Vulnfeed

Archives
Log in
Subscribe
September 25, 2026

[vulnfeed] 4 critical CVEs — 2026-09-25 20:00 UTC

vulnfeed Critical alert — 2026-09-25 20:05 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-92161CRITICAL
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Pr
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified fiel
CVSS 9.8
CVE-2026-39353CRITICAL
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template dire
CVSS 9.1
CVE-2026-42322CRITICAL
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_sta
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-contr
CVSS 9.1
CVE-2026-62262CRITICAL
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 7 critical CVEs — 2026-09-25 20:00 UTC Older → [vulnfeed] 6 critical CVEs — 2026-09-24 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.