Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "index.php"
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18720: Improper Authorization in kalcaddle kodboxCVE-2026-18720 0 CVE-2026-18720 is a medium severity vulnerability in kalcaddle kodbox version 1.67 Build 02 affecting the msgWarning plugin. It allows remote attackers to perform improper authorization via manipulation of the /index.php?plugin/msgWarning/action endpoint. Exploit code has been published, but no official vendor response or patch is available. Join the discussion | CVE Database V5 | 08/04/2026, 01:45:10 UTC Added: 08/04/2026, 12:56:07 UTC |
CVE-2026-45139: CWE-73: External Control of File Name or Path in ci4-cms-erp ci4msCVE-2026-45139 0 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive endpoints — `deleteFileOrFolder` and `renameFile` — never validate the extension of the *source* path. A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small `$hiddenItems` blocklist. Critical framework files such as `app/Config/Routes.php`, `app/Config/App.php`, `app/Config/Database.php`, `app/Config/Filters.php`, `public/index.php`, and `public/.htaccess` all live outside that blocklist and can be destroyed, producing a persistent denial of service that requires filesystem-level redeployment to recover. Version 0.31.9.0 patches the issue. Join the discussion | CVE Database V5 | 07/20/2026, 13:58:39 UTC Added: 07/20/2026, 14:42:39 UTC |
CVE-2026-16229: Cross Site Scripting in itsourcecode Courier Management SystemCVE-2026-16229 0 A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. Join the discussion | CVE Database V5 | 07/19/2026, 09:45:08 UTC Added: 07/19/2026, 09:57:19 UTC |
CVE-2026-52837: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in alextselegidis easyappointmentsCVE-2026-52837 0 Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`) without authentication and without field whitelisting. Anyone in possession of the 12-character `appointment_hash` — which appears in plain text in reschedule emails, confirmation page URLs, and operator-side calendar links — can read every column of that customer's row in the `ea_users` table. Version 1.6.0 contains a patch. Join the discussion | CVE Database V5 | 07/14/2026, 14:48:26 UTC Added: 07/14/2026, 15:18:25 UTC |
CVE-2026-15540: Improper Control of Filename for Include/Require Statement in PHP Program in SourceCodester Online Book Store SystemCVE-2026-15540 0 CVE-2026-15540 is a medium severity vulnerability in SourceCodester Online Book Store System version 1.0. It involves improper control of the filename used in an include or require statement within the administrative interface's /admin/index.php file. This flaw allows remote attackers to manipulate the 'page' argument, potentially leading to unintended file inclusion. The vulnerability is publicly known, but no official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 07/13/2026, 06:30:08 UTC Added: 07/13/2026, 07:51:42 UTC |
CVE-2026-15539: Unrestricted Upload in SourceCodester Online Book Store SystemCVE-2026-15539 0 A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 07/13/2026, 06:15:07 UTC Added: 07/13/2026, 06:33:20 UTC |
CVE-2026-15530: Information Disclosure in WuzhiCMSCVE-2026-15530 0 WuzhiCMS versions 4.0 and 4.1.0 contain an information disclosure vulnerability in the Attachment API component, specifically in the config/listimage function of /index.php?m=attachment&f=index&v=upload. This flaw allows remote attackers to manipulate the function to disclose information. The vulnerability has a medium severity rating with a CVSS score of 6.9. No official patch or remediation has been provided by the vendor as of the publication date. Exploit code has been published, but no known exploitation in the wild has been confirmed. Join the discussion | CVE Database V5 | 07/13/2026, 04:00:08 UTC Added: 07/13/2026, 05:18:05 UTC |
CVE-2026-15516: Authorization Bypass in MacCMS ProCVE-2026-15516 0 A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit is now public and may be used. Upgrading to version 2022.1000.3025 is recommended to address this issue. Upgrading the affected component is recommended. Join the discussion | CVE Database V5 | 07/13/2026, 00:15:08 UTC Added: 07/13/2026, 00:33:06 UTC |
CVE-2026-15134: SQL Injection in CodeAstro Simple Online Leave Management SystemCVE-2026-15134 0 A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Join the discussion | CVE Database V5 | 07/08/2026, 23:00:10 UTC Added: 07/08/2026, 23:29:31 UTC |
CVE-2026-42148: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coollabsio coolifyCVE-2026-42148 0 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell escaping, allowing an attacker who can set the helper version and trigger the helper image build in a development environment to execute arbitrary commands on the server. This issue is fixed in version 4.0.0-beta.474. Join the discussion | CVE Database V5 | 07/06/2026, 21:14:31 UTC Added: 07/06/2026, 21:53:29 UTC |
Showing 1 to 10 of 10 results