# Exploit-DB.com RSS Feed

The Exploit Database - Exploits, Shellcode, 0days, Remote Exploits, Local Exploits, Web Apps, Vulnerability Reports, Security Articles, Tutorials and more.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## \[remote\] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS \< 9.22, 10.0 \< 10.10, 11.0 \< 11.3 - RCE

DevFeed: [\[remote\] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS \< 9.22, 10.0 \< 10.10, 11.0 \< 11.3 - RCE](<https://devfeed.tech/articles/remote-cve-2026-80428-unauthenticated-php-object-injection-via-shibboleth-ilias-9-22-10-0-10-10-11-0-11-3-rce-34775.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52682>)

Author: DigiProSec

Published: 2026-09-11T00:00:00Z

Content type: news

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-80428](<https://devfeed.tech/tags/cve-2026-80428.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [object](<https://devfeed.tech/tags/object.md>), [php](<https://devfeed.tech/tags/php.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote](<https://devfeed.tech/tags/remote.md>)

### AI overview

CVE-2026-80428 is an unauthenticated PHP object injection vulnerability via Shibboleth in ILIAS versions earlier than 9.22, 10.10, and 11.3, with remote code execution indicated.

### Source excerpt

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

## \[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution

DevFeed: [\[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution](<https://devfeed.tech/articles/webapps-metabase-0-61-0-authenticated-remote-code-execution-34773.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52680>)

Author: Gutierre0x80

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-59827](<https://devfeed.tech/tags/cve-2026-59827.md>), [execution](<https://devfeed.tech/tags/execution.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit-DB entry identifies authenticated remote code execution affecting Metabase 0.61.0 and associates it with CVE-2026-59827.

### Source excerpt

Metabase 0.61.0 - Authenticated Remote Code Execution

## \[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)

DevFeed: [\[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)](<https://devfeed.tech/articles/webapps-freepbx-17-0-2-remote-code-execution-rce-34774.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52681>)

Author: Jared Brits

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-57819](<https://devfeed.tech/tags/cve-2025-57819.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry describing remote code execution affecting FreePBX 17.0.2, associated with CVE-2025-57819.

### Source excerpt

FreePBX 17.0.2 - Remote Code Execution (RCE)

## \[hardware\] Fullhan FH8626V100 - Multiple Vulnerabilities

DevFeed: [\[hardware\] Fullhan FH8626V100 - Multiple Vulnerabilities](<https://devfeed.tech/articles/hardware-fullhan-fh8626v100-multiple-vulnerabilities-34767.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52674>)

Author: Amir Aliu

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51407cve-2026-51406cve-2026-51405cve-2026-51404cve-2026-51403cve-2026-51402](<https://devfeed.tech/tags/cve-2026-51407cve-2026-51406cve-2026-51405cve-2026-51404cve-2026-51403cve-2026-51402.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This exploit record concerns multiple vulnerabilities in the Fullhan FH8626V100 hardware platform. It lists CVE-2026-51407 through CVE-2026-51402.

### Source excerpt

Fullhan FH8626V100 - Multiple Vulnerabilities

## \[webapps\] Langflow 1.10.0 - RCE

DevFeed: [\[webapps\] Langflow 1.10.0 - RCE](<https://devfeed.tech/articles/webapps-langflow-1-10-0-rce-34768.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52675>)

Author: Richard Howe

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-9198](<https://devfeed.tech/tags/cve-2026-9198.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An entry describing a remote code execution exploit affecting Langflow 1.10.0, identified as CVE-2026-9198.

### Source excerpt

Langflow 1.10.0 - RCE

## \[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution

DevFeed: [\[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution](<https://devfeed.tech/articles/webapps-ghost-cms-6-19-0-remote-code-execution-34769.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52676>)

Author: Maksim Rogov

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-29053](<https://devfeed.tech/tags/cve-2026-29053.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a remote code execution exploit affecting Ghost_CMS 6.19.0, associated with CVE-2026-29053 and listed for multiple platforms.

### Source excerpt

Ghost_CMS 6.19.0 - Remote Code Execution

## Wolf CMS 0.8.3.1 RCE Exploit (CVE-2026-67206)

DevFeed: [Wolf CMS 0.8.3.1 RCE Exploit (CVE-2026-67206)](<https://devfeed.tech/articles/webapps-wolf-cms-0-8-3-1-rce-v-34765.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52672>)

Author: Balachandar Gowrisankar

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Content Management System](<https://devfeed.tech/topics/cms.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-67206](<https://devfeed.tech/tags/cve-2026-67206.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry for Wolf CMS 0.8.3.1 describing a remote code execution issue identified as CVE-2026-67206.

### Source excerpt

Wolf CMS 0.8.3.1 - RCE v

## \[webapps\] Bludit CMS - Stored XSS

DevFeed: [\[webapps\] Bludit CMS - Stored XSS](<https://devfeed.tech/articles/webapps-bludit-cms-stored-xss-34763.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52670>)

Author: Saud Alenazi

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Content Management System](<https://devfeed.tech/topics/cms.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A concise exploit entry describing stored cross-site scripting (XSS) in Bludit CMS for web applications across multiple platforms.

### Source excerpt

Bludit CMS - Stored XSS

## \[webapps\] Grav CMS 2.0.7 - RCE

DevFeed: [\[webapps\] Grav CMS 2.0.7 - RCE](<https://devfeed.tech/articles/webapps-grav-cms-2-0-7-rce-34762.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52669>)

Author: zer0dayf

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Content Management System](<https://devfeed.tech/topics/cms.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cms](<https://devfeed.tech/tags/cms.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-65008](<https://devfeed.tech/tags/cve-2026-65008.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a remote code execution exploit affecting Grav CMS 2.0.7 and references CVE-2026-65008.

### Source excerpt

Grav CMS 2.0.7 - RCE

## \[webapps\] EasyAppointments 1.5.1 - Blind SQL Injection

DevFeed: [\[webapps\] EasyAppointments 1.5.1 - Blind SQL Injection](<https://devfeed.tech/articles/webapps-easyappointments-1-5-1-blind-sql-injection-34760.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52667>)

Author: Michael Chesang

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [SQL](<https://devfeed.tech/topics/sql.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-50455](<https://devfeed.tech/tags/cve-2025-50455.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [sql](<https://devfeed.tech/tags/sql.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry describes a blind SQL injection affecting EasyAppointments 1.5.1, identified as CVE-2025-50455.

### Source excerpt

EasyAppointments 1.5.1 - Blind SQL Injection

## \[webapps\] miniOrange 5.4.3 - Unauthenticated Auth Bypass

DevFeed: [\[webapps\] miniOrange 5.4.3 - Unauthenticated Auth Bypass](<https://devfeed.tech/articles/webapps-miniorange-5-4-3-unauthenticated-auth-bypass-34761.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52668>)

Author: zer0dayf

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-15013](<https://devfeed.tech/tags/cve-2026-15013.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

The entry identifies an unauthenticated authentication bypass affecting miniOrange 5.4.3, tracked as CVE-2026-15013. It is categorized as a web application exploit for multiple platforms.

### Source excerpt

miniOrange 5.4.3 - Unauthenticated Auth Bypass

## \[webapps\] CubeCart 6.7.4 - SQL

DevFeed: [\[webapps\] CubeCart 6.7.4 - SQL](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-sql-34756.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52663>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve-2026-54646](<https://devfeed.tech/tags/cve-2026-54646.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [sql](<https://devfeed.tech/tags/sql.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit database entry identifying a SQL exploit for CubeCart 6.7.4, associated with CVE-2026-54646.

### Source excerpt

CubeCart 6.7.4 - SQL

## \[webapps\] Linksys E1200\_2.0.04 - Unauthenticated OS Command Injection

DevFeed: [\[webapps\] Linksys E1200\_2.0.04 - Unauthenticated OS Command Injection](<https://devfeed.tech/articles/webapps-linksys-e1200-2-0-04-unauthenticated-os-command-injection-34753.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52660>)

Author: jarrett

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [command](<https://devfeed.tech/tags/command.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-60689](<https://devfeed.tech/tags/cve-2025-60689.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [os](<https://devfeed.tech/tags/os.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

This exploit listing identifies an unauthenticated OS command injection affecting Linksys E1200 version 2.0.04 and references CVE-2025-60689.

### Source excerpt

Linksys E1200_2.0.04 - Unauthenticated OS Command Injection

## \[webapps\] CubeCart 6.7.4 - Stored XSS

DevFeed: [\[webapps\] CubeCart 6.7.4 - Stored XSS](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-stored-xss-34755.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52662>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-54645](<https://devfeed.tech/tags/cve-2026-54645.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

An exploit entry for CubeCart 6.7.4 describing a stored cross-site scripting vulnerability identified as CVE-2026-54645. It is categorized as a web applications exploit for multiple platforms.

### Source excerpt

CubeCart 6.7.4 - Stored XSS

## \[webapps\] Langflow 1.8.4 - Path Traversal to Remote Code Execution

DevFeed: [\[webapps\] Langflow 1.8.4 - Path Traversal to Remote Code Execution](<https://devfeed.tech/articles/webapps-langflow-1-8-4-path-traversal-to-remote-code-execution-34752.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52659>)

Author: cardosource

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-5027](<https://devfeed.tech/tags/cve-2026-5027.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit record identifies a path traversal vulnerability in Langflow 1.8.4 that can lead to remote code execution. It references CVE-2026-5027.

### Source excerpt

Langflow 1.8.4 - Path Traversal to Remote Code Execution

## \[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)

DevFeed: [\[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)](<https://devfeed.tech/articles/webapps-c-mor-6-0104-cross-site-scripting-xss-34758.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52665>)

Author: Samir Shamdin

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51133](<https://devfeed.tech/tags/cve-2026-51133.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A C-MOR 6.0104 entry documenting a Cross-Site Scripting (XSS) exploit identified as CVE-2026-51133.

### Source excerpt

C-MOR 6.0104 - Cross-Site Scripting (XSS)

## \[webapps\] CubeCart 6.7.4 - SQL injection

DevFeed: [\[webapps\] CubeCart 6.7.4 - SQL injection](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-sql-injection-34757.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52664>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [SQL](<https://devfeed.tech/topics/sql.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-54647](<https://devfeed.tech/tags/cve-2026-54647.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit listing reports an SQL injection affecting CubeCart 6.7.4 and identifies it as CVE-2026-54647.

### Source excerpt

CubeCart 6.7.4 - SQL injection

## \[webapps\] CubeCart 6.7.4 - Cross-Site Scripting

DevFeed: [\[webapps\] CubeCart 6.7.4 - Cross-Site Scripting](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-cross-site-scripting-34754.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52661>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-54644](<https://devfeed.tech/tags/cve-2026-54644.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a cross-site scripting vulnerability in CubeCart 6.7.4, tracked as CVE-2026-54644.

### Source excerpt

CubeCart 6.7.4 - Cross-Site Scripting

## \[webapps\] C-MOR 6.0104 - Directory Traversal

DevFeed: [\[webapps\] C-MOR 6.0104 - Directory Traversal](<https://devfeed.tech/articles/webapps-c-mor-6-0104-directory-traversal-34759.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52666>)

Author: Samir Shamdin

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51134](<https://devfeed.tech/tags/cve-2026-51134.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry documenting a directory traversal vulnerability in C-MOR 6.0104, identified as CVE-2026-51134 and categorized for web applications on multiple platforms.

### Source excerpt

C-MOR 6.0104 - Directory Traversal

## \[remote\] PCMan 2.0.7 - Buffer Overflow

DevFeed: [\[remote\] PCMan 2.0.7 - Buffer Overflow](<https://devfeed.tech/articles/remote-pcman-2-0-7-buffer-overflow-34750.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52657>)

Author: Thiago Cunha

Published: 2026-08-18T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-4871](<https://devfeed.tech/tags/cve-2025-4871.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [remote](<https://devfeed.tech/tags/remote.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A remote buffer overflow exploit for PCMan 2.0.7 on Windows, associated with CVE-2025-4871.

### Source excerpt

PCMan 2.0.7 - Buffer Overflow

## \[webapps\] Joomla JCE\_2.9.15 - Remote Code Execution

DevFeed: [\[webapps\] Joomla JCE\_2.9.15 - Remote Code Execution](<https://devfeed.tech/articles/webapps-joomla-jce-2-9-15-remote-code-execution-34738.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52645>)

Author: Jared Brits

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-48907](<https://devfeed.tech/tags/cve-2026-48907.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

A record describing a remote code execution exploit affecting Joomla JCE 2.9.15, identified as CVE-2026-48907 and categorized under web applications for multiple platforms.

### Source excerpt

Joomla JCE_2.9.15 - Remote Code Execution

## \[webapps\] Duplicati 2.2.0.3 - JWT Signing Key Leak

DevFeed: [\[webapps\] Duplicati 2.2.0.3 - JWT Signing Key Leak](<https://devfeed.tech/articles/webapps-duplicati-2-2-0-3-jwt-signing-key-leak-34739.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52646>)

Author: Gabriel Rodrigues

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [exploit](<https://devfeed.tech/tags/exploit.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [leak](<https://devfeed.tech/tags/leak.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [signing](<https://devfeed.tech/tags/signing.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit listing identifies a JWT signing key leak in Duplicati 2.2.0.3 and describes it as a web application exploit for multiple platforms.

### Source excerpt

Duplicati 2.2.0.3 - JWT Signing Key Leak

## \[webapps\] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

DevFeed: [\[webapps\] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload](<https://devfeed.tech/articles/webapps-woocommerce-1-5-0-unauthenticated-arbitrary-file-upload-34735.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52642>)

Author: Mohammad Hossein Sadeghian

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-3891](<https://devfeed.tech/tags/cve-2026-3891.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry reports an unauthenticated arbitrary file upload vulnerability in WooCommerce 1.5.0, identified as CVE-2026-3891.

### Source excerpt

WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

## \[webapps\] Blocksy Companion 2.1.46 - RCE

DevFeed: [\[webapps\] Blocksy Companion 2.1.46 - RCE](<https://devfeed.tech/articles/webapps-blocksy-companion-2-1-46-rce-34733.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52640>)

Author: banyamer

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-58480](<https://devfeed.tech/tags/cve-2026-58480.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry identifies a remote code execution issue in Blocksy Companion 2.1.46, associated with CVE-2026-58480.

### Source excerpt

Blocksy Companion 2.1.46 - RCE

[Next page](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md?cursor=WyIyMDI2LTA4LTExVDAwOjAwOjAwKzAwOjAwIiwgImVjZGViODZhLTc1NDItNDQxNi1hNWFjLWRmYmIxNzQ0NTJiZSJd>)