Vulnerabilities
Vulnerable Software
Security Vulnerabilities
CVE-2026-102489
Known exploited
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
CVSS Score
9.4
EPSS Score
0.014
Published
2026-09-30
CVE-2026-102490
Known exploited
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVSS Score
9.4
EPSS Score
0.006
Published
2026-09-30
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVSS Score
6.9
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVSS Score
5.9
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVSS Score
8.9
EPSS Score
0.003
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVSS Score
4.9
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVSS Score
6.5
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVSS Score
3.1
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVSS Score
7.7
EPSS Score
0.002
Published
2026-09-30


Contact Us

Shodan ® - All rights reserved