# webapps

Webapps are small, platform-independent web-based programs downloaded on demand and executed inside a client such as a browser.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## \[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution

DevFeed: [\[webapps\] Metabase 0.61.0 - Authenticated Remote Code Execution](<https://devfeed.tech/articles/webapps-metabase-0-61-0-authenticated-remote-code-execution-34773.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52680>)

Author: Gutierre0x80

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-59827](<https://devfeed.tech/tags/cve-2026-59827.md>), [execution](<https://devfeed.tech/tags/execution.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit-DB entry identifies authenticated remote code execution affecting Metabase 0.61.0 and associates it with CVE-2026-59827.

### Source excerpt

Metabase 0.61.0 - Authenticated Remote Code Execution

## \[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)

DevFeed: [\[webapps\] FreePBX 17.0.2 - Remote Code Execution (RCE)](<https://devfeed.tech/articles/webapps-freepbx-17-0-2-remote-code-execution-rce-34774.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52681>)

Author: Jared Brits

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-57819](<https://devfeed.tech/tags/cve-2025-57819.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry describing remote code execution affecting FreePBX 17.0.2, associated with CVE-2025-57819.

### Source excerpt

FreePBX 17.0.2 - Remote Code Execution (RCE)

## \[webapps\] Langflow 1.10.0 - RCE

DevFeed: [\[webapps\] Langflow 1.10.0 - RCE](<https://devfeed.tech/articles/webapps-langflow-1-10-0-rce-34768.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52675>)

Author: Richard Howe

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-9198](<https://devfeed.tech/tags/cve-2026-9198.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [rce](<https://devfeed.tech/tags/rce.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An entry describing a remote code execution exploit affecting Langflow 1.10.0, identified as CVE-2026-9198.

### Source excerpt

Langflow 1.10.0 - RCE

## \[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution

DevFeed: [\[webapps\] Ghost\_CMS 6.19.0 - Remote Code Execution](<https://devfeed.tech/articles/webapps-ghost-cms-6-19-0-remote-code-execution-34769.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52676>)

Author: Maksim Rogov

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-29053](<https://devfeed.tech/tags/cve-2026-29053.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry identifies a remote code execution exploit affecting Ghost_CMS 6.19.0, associated with CVE-2026-29053 and listed for multiple platforms.

### Source excerpt

Ghost_CMS 6.19.0 - Remote Code Execution

## \[webapps\] Bludit CMS - Stored XSS

DevFeed: [\[webapps\] Bludit CMS - Stored XSS](<https://devfeed.tech/articles/webapps-bludit-cms-stored-xss-34763.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52670>)

Author: Saud Alenazi

Published: 2026-09-01T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [XSS](<https://devfeed.tech/topics/xss.md>), [Content Management System](<https://devfeed.tech/topics/cms.md>), [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cms](<https://devfeed.tech/tags/cms.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [stored](<https://devfeed.tech/tags/stored.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A concise exploit entry describing stored cross-site scripting (XSS) in Bludit CMS for web applications across multiple platforms.

### Source excerpt

Bludit CMS - Stored XSS

## \[webapps\] CubeCart 6.7.4 - SQL

DevFeed: [\[webapps\] CubeCart 6.7.4 - SQL](<https://devfeed.tech/articles/webapps-cubecart-6-7-4-sql-34756.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52663>)

Author: Mikail KOCADAĞ

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve-2026-54646](<https://devfeed.tech/tags/cve-2026-54646.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [sql](<https://devfeed.tech/tags/sql.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit database entry identifying a SQL exploit for CubeCart 6.7.4, associated with CVE-2026-54646.

### Source excerpt

CubeCart 6.7.4 - SQL

## \[webapps\] Linksys E1200\_2.0.04 - Unauthenticated OS Command Injection

DevFeed: [\[webapps\] Linksys E1200\_2.0.04 - Unauthenticated OS Command Injection](<https://devfeed.tech/articles/webapps-linksys-e1200-2-0-04-unauthenticated-os-command-injection-34753.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52660>)

Author: jarrett

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [command](<https://devfeed.tech/tags/command.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-60689](<https://devfeed.tech/tags/cve-2025-60689.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [os](<https://devfeed.tech/tags/os.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

This exploit listing identifies an unauthenticated OS command injection affecting Linksys E1200 version 2.0.04 and references CVE-2025-60689.

### Source excerpt

Linksys E1200_2.0.04 - Unauthenticated OS Command Injection

## \[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)

DevFeed: [\[webapps\] C-MOR 6.0104 - Cross-Site Scripting (XSS)](<https://devfeed.tech/articles/webapps-c-mor-6-0104-cross-site-scripting-xss-34758.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52665>)

Author: Samir Shamdin

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [XSS](<https://devfeed.tech/topics/xss.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-51133](<https://devfeed.tech/tags/cve-2026-51133.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [webapps](<https://devfeed.tech/tags/webapps.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

A C-MOR 6.0104 entry documenting a Cross-Site Scripting (XSS) exploit identified as CVE-2026-51133.

### Source excerpt

C-MOR 6.0104 - Cross-Site Scripting (XSS)

## \[webapps\] Joomla JCE\_2.9.15 - Remote Code Execution

DevFeed: [\[webapps\] Joomla JCE\_2.9.15 - Remote Code Execution](<https://devfeed.tech/articles/webapps-joomla-jce-2-9-15-remote-code-execution-34738.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52645>)

Author: Jared Brits

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [webapps](<https://devfeed.tech/topics/webapps.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-48907](<https://devfeed.tech/tags/cve-2026-48907.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

A record describing a remote code execution exploit affecting Joomla JCE 2.9.15, identified as CVE-2026-48907 and categorized under web applications for multiple platforms.

### Source excerpt

Joomla JCE_2.9.15 - Remote Code Execution

## \[webapps\] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

DevFeed: [\[webapps\] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload](<https://devfeed.tech/articles/webapps-woocommerce-1-5-0-unauthenticated-arbitrary-file-upload-34735.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52642>)

Author: Mohammad Hossein Sadeghian

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-3891](<https://devfeed.tech/tags/cve-2026-3891.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [platform](<https://devfeed.tech/tags/platform.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An exploit entry reports an unauthenticated arbitrary file upload vulnerability in WooCommerce 1.5.0, identified as CVE-2026-3891.

### Source excerpt

WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

## \[webapps\] Ray 2.56.0 - Directory Traversal & Local File Inclusion

DevFeed: [\[webapps\] Ray 2.56.0 - Directory Traversal & Local File Inclusion](<https://devfeed.tech/articles/webapps-ray-2-56-0-directory-traversal-local-file-inclusion-34728.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52635>)

Author: Richard Howe

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [webapps](<https://devfeed.tech/topics/webapps.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [exploit](<https://devfeed.tech/tags/exploit.md>), [inclusion](<https://devfeed.tech/tags/inclusion.md>), [local](<https://devfeed.tech/tags/local.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry describing directory traversal and local file inclusion vulnerabilities in Ray 2.56.0, affecting web applications across multiple platforms.

### Source excerpt

Ray 2.56.0 - Directory Traversal & Local File Inclusion