Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-13546: Missing Authentication in Feehi CMSCVE-2026-13546
0

A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
CVE-2026-13544: Improper Access Controls in Feehi CMSCVE-2026-13544
0

A flaw has been found in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
CVE-2026-56394: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in craftcms cmsCVE-2026-56394
0

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

Join the discussion
CVE-2026-56393: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in craftcms cmsCVE-2026-56393
0

Craft CMS versions 4.x (from 4.0.0-RC1 up to but not including 4.17.0-beta.1) and 5.x (from 5.0.0-RC1 up to but not including 5.9.0-beta.1) contain multiple stored cross-site scripting (XSS) vulnerabilities. These arise because certain settings names and field option labels are rendered without proper sanitization, allowing an authenticated administrator with allowAdminChanges enabled to inject malicious JavaScript payloads. This can lead to arbitrary script execution in other users' control-panel sessions. The vulnerabilities are fixed starting from versions 4.17.0-beta.1 and 5.9.0-beta.1.

Join the discussion
CVE-2026-56385: Authorization Bypass Through User-Controlled Key in craftcms cmsCVE-2026-56385
0

Craft CMS versions 4.0.0-RC1 through 4.17.7 and 5.0.0-RC1 through 5.9.13 contain an authorization bypass vulnerability in the assets/preview-file endpoint. This flaw allows authenticated users with low privileges to access preview content of assets they are not authorized to view by supplying a controlled assetId. The vulnerability was fixed in versions 4.17.8 and 5.9.14.

Join the discussion
CVE-2026-56384: Missing Authorization in craftcms cmsCVE-2026-56384
0

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback transform preview link for that private asset, because no asset-view permission check is performed before preview generation. This affects versions >= 4.0.0-RC1, <= 4.17.7 and >= 5.0.0-RC1, <= 5.9.13, and is fixed in 4.17.8 and 5.9.14.

Join the discussion
CVE-2026-56383: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in craftcms cmsCVE-2026-56383
0

Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with allowAdminChanges enabled) to inject arbitrary JavaScript that executes when another user views a page containing the affected table field. Affected versions are >= 4.5.0-beta.1 through 4.16.18 and >= 5.0.0-RC1 through 5.8.22; fixed in 4.16.19 and 5.8.23.

Join the discussion
CVE-2026-56381: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in craftcms cmsCVE-2026-56381
0

Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the user group name field that executes when other users view or edit permissions.

Join the discussion
CVE-2026-49287: CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in statamic cmsCVE-2026-49287
0

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue in the query builder, but the same protection was not applied to in-memory collection sorting. Manipulating sort parameters could result in the loss of content and assets. This requires a front-end template that passes request input into a tag's sort parameter. It is not exploitable by default — a template would need to be explicitly set up to sort by a visitor-controlled value. This has been fixed in 5.73.23 and 6.20.0.

Join the discussion
CVE-2026-49288: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in statamic cmsCVE-2026-49288
0

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.

Join the discussion

Showing 1 to 10 of 10 results

Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses