[vulnfeed] 4 critical CVEs — 2026-09-25 20:00 UTC
vulnfeed
Critical alert — 2026-09-25 20:05 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-92161CRITICAL
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Pr
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified fiel
CVSS 9.8
CVE-2026-39353CRITICAL
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template dire
CVSS 9.1
CVE-2026-42322CRITICAL
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_sta
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-contr
CVSS 9.1
CVE-2026-62262CRITICAL
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: