<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number,the version of Squid installed on the remote host is prior to 7.2. It is, therefore, affected by an Information Disclosure due to a failure to redact HTTP Authentication credentials.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Squid version 7.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115020">https://www.tenable.com/plugins/was/115020</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Adobe Commerce / Magento Insecure Deserialization (SessionReaper)]]></title>
            <link>https://www.tenable.com/plugins/was/115019</link>
            <guid>https://www.tenable.com/plugins/was/115019</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115019 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Adobe Commerce / Magento Insecure Deserialization (SessionReaper)<br /></span>
      <h3>Description</h3>
      <span>Adobe Magento Open Source / Commerce is prone to an unauthenticated Remote Code Execution vulnerability due to insecure deserialization of untrusted data. An attacker can exploit this issue to execute arbitrary code in the context of the web server process.<br /></span>
      <h3>Solution</h3>
      <span>Apply the appropriate patch according to the vendor advisory.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115019">https://www.tenable.com/plugins/was/115019</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Confluence 10.x < 10.0.2 Denial of Service]]></title>
            <link>https://www.tenable.com/plugins/was/115018</link>
            <guid>https://www.tenable.com/plugins/was/115018</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115018 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Confluence 10.x < 10.0.2 Denial of Service<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Confluence application running on the remote host is 2.x prior to 8.5.25, 9.2.x prior to 9.2.7 or 10.x prior to 10.0.2. It is, therefore, affected by a denial of service vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Confluence version 10.0.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115018">https://www.tenable.com/plugins/was/115018</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Confluence 9.2.x < 9.2.7 Denial of Service]]></title>
            <link>https://www.tenable.com/plugins/was/115017</link>
            <guid>https://www.tenable.com/plugins/was/115017</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115017 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Confluence 9.2.x < 9.2.7 Denial of Service<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Confluence application running on the remote host is 2.x prior to 8.5.25, 9.2.x prior to 9.2.7 or 10.x prior to 10.0.2. It is, therefore, affected by a denial of service vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Confluence version 9.2.7 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115017">https://www.tenable.com/plugins/was/115017</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Confluence 2.x < 8.5.25 Denial of Service]]></title>
            <link>https://www.tenable.com/plugins/was/115016</link>
            <guid>https://www.tenable.com/plugins/was/115016</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115016 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Confluence 2.x < 8.5.25 Denial of Service<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Confluence application running on the remote host is 2.x prior to 8.5.25, 9.2.x prior to 9.2.7 or 10.x prior to 10.0.2. It is, therefore, affected by a denial of service vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Confluence version 8.5.25 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115016">https://www.tenable.com/plugins/was/115016</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Jira 11.x < 11.1.0 Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/115015</link>
            <guid>https://www.tenable.com/plugins/was/115015</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115015 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Jira 11.x < 11.1.0 Path Traversal<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Jira application running on the remote host is 9.12.x prior to 9.12.28, 10.3.x prior to 10.3.12 or 11.x prior to 11.1.0. It is, therefore, affected by a path traversal vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Jira version 11.1.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115015">https://www.tenable.com/plugins/was/115015</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Jira 10.3.x < 10.3.12 Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/115014</link>
            <guid>https://www.tenable.com/plugins/was/115014</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115014 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Jira 10.3.x < 10.3.12 Path Traversal<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Jira application running on the remote host is 9.12.x prior to 9.12.28, 10.3.x prior to 10.3.12 or 11.x prior to 11.1.0. It is, therefore, affected by a path traversal vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Jira version 10.3.12 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115014">https://www.tenable.com/plugins/was/115014</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Atlassian Jira 9.12.x < 9.12.28 Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/115013</link>
            <guid>https://www.tenable.com/plugins/was/115013</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115013 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Atlassian Jira 9.12.x < 9.12.28 Path Traversal<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version number, the Atlassian Jira application running on the remote host is 9.12.x prior to 9.12.28, 10.3.x prior to 10.3.12 or 11.x prior to 11.1.0. It is, therefore, affected by a path traversal vulnerability.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Atlassian Jira version 9.12.28 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115013">https://www.tenable.com/plugins/was/115013</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Authentik 2024.8.x < 2024.8.3 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115012</link>
            <guid>https://www.tenable.com/plugins/was/115012</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115012 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Authentik 2024.8.x < 2024.8.3 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Authentik running on the remote host is prior to 2024.6.5 or 2024.8.x prior to 2024.8.3. It is, therefore, affected by an Authentication Bypass vulnerability via the X-Forwarded-For header.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Authentik version 2024.6.5 or 2024.8.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115012">https://www.tenable.com/plugins/was/115012</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Authentik < 2024.6.5 Authentication Bypass]]></title>
            <link>https://www.tenable.com/plugins/was/115011</link>
            <guid>https://www.tenable.com/plugins/was/115011</guid>
            <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115011 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Authentik < 2024.6.5 Authentication Bypass<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Authentik running on the remote host is prior to 2024.6.5 or 2024.8.x prior to 2024.8.3. It is, therefore, affected by an Authentication Bypass vulnerability via the X-Forwarded-For header.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Authentik version 2024.6.5 or 2024.8.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115011">https://www.tenable.com/plugins/was/115011</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Object-Relational Mapping (ORM) Leak]]></title>
            <link>https://www.tenable.com/plugins/was/115010</link>
            <guid>https://www.tenable.com/plugins/was/115010</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115010 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Object-Relational Mapping (ORM) Leak<br /></span>
      <h3>Description</h3>
      <span>An Object-Relational Mapping (ORM) Leak vulnerability occurs when an application does not properly control how user-provided data is passed to the ORM. An attacker can exploit this by manipulating input parameters to query fields that are not intended to be exposed. This can lead to the disclosure of sensitive information from the database, such as user credentials, personal information, or other confidential data. In some cases, it could also allow an attacker to perform unauthorized data modification operations.<br /></span>
      <h3>Solution</h3>
      <span>Ensure that user-controllable input is never directly used to construct ORM queries. Implement a strict whitelist of allowed fields and operators for filtering and searching. Validate and sanitize all input to prevent malicious query modifications.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115010">https://www.tenable.com/plugins/was/115010</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Discourse < 3.3.3 Backup Disclosure]]></title>
            <link>https://www.tenable.com/plugins/was/115009</link>
            <guid>https://www.tenable.com/plugins/was/115009</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115009 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Discourse < 3.3.3 Backup Disclosure<br /></span>
      <h3>Description</h3>
      <span>Discourse versions prior to 3.3.3 are vulnerable to a backup disclosure vulnerability due to improper handling of file downloads in the `rails send_file` method. An attacker could exploit this vulnerability to download backup files containing sensitive information, potentially leading to data exposure.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Discourse 3.3.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115009">https://www.tenable.com/plugins/was/115009</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Jenkins Sidepanel Unauthorized Agent/Queue Exposure]]></title>
            <link>https://www.tenable.com/plugins/was/115008</link>
            <guid>https://www.tenable.com/plugins/was/115008</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115008 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Jenkins Sidepanel Unauthorized Agent/Queue Exposure<br /></span>
      <h3>Description</h3>
      <span>Jenkins versions prior to 2.582 and prior to LTS 2.516.3 are affected by a lack of permission check for the authenticated user profile dropdown menu. A remote and unauthenticated attacker can obtain limited information about the Jenkins configuration agent and builds.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Jenkins 2.528, LTS 2.156.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115008">https://www.tenable.com/plugins/was/115008</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Node.js Express DevMode Enabled]]></title>
            <link>https://www.tenable.com/plugins/was/115007</link>
            <guid>https://www.tenable.com/plugins/was/115007</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115007 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Node.js Express DevMode Enabled<br /></span>
      <h3>Description</h3>
      <span>Node.js Express installed on the remote host is configured to operate in development mode (devMode). While this environment can help speed up development of web applications, it can leak information about the underlying web applications as well as the installation of Express, Node.js.<br /></span>
      <h3>Solution</h3>
      <span>Disable Node.js Express development mode.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115007">https://www.tenable.com/plugins/was/115007</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Custom HTTP Header Detected]]></title>
            <link>https://www.tenable.com/plugins/was/115006</link>
            <guid>https://www.tenable.com/plugins/was/115006</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115006 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Custom HTTP Header Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational notice that the scanner was able to detect custom HTTP headers in the target application's responses.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115006">https://www.tenable.com/plugins/was/115006</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Zimbra Collaboration 10.0.x < 10.0.13 Stored Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115005</link>
            <guid>https://www.tenable.com/plugins/was/115005</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115005 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Zimbra Collaboration 10.0.x < 10.0.13 Stored Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Zimbra Collaboration running on the remote host is 10.0.x prior to 10.0.13 or 10.1.x prior to 10.1.5. It is, therefore, affected by a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization of HTML content in ICS files.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Zimbra Collaboration version 10.0.13, 10.1.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115005">https://www.tenable.com/plugins/was/115005</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Zimbra Collaboration 10.1.x < 10.1.5 Stored Cross-Site Scripting]]></title>
            <link>https://www.tenable.com/plugins/was/115004</link>
            <guid>https://www.tenable.com/plugins/was/115004</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115004 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Zimbra Collaboration 10.1.x < 10.1.5 Stored Cross-Site Scripting<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Zimbra Collaboration running on the remote host is 10.0.x prior to 10.0.13 or 10.1.x prior to 10.1.5. It is, therefore, affected by a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization of HTML content in ICS files.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Zimbra Collaboration version 10.0.13, 10.1.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115004">https://www.tenable.com/plugins/was/115004</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Fortra GoAnywhere MFT License Servlet Deserialization Vulnerability]]></title>
            <link>https://www.tenable.com/plugins/was/115003</link>
            <guid>https://www.tenable.com/plugins/was/115003</guid>
            <pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115003 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Fortra GoAnywhere MFT License Servlet Deserialization Vulnerability<br /></span>
      <h3>Description</h3>
      <span>Fortra GoAnywhere MFT is a Managed File Transfer (MFT) solution helping organizations build both internal and external data transfer exchanges. GoAnyWhere MFT versions before 7.8.4 and before 7.6.3 suffer from a deserialization vulnerabilty. By crafting a specific payload, a remote and unauthenticated attacker can achieve remote code execution on the target vulnerable instance.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to version 7.6.3 (sustain release), 7.8.4 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115003">https://www.tenable.com/plugins/was/115003</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Intercom Chatbot Misconfiguration]]></title>
            <link>https://www.tenable.com/plugins/was/115001</link>
            <guid>https://www.tenable.com/plugins/was/115001</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115001 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Intercom Chatbot Misconfiguration<br /></span>
      <h3>Description</h3>
      <span>Intercom is a solution to build & deploy AI customer experiences. If the identity verification is not enabled, an attacker can impersonate an other user and access to the previous conversations and data. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Enable identity verification in Intercom settings.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115001">https://www.tenable.com/plugins/was/115001</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Dell UnityVSA < 5.5.1.0 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/115000</link>
            <guid>https://www.tenable.com/plugins/was/115000</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115000 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Dell UnityVSA < 5.5.1.0 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Dell UnityVSA versions prior to 5.5.10 is vulnerable to a Remote Code Execution vulnerability due to an improper input validation. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Dell UnityVSA version 5.5.1.0 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115000">https://www.tenable.com/plugins/was/115000</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 8.0.x < 8.0.7 / 8.1.x < 8.1.8 / 8.2.x < 8.2.7 / 8.3.x < 8.3.1 Path Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/114999</link>
            <guid>https://www.tenable.com/plugins/was/114999</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114999 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 8.0.x < 8.0.7 / 8.1.x < 8.1.8 / 8.2.x < 8.2.7 / 8.3.x < 8.3.1 Path Traversal<br /></span>
      <h3>Description</h3>
      <span>Grafana version 8.0.x prior to 8.0.7, 8.1.x prior to 8.1.8, 8.2.x prior to 8.2.7, and 8.3.x prior to 8.3.1 are vulnerable to a path traversal issue that could allow an attacker to read arbitrary files on the host system that Grafana has access to.<br /></span><span><br /></span><span>A remote attacker could exploit this vulnerability by sending a specially crafted request to the affected application.<br /></span><span><br /></span><span>Successful exploitation could allow the attacker to read sensitive files on the host system.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Grafana version 8.0.7 or 8.1.8 or 8.2.7 or 8.3.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114999">https://www.tenable.com/plugins/was/114999</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.5.x < 11.5.3 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/114998</link>
            <guid>https://www.tenable.com/plugins/was/114998</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114998 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.5.x < 11.5.3 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 10.4.17, or 11.2.x prior to 11.2.8, or 11.3.x prior to 11.3.5, or 11.4.x prior to 11.4.3, or 11.5.x prior to 11.5.3. It is, therefore, affected by an improper authorization.<br /></span><span><br /></span><span>- Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.5.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114998">https://www.tenable.com/plugins/was/114998</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.4.x < 11.4.3 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/114997</link>
            <guid>https://www.tenable.com/plugins/was/114997</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114997 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.4.x < 11.4.3 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 10.4.17, or 11.2.x prior to 11.2.8, or 11.3.x prior to 11.3.5, or 11.4.x prior to 11.4.3, or 11.5.x prior to 11.5.3. It is, therefore, affected by an improper authorization.<br /></span><span><br /></span><span>- Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.4.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114997">https://www.tenable.com/plugins/was/114997</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.3.x < 11.3.5 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/114996</link>
            <guid>https://www.tenable.com/plugins/was/114996</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114996 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.3.x < 11.3.5 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 10.4.17, or 11.2.x prior to 11.2.8, or 11.3.x prior to 11.3.5, or 11.4.x prior to 11.4.3, or 11.5.x prior to 11.5.3. It is, therefore, affected by an improper authorization.<br /></span><span><br /></span><span>- Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.3.5 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114996">https://www.tenable.com/plugins/was/114996</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.2.x < 11.2.8 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/114995</link>
            <guid>https://www.tenable.com/plugins/was/114995</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114995 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.2.x < 11.2.8 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 10.4.17, or 11.2.x prior to 11.2.8, or 11.3.x prior to 11.3.5, or 11.4.x prior to 11.4.3, or 11.5.x prior to 11.5.3. It is, therefore, affected by an improper authorization.<br /></span><span><br /></span><span>- Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.2.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114995">https://www.tenable.com/plugins/was/114995</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 10.4.17 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/114994</link>
            <guid>https://www.tenable.com/plugins/was/114994</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114994 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 10.4.17 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 10.4.17, or 11.2.x prior to 11.2.8, or 11.3.x prior to 11.3.5, or 11.4.x prior to 11.4.3, or 11.5.x prior to 11.5.3. It is, therefore, affected by an improper authorization.<br /></span><span><br /></span><span>- Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 10.4.17 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114994">https://www.tenable.com/plugins/was/114994</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 11.6.2 Improper Input Validation]]></title>
            <link>https://www.tenable.com/plugins/was/114993</link>
            <guid>https://www.tenable.com/plugins/was/114993</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114993 with Low Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 11.6.2 Improper Input Validation<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.6.2. It is, therefore, affected by an improper input validation.<br /></span><span><br /></span><span>- An excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.6.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114993">https://www.tenable.com/plugins/was/114993</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.1.x < 12.1.2 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114992</link>
            <guid>https://www.tenable.com/plugins/was/114992</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114992 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.1.x < 12.1.2 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.3.8, or 11.4.x prior to 11.4.6, or 11.5.x prior to 11.5.6, or 11.6.x prior to 11.6.3, or 12.0.x prior to 12.0.2, or 12.1.x prior to 12.1.2. It is, therefore, affected by multiples vulnerabilities.<br /></span><span><br /></span><span>- An Open Redirect vulnerability in Grafana organization switching functionality.<br /></span><span><br /></span><span>- An Open Redirect can be chained with Path Traversal vulnerabilities to achieve XSS via scripted dashboards.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.1.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114992">https://www.tenable.com/plugins/was/114992</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 12.0.x < 12.0.2 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114991</link>
            <guid>https://www.tenable.com/plugins/was/114991</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114991 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 12.0.x < 12.0.2 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.3.8, or 11.4.x prior to 11.4.6, or 11.5.x prior to 11.5.6, or 11.6.x prior to 11.6.3, or 12.0.x prior to 12.0.2, or 12.1.x prior to 12.1.2. It is, therefore, affected by multiples vulnerabilities.<br /></span><span><br /></span><span>- An Open Redirect vulnerability in Grafana organization switching functionality.<br /></span><span><br /></span><span>- An Open Redirect can be chained with Path Traversal vulnerabilities to achieve XSS via scripted dashboards.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 12.0.2 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114991">https://www.tenable.com/plugins/was/114991</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.6.x < 11.6.3 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114990</link>
            <guid>https://www.tenable.com/plugins/was/114990</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114990 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.6.x < 11.6.3 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.3.8, or 11.4.x prior to 11.4.6, or 11.5.x prior to 11.5.6, or 11.6.x prior to 11.6.3, or 12.0.x prior to 12.0.2, or 12.1.x prior to 12.1.2. It is, therefore, affected by multiples vulnerabilities.<br /></span><span><br /></span><span>- An Open Redirect vulnerability in Grafana organization switching functionality.<br /></span><span><br /></span><span>- An Open Redirect can be chained with Path Traversal vulnerabilities to achieve XSS via scripted dashboards.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.6.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114990">https://www.tenable.com/plugins/was/114990</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.5.x < 11.5.6 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114989</link>
            <guid>https://www.tenable.com/plugins/was/114989</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114989 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.5.x < 11.5.6 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.3.8, or 11.4.x prior to 11.4.6, or 11.5.x prior to 11.5.6, or 11.6.x prior to 11.6.3, or 12.0.x prior to 12.0.2, or 12.1.x prior to 12.1.2. It is, therefore, affected by multiples vulnerabilities.<br /></span><span><br /></span><span>- An Open Redirect vulnerability in Grafana organization switching functionality.<br /></span><span><br /></span><span>- An Open Redirect can be chained with Path Traversal vulnerabilities to achieve XSS via scripted dashboards.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.5.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114989">https://www.tenable.com/plugins/was/114989</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana 11.4.x < 11.4.6 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114988</link>
            <guid>https://www.tenable.com/plugins/was/114988</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114988 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana 11.4.x < 11.4.6 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.3.8, or 11.4.x prior to 11.4.6, or 11.5.x prior to 11.5.6, or 11.6.x prior to 11.6.3, or 12.0.x prior to 12.0.2, or 12.1.x prior to 12.1.2. It is, therefore, affected by multiples vulnerabilities.<br /></span><span><br /></span><span>- An Open Redirect vulnerability in Grafana organization switching functionality.<br /></span><span><br /></span><span>- An Open Redirect can be chained with Path Traversal vulnerabilities to achieve XSS via scripted dashboards.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.4.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114988">https://www.tenable.com/plugins/was/114988</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Grafana < 11.3.8 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114987</link>
            <guid>https://www.tenable.com/plugins/was/114987</guid>
            <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114987 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Grafana < 11.3.8 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the Grafana install hosted on the remote host is prior to 11.3.8, or 11.4.x prior to 11.4.6, or 11.5.x prior to 11.5.6, or 11.6.x prior to 11.6.3, or 12.0.x prior to 12.0.2, or 12.1.x prior to 12.1.2. It is, therefore, affected by multiples vulnerabilities.<br /></span><span><br /></span><span>- An Open Redirect vulnerability in Grafana organization switching functionality.<br /></span><span><br /></span><span>- An Open Redirect can be chained with Path Traversal vulnerabilities to achieve XSS via scripted dashboards.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Grafana version 11.3.8 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114987">https://www.tenable.com/plugins/was/114987</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Netdisco Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/115002</link>
            <guid>https://www.tenable.com/plugins/was/115002</guid>
            <pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 115002 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Netdisco Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>Netdisco is a web-based network management tool. When accessible without authentication, an attacker can gain unauthorized access to the Netdisco interface, potentially leading to information disclosure or further exploitation of the system.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Netdisco interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/115002">https://www.tenable.com/plugins/was/115002</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Airflow Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114986</link>
            <guid>https://www.tenable.com/plugins/was/114986</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114986 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Airflow Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>Apache Airflow is a platform to programmatically author, schedule and monitor workflows. When authentication is not enabled, an attacker can access the Airflow web interface without any credentials. This may allow an attacker to view and modify workflows, access sensitive information, and potentially execute arbitrary code on the server hosting Airflow.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Apache Airflow interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114986">https://www.tenable.com/plugins/was/114986</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Hitachi Pentaho Business Analytics Server 8.3.x < 9.3.0.2 / 9.4.x < 9.4.0.1 Remote Code Execution]]></title>
            <link>https://www.tenable.com/plugins/was/114985</link>
            <guid>https://www.tenable.com/plugins/was/114985</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114985 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Hitachi Pentaho Business Analytics Server 8.3.x < 9.3.0.2 / 9.4.x < 9.4.0.1 Remote Code Execution<br /></span>
      <h3>Description</h3>
      <span>Hitachi Pentaho Business Analytics Server versions 8.3.x prior to 9.3.0.2 or 9.4.x prior to 9.4.0.1 suffer from a remote code execution vulnerability. An attacker can exploit this issue by sending a specially crafted HTTP request to the affected application. A successful exploit could allow the attacker to execute arbitrary code on the target system.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Hitachi Pentaho Business Analytics Server version 9.3.0.2 or 9.4.0.1 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114985">https://www.tenable.com/plugins/was/114985</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Apache Kylin 2.3.x < 3.1.0 Command Injection]]></title>
            <link>https://www.tenable.com/plugins/was/114984</link>
            <guid>https://www.tenable.com/plugins/was/114984</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114984 with High Severity</p>
      <h3>Synopsis</h3>
      <span>Apache Kylin 2.3.x < 3.1.0 Command Injection<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Apache Kylin running on the remote host is 2.3.x < 3.1.0. It is, therefore, affected by a Command Injection vulnerability through the REST API.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Apache Kylin version 3.1.0 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114984">https://www.tenable.com/plugins/was/114984</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Zyxel < 5.38 Directory Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/114983</link>
            <guid>https://www.tenable.com/plugins/was/114983</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114983 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Zyxel < 5.38 Directory Traversal<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Zyxel running on the remote host is < 5.38. It is, therefore, affected by a Directory Traversal that could allow an attacker to download or upload files via a crafted URL.<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Zyxel version 5.38 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114983">https://www.tenable.com/plugins/was/114983</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 4.x < 4.4.14 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114982</link>
            <guid>https://www.tenable.com/plugins/was/114982</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114982 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 4.x < 4.4.14 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 4.x prior to 4.4.14 or 5.x prior to 5.3.4. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. (CVE-2025-54476)<br /></span><span><br /></span><span>- Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. (CVE-2025-54477)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 4.4.14 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114982">https://www.tenable.com/plugins/was/114982</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Joomla! 5.x < 5.3.4 Multiple Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114981</link>
            <guid>https://www.tenable.com/plugins/was/114981</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114981 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Joomla! 5.x < 5.3.4 Multiple Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its self-reported version, the instance of Joomla! running on the remote web server is 4.x prior to 4.4.14 or 5.x prior to 5.3.4. It is, therefore, affected by multiple vulnerabilities.<br /></span><span><br /></span><span>- Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. (CVE-2025-54476)<br /></span><span><br /></span><span>- Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. (CVE-2025-54477)<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Update to Joomla! version 5.3.4 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114981">https://www.tenable.com/plugins/was/114981</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[TRUFusion Entreprise Sensitive Data Exposure]]></title>
            <link>https://www.tenable.com/plugins/was/114980</link>
            <guid>https://www.tenable.com/plugins/was/114980</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114980 with High Severity</p>
      <h3>Synopsis</h3>
      <span>TRUFusion Entreprise Sensitive Data Exposure<br /></span>
      <h3>Description</h3>
      <span>TRUFusion Entreprise is a solution to easily and securely manage the exchange of CAD files and related product design data from within your PLM system. Due to a lack of control, it is possible for an unauthenticated attacker to access an endpoint that returns all partners who have access to the instance.<br /></span>
      <h3>Solution</h3>
      <span>Refer to the TRUFusion Entreprise advisory for mitigation options.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114980">https://www.tenable.com/plugins/was/114980</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[pyLoad Default Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/114979</link>
            <guid>https://www.tenable.com/plugins/was/114979</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114979 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>pyLoad Default Credentials<br /></span>
      <h3>Description</h3>
      <span>pyLoad is an open-source download manager written in Python. By default, pyLoad is configured with a default username and password allowing any attacker to log in to the application and have full access to its functionality. An attacker can leverage this vulnerability to perform further attacks against the application.<br /></span>
      <h3>Solution</h3>
      <span>The application should not be configured with accounts using default or predictable credentials. A complex password policy should be defined and enforced on every account available in the application to prevent attackers from guessing it and have unauthorized access to the application.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114979">https://www.tenable.com/plugins/was/114979</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[pyLoad < 0.5.0b3.dev76 Improper Access Control]]></title>
            <link>https://www.tenable.com/plugins/was/114978</link>
            <guid>https://www.tenable.com/plugins/was/114978</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114978 with High Severity</p>
      <h3>Synopsis</h3>
      <span>pyLoad < 0.5.0b3.dev76 Improper Access Control<br /></span>
      <h3>Description</h3>
      <span>pyLoad version prior to 0.5.0b3.dev76 is affected by an Improper Access Control vulnerability. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. An attacker can leverage this vulnerability to perform further attacks against the application.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to pyLoad version 0.5.0b3.dev76 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114978">https://www.tenable.com/plugins/was/114978</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[ProjectSend < r1720 Improper Authorization]]></title>
            <link>https://www.tenable.com/plugins/was/114977</link>
            <guid>https://www.tenable.com/plugins/was/114977</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114977 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>ProjectSend < r1720 Improper Authorization<br /></span>
      <h3>Description</h3>
      <span>ProjectSend version prior to r1720 is affected by an Improper Authorization vulnerability. An unauthenticated attacker can exploit this issue to access sensitive information and perform unauthorized actions within the application.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to ProjectSend version r1720 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114977">https://www.tenable.com/plugins/was/114977</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[GoCD Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114976</link>
            <guid>https://www.tenable.com/plugins/was/114976</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114976 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>GoCD Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>GoCD is an open-source continuous delivery server. When accessible without authentication, an attacker can gain unauthorized access to the GoCD interface, potentially leading to information disclosure or further exploitation of the system.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the GoCD interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114976">https://www.tenable.com/plugins/was/114976</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Anteon Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114975</link>
            <guid>https://www.tenable.com/plugins/was/114975</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114975 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Anteon Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>Anteon is an eBPF-based Kubernetes Monitoring and Performance Testing Platform. When accessible without authentication, an attacker can gain unauthorized access to the Anteon interface, potentially leading to information disclosure or further exploitation of the system.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Anteon interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114975">https://www.tenable.com/plugins/was/114975</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Clickhouse API Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114974</link>
            <guid>https://www.tenable.com/plugins/was/114974</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114974 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Clickhouse API Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>Clickhouse is an open-source columnar database management system for online analytical processing. The Clickhouse HTTP interface allows users to interact with the database using HTTP requests.<br /></span><span><br /></span><span>When no authentication is configured, the Clickhouse API can be accessed without any credentials. This can lead to unauthorized access to sensitive data and potential data breaches.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Clickhouse API.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114974">https://www.tenable.com/plugins/was/114974</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Tiny File Manager Default Credentials]]></title>
            <link>https://www.tenable.com/plugins/was/114973</link>
            <guid>https://www.tenable.com/plugins/was/114973</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114973 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Tiny File Manager Default Credentials<br /></span>
      <h3>Description</h3>
      <span>Tiny File Manager is a web-based file manager that allows users to manage files on a server through a web interface. By default, Tiny File Manager comes with a default username and password combination. If these default credentials are not changed, a remote and unauthenticated attacker could gain unauthorized access to the application and perform arbitrary actions on it.<br /></span>
      <h3>Solution</h3>
      <span>The application should not be configured with accounts using default or predictable credentials. A complex password policy should be defined and enforced on every account available in the application to prevent attackers from guessing it and have unauthorized access to the application.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114973">https://www.tenable.com/plugins/was/114973</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Tiny File Manager Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114972</link>
            <guid>https://www.tenable.com/plugins/was/114972</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114972 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Tiny File Manager Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>Tiny File Manager is a web-based file manager written in PHP. It allows users to manage files on a web server through a simple and user-friendly interface. When authentication is not enforced, an attacker can access the File Browser interface without any credentials. This can lead to unauthorized access to files and directories on the server, potentially exposing sensitive information or allowing for further exploitation of the system.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Tiny File Manager interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114972">https://www.tenable.com/plugins/was/114972</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[File Browser Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114971</link>
            <guid>https://www.tenable.com/plugins/was/114971</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114971 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>File Browser Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>File Browser is an open-source web-based file manager that allows users to manage files on a server through a web interface. If the File Browser instance is accessible without authentication, it can lead to unauthorized access to sensitive files and directories on the server.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the File Browser interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114971">https://www.tenable.com/plugins/was/114971</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[cAdvisor Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114970</link>
            <guid>https://www.tenable.com/plugins/was/114970</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114970 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>cAdvisor Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>cAdvisor (short for container Advisor) is an open-source tool developed by Google that provides real-time monitoring and performance analysis of running containers. By default, cAdvisor does not require authentication to access the application. This allows an attacker to access sensitive data.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the cAdvisor interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114970">https://www.tenable.com/plugins/was/114970</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[H2O Flow Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114969</link>
            <guid>https://www.tenable.com/plugins/was/114969</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114969 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>H2O Flow Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>H2O Flow is an open-source user interface for H2O, an open-source, distributed and scalable machine learning and predictive analytics platform. By default, H2O Flow does not require authentication to access the application. This allows an attacker to access sensitive data. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the H2O Flow interface.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114969">https://www.tenable.com/plugins/was/114969</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Jenkins Unauthenticated Access]]></title>
            <link>https://www.tenable.com/plugins/was/114968</link>
            <guid>https://www.tenable.com/plugins/was/114968</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114968 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Jenkins Unauthenticated Access<br /></span>
      <h3>Description</h3>
      <span>Jenkins is an open-source automation server used to automate various aspects of software development, including building, testing, and deploying application. If authentication is not enforced, an attacker can gain administrative access to Jenkins, potentially allowing for the execution of arbitrary code, theft of sensitive information, and full control over the CI/CD pipeline.<br /></span>
      <h3>Solution</h3>
      <span>Authentication should be enforced to prevent unauthorized access to the Jenkins instance.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114968">https://www.tenable.com/plugins/was/114968</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Personal Identifying Information (PII) Fields Detected]]></title>
            <link>https://www.tenable.com/plugins/was/114966</link>
            <guid>https://www.tenable.com/plugins/was/114966</guid>
            <pubDate>Fri, 26 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114966 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Personal Identifying Information (PII) Fields Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational notice that the scanner was able to detect forms with fields collecting Personal Identifying Information (PII) data. Examples of PII data include, but are not limited to, names, email addresses, phone numbers, social security numbers, and financial information.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114966">https://www.tenable.com/plugins/was/114966</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Jenkins User Registration Form Detected]]></title>
            <link>https://www.tenable.com/plugins/was/114967</link>
            <guid>https://www.tenable.com/plugins/was/114967</guid>
            <pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114967 with Medium Severity</p>
      <h3>Synopsis</h3>
      <span>Jenkins User Registration Form Detected<br /></span>
      <h3>Description</h3>
      <span>Jenkins is an open-source automation server used to automate various aspects of software development, including building, testing, and deploying applications. An internal only Jenkins instance may be misconfigured to allow user registration, potentially leading to attackers creating accounts and gaining unauthorized access to the Jenkins instance and its resources.<br /></span>
      <h3>Solution</h3>
      <span>Review the scope of the Jenkins instance. If the detected instance is intended for internal users only, disable the user registration feature.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114967">https://www.tenable.com/plugins/was/114967</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[MCP Server Tools Detected]]></title>
            <link>https://www.tenable.com/plugins/was/114965</link>
            <guid>https://www.tenable.com/plugins/was/114965</guid>
            <pubDate>Fri, 19 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114965 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>MCP Server Tools Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational notice that the scanner was able to detect the exposition of tools on the target Model Context Protocol (MCP) server.<br /></span>
      <h3>Solution</h3>
      <span><br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114965">https://www.tenable.com/plugins/was/114965</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Jenkins Cross-Site WebSocket Hijacking]]></title>
            <link>https://www.tenable.com/plugins/was/114964</link>
            <guid>https://www.tenable.com/plugins/was/114964</guid>
            <pubDate>Fri, 19 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114964 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Jenkins Cross-Site WebSocket Hijacking<br /></span>
      <h3>Description</h3>
      <span>A vulnerability exists in Jenkins versions from 2.217 before 2.442 and from LTS 2.222.1 before LTS 2.426.3 allowing an unauthenticated and remote attacker to trick a user authenticated on the target Jenkins instance and perform Jenkins CLI cross-site arbitrary commands through websockets.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Jenkins version 2.442, LTS 2.426.3 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114964">https://www.tenable.com/plugins/was/114964</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Flowise < 3.0.6 Multiples Vulnerabilities]]></title>
            <link>https://www.tenable.com/plugins/was/114963</link>
            <guid>https://www.tenable.com/plugins/was/114963</guid>
            <pubDate>Fri, 19 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114963 with Critical Severity</p>
      <h3>Synopsis</h3>
      <span>Flowise < 3.0.6 Multiples Vulnerabilities<br /></span>
      <h3>Description</h3>
      <span>According to its banner, the version of Flowise running on the remote host is < 3.0.6. It is, therefore, affected by multiple vulnerabilities :<br /></span><span><br /></span><span>- An Unauthenticated Password Reset Token Disclosure<br /></span><span><br /></span><span>- A Server-Side Request Forgery vulnerability in the /api/v1/fetch-links endpoint<br /></span><span><br /></span><span>- A Remote Code Execution through CustomMCP node<br /></span><span><br /></span><span>- An unauthenticated Arbitrary File Read vulnerability through the chatId parameter supplied to both the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints<br /></span><span><br /></span><span>- A Remote Code Execution through the Supabase RPC Filter component<br /></span><span><br /></span><span>Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.<br /></span>
      <h3>Solution</h3>
      <span>Upgrade to Flowise version 3.0.6 or later.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114963">https://www.tenable.com/plugins/was/114963</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[Lunary Detected]]></title>
            <link>https://www.tenable.com/plugins/was/114962</link>
            <guid>https://www.tenable.com/plugins/was/114962</guid>
            <pubDate>Fri, 19 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114962 with Info Severity</p>
      <h3>Synopsis</h3>
      <span>Lunary Detected<br /></span>
      <h3>Description</h3>
      <span>This is an informational plugin to inform the user that the scanner has detected a publicly accessible Lunary instance on the target application. Lunary is an observability, prompt management and evaluations platform. This detection is included in the AI and LLM category.<br /></span>
      <h3>Solution</h3>
      <span>If the application is not expected to be public, restrict access using a .htaccess file, limiting access to known IP Addresses.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114962">https://www.tenable.com/plugins/was/114962</a></p>
    ]]></description>
        </item>
        <item>
            <title><![CDATA[AIOHTTP < 3.9.2 Directory Traversal]]></title>
            <link>https://www.tenable.com/plugins/was/114961</link>
            <guid>https://www.tenable.com/plugins/was/114961</guid>
            <pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate>
            <description><![CDATA[
      <p>Web App Scanning Plugin ID 114961 with High Severity</p>
      <h3>Synopsis</h3>
      <span>AIOHTTP < 3.9.2 Directory Traversal<br /></span>
      <h3>Description</h3>
      <span>AIOHTTP versions prior to 3.9.2 are vulnerable to a directory traversal allowing an unauthenticated attacker to access sensitive files via a specially crafted request.<br /></span>
      <h3>Solution</h3>
      <span>Update to AIOHTTP version 3.9.2 or latest.<br /></span>

      <p>Read more at  <a href="https://www.tenable.com/plugins/was/114961">https://www.tenable.com/plugins/was/114961</a></p>
    ]]></description>
        </item>
    </channel>
</rss>