Vulnerabilities (CVE)

Filtered by CWE-918
Total 3162 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29461 1 Appleple 1 A-blogcms 2026-06-17 N/A 7.6 HIGH
An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.
CVE-2025-29460 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29459 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29458 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29457 1 Mybb 1 Mybb 2026-06-17 N/A 7.6 HIGH
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
CVE-2025-29456 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.
CVE-2025-29455 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
CVE-2025-29454 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
CVE-2025-29453 1 Personal-management-system 1 Personal Management System 2026-06-17 N/A 6.5 MEDIUM
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.
CVE-2025-29452 1 Seopanel 1 Seo Panel 2026-06-17 N/A 7.6 HIGH
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
CVE-2025-29451 1 Seopanel 1 Seo Panel 2026-06-17 N/A 7.6 HIGH
An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
CVE-2025-29450 1 Lm21 1 Twonav 2026-06-17 N/A 6.5 MEDIUM
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings component.
CVE-2025-29449 1 Lm21 1 Twonav 2026-06-17 N/A 6.5 MEDIUM
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function.
CVE-2025-29008 2026-06-17 N/A 4.9 MEDIUM
Server-Side Request Forgery (SSRF) vulnerability in ShawonPro SocialMark socialmark allows Server Side Request Forgery.This issue affects SocialMark: from n/a through <= 2.0.7.
CVE-2025-28987 2026-06-17 N/A 6.4 MEDIUM
Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Forgery.This issue affects PressForward: from n/a through <= 5.9.5.
CVE-2025-28963 2026-06-17 N/A 5.4 MEDIUM
Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affects URL Shortener: from n/a through <= 3.0.7.
CVE-2025-28197 1 Kidocode 1 Crawl4ai 2026-06-17 N/A 9.1 CRITICAL
Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
CVE-2025-28096 1 Onenav 1 Onenav 2026-06-17 N/A 5.4 MEDIUM
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
CVE-2025-28094 1 Shopxo 1 Shopxo 2026-06-17 N/A 6.5 MEDIUM
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
CVE-2025-28093 1 Shopxo 1 Shopxo 2026-06-17 N/A 6.3 MEDIUM
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.