In FreeScout versions prior to 1.8.213 a critical severity vulnerability CVE-2026-40498 was detected. This vulnerability allows unauthenticated attackers to access restricted diagnostic and system tools using an exposed static MD5 hash, leading to sensitive information disclosure (such as full path and process IDs) and resource exhaustion (DoS) through the repeated triggering of background tasks. To address this issue, users should upgrade FreeScout to version 1.8.213. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-40498.
Read more Customer ServiceIn Dolibarr ERP/CRM versions prior to 23.0.2 a high vulnerability CVE-2026-22666 allows authenticated administrators to achieve remote code execution through the dol_eval_standard() function. The function fails to properly enforce forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax, allowing attackers to inject malicious payloads via computed extrafields or other evaluation paths. To address this issue, users should upgrade Dolibarr to version 23.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-22666.
Read more ERPIn BookStack versions up to 26.03 a medium severity vulnerability CVE-2026-5484 was detected. This vulnerability allows attackers to exploit improper access controls in the chapterToMarkdown function of the Chapter Export Handler by manipulating the pagesargument, potentially enabling unauthorized data access. To address this issue, users should upgrade BookStack to version 26.03.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5484.
Read more CMSIn Download Monitor plugin for WordPress versions up to and including 5.1.7 a high severity vulnerability CVE-2026-3124 was detected. An Insecure Direct Object Reference in the executePayment() function allows unauthenticated attackers to complete arbitrary pending orders by exploiting a mismatch between PayPal transaction tokens and local orders, enabling theft of paid digital goods. To address this issue, users should upgrade Download Monitor plugin to version to version 5.1.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3124.
Read more CMSIn Dolibarr versions 22.0.4 and prior a medium severity vulnerability CVE-2026-34036 was detected. This vulnerability allows an authenticated user with no specific privileges to read arbitrary non-PHP files on the server (e.g., .env, .htaccess, configuration backups, logs) by exploiting a Local File Inclusion (LFI) flaw in the `/core/ajax/selectobject.php` endpoint via the `objectdesc` parameter and a fail-open logic in the `restrictedArea()` access control function. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34036.
Read more ERPIn Ghost versions 5.101.6 to 6.19.2 a high severity vulnerability CVE-2026-29784 was detected. This vulnerability allows attackers to exploit incomplete CSRF protections around the /session/verify endpoint, enabling the use of one-time codes (OTCs) in login sessions different from the requesting session. In some scenarios, this could have made it easier for phishers to take over a Ghost site. To address this issue, users should upgrade Ghost to version 6.19.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-29784.
Read more CMSIn FreeScout versions prior to 1.8.206 a critical severity vulnerability CVE-2026-27637 was detected. This vulnerability allows attackers to compute predictable authentication tokens using `MD5(user_id + created_at + APP_KEY)`, enabling full account takeover, including administrative accounts, without requiring a password. To address this issue, users should upgrade FreeScout to version 1.8.206 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27637.
Read more Customer ServiceIn FreeScout versions prior to 1.8.206 a critical severity vulnerability CVE-2026-27636 was detected. This vulnerability allows authenticated users to upload `.htaccess` files on Apache servers with `AllowOverride All`, bypassing file upload restrictions and enabling remote code execution. To address this issue, users should upgrade FreeScout to version 1.8.206 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27636.
Read more Customer ServiceIn Dolibarr ERP/CRM version 10.0.1 a high severity vulnerability CVE-2019-25450 was detected. This vulnerability allows authenticated attackers to execute arbitrary SQL queries via POST parameters such as `actioncode`, `demand_reason_id`, and `availability_id` in the `card.php` endpoint, potentially exposing sensitive database information through boolean-based blind, error-based, or time-based blind SQL injection techniques. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2019-25450.
Read more ERP