Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:composer/flightphp/core

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Join the discussion

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Join the discussion

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Join the discussion

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

Join the discussion

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide whether a property is exposed. The componentsCache arrays in ApiPlatform\JsonApi\Serializer\ItemNormalizer and ApiPlatform\Hal\Serializer\ItemNormalizer are keyed on $context['cache_key'], which is set unconditionally before delegating to the parent normalizer. The component structure (attributes, relationships, links) computed for one request can therefore be reused for a subsequent request whose user has a different set of accessible properties. A user with lower privileges may end up seeing the structure of properties that the security predicate would otherwise have hidden for them. This issue has been fixed in versions 4.1.29, 4.2.26, and 4.3.12.

Join the discussion

CVE-2026-9811 is a stored Cross-Site Scripting (XSS) vulnerability in Mautic version 7.0.0. It occurs in the project selector component where project names returned via AJAX are not properly sanitized before being injected into the DOM. An authenticated user with project creation permissions can store malicious scripts in project names, which execute when another administrative user opens an entity editor containing the project selector. This can lead to session hijacking or unauthorized access to organizational data within the dashboard.

Join the discussion

CVE-2026-9809 is a stored Cross-Site Scripting (XSS) vulnerability in Mautic version 7.0.0 affecting the Projects component. It occurs when project names supplied by authenticated users with project creation or editing permissions are rendered without proper sanitization in administrative detail views. This allows malicious scripts to execute in the browser context of administrative users who view or hover over compromised project tags, potentially enabling unauthorized administrative actions or data exfiltration.

Join the discussion
0

CVE-2026-9808 is an authorization bypass vulnerability in Mautic 7.0.0 API v2 endpoints. Roles with owner-scope restrictions such as 'viewown' or 'editown' are not properly enforced, allowing low-privilege authenticated API users to access or modify resources owned by other users. This vulnerability has a high severity with a CVSS score of 7.1.

Join the discussion

CVE-2026-9559 is a critical path traversal vulnerability in Mautic version 7.0.0 affecting the campaign import feature. It allows an authenticated user with campaign import privileges to write arbitrary PHP files outside the intended temporary directories by exploiting improper validation of ZIP file extraction paths. This can lead to remote code execution under the web server user context.

Join the discussion

CVE-2026-9558 is a critical Server-Side Template Injection (SSTI) vulnerability in Mautic's theme engine. It allows authenticated users with theme creation or upload permissions to execute arbitrary code on the hosting server or access restricted system files. The vulnerability arises because the platform renders uploaded Twig templates without sandboxing or strict function restrictions. This can lead to remote code execution and full compromise of confidentiality, integrity, and availability of the affected system.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Package: pkg:composer/flightphp/core
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses