        <?xml version="1.0" encoding="UTF-8"?>
        <rss version="2.0">
          <channel>
            <title>Security News Radar</title>
            <link>index.html</link>
            <description>Aktuelle CVEs, bekannte Exploits und wichtige Cybersecurity-Meldungen.</description>
            <language>de-DE</language>
            <lastBuildDate>Tue, 18 Aug 2026 13:03:48 +0000</lastBuildDate>
            <atom:link xmlns:atom="http://www.w3.org/2005/Atom" href="feed.xml" rel="self" type="application/rss+xml" />

            <item>
              <title>CVE-2026-35219: Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, (budibase)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60381</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60381</guid>
              <pubDate>Tue, 18 Aug 2026 12:37:02 +0000</pubDate>
              <source>EUVD</source>
              <description>Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and packages/server/src/automations/steps/discord.ts use node-fetch on user-provided URLs without the BLACKLIST_IPS enforcement used by the REST integration, allowing an authenticated user to make server-side requests to cloud metadata and internal services. This issue is fixed in version 3.41.3.</description>
            </item>

            <item>
              <title>CVE-2026-67960: An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentControll (n/a)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60551</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60551</guid>
              <pubDate>Tue, 18 Aug 2026 12:30:43 +0000</pubDate>
              <source>EUVD</source>
              <description>An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components</description>
            </item>

            <item>
              <title>CVE-2026-42163: Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under  (n/a)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60549</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60549</guid>
              <pubDate>Tue, 18 Aug 2026 12:28:29 +0000</pubDate>
              <source>EUVD</source>
              <description>Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.</description>
            </item>

            <item>
              <title>CVE-2026-18751: External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.

This issue affects WorkSpace App: 2607. (Citrix)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60701</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60701</guid>
              <pubDate>Tue, 18 Aug 2026 12:26:35 +0000</pubDate>
              <source>EUVD</source>
              <description>External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.

This issue affects WorkSpace App: 2607.</description>
            </item>

            <item>
              <title>CVE-2026-51977: An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privilege (n/a)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60550</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60550</guid>
              <pubDate>Tue, 18 Aug 2026 12:26:09 +0000</pubDate>
              <source>EUVD</source>
              <description>An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component</description>
            </item>

            <item>
              <title>CVE-2026-74989: Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect an</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60700</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60700</guid>
              <pubDate>Tue, 18 Aug 2026 12:23:41 +0000</pubDate>
              <source>EUVD</source>
              <description>Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154.</description>
            </item>

            <item>
              <title>CVE-2026-74988: Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another secur</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60699</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60699</guid>
              <pubDate>Tue, 18 Aug 2026 12:23:41 +0000</pubDate>
              <source>EUVD</source>
              <description>Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.</description>
            </item>

            <item>
              <title>CVE-2026-74990: Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed eviden</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60673</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60673</guid>
              <pubDate>Tue, 18 Aug 2026 12:23:35 +0000</pubDate>
              <source>EUVD</source>
              <description>Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.</description>
            </item>

            <item>
              <title>CVE-2026-74987: Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corrupt</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60672</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60672</guid>
              <pubDate>Tue, 18 Aug 2026 12:23:34 +0000</pubDate>
              <source>EUVD</source>
              <description>Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.</description>
            </item>

            <item>
              <title>CVE-2026-75855: ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint&#x27;s create database and drop database comm</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75855</link>
              <guid isPermaLink="false">nvd:CVE-2026-75855</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:35 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint&#x27;s create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configured database directory. Attackers can supply database names containing ../ sequences to create databases at arbitrary filesystem paths or recursively delete directories the server process can access.</description>
            </item>

            <item>
              <title>CVE-2026-75854: ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75854</link>
              <guid isPermaLink="false">nvd:CVE-2026-75854</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:35 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates.</description>
            </item>

            <item>
              <title>CVE-2026-75853: ArcadeDB&#x27;s Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions &lt;= 26.7.3 enforces authentication (SASL PLAIN) but perfo</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75853</link>
              <guid isPermaLink="false">nvd:CVE-2026-75853</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:35 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB&#x27;s Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions &lt;= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server credential — even one provisioned for zero or one unrelated database — can read, write, and drop data in any database on the server by selecting a target database via a traversal-source alias, completely bypassing the engine&#x27;s per-type/read-only/UPDATE_SCHEMA ACLs. The issue is fixed in version 26.8.1.</description>
            </item>

            <item>
              <title>CVE-2026-75852: ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated at</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75852</link>
              <guid isPermaLink="false">nvd:CVE-2026-75852</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:35 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.</description>
            </item>

            <item>
              <title>CVE-2026-75851: ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75851</link>
              <guid isPermaLink="false">nvd:CVE-2026-75851</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:35 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. A user with only read access to a single database can submit an asynchronous JavaScript (language=js) command via the /api/v1/command endpoint to run code with unrestricted host access (e.g., database.getSecurity().createUser) and create a server-wide administrator, escalating to full administrative control. Fixed in 26.8.1.</description>
            </item>

            <item>
              <title>CVE-2026-75846: ArcadeDB before 26.8.1 (affected versions &lt;= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. De</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75846</link>
              <guid isPermaLink="false">nvd:CVE-2026-75846</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:35 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB before 26.8.1 (affected versions &lt;= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function without any checkPermissionsOnDatabase (UPDATE_SCHEMA) check. Any user with database access can execute DELETE FUNCTION via the command API (POST /api/v1/command/{db}) to permanently remove any registered server-side function, including security-relevant logic, impacting integrity and availability.</description>
            </item>

            <item>
              <title>CVE-2026-75844: ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security valida</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75844</link>
              <guid isPermaLink="false">nvd:CVE-2026-75844</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:34 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud metadata endpoints, internal services, or read arbitrary local files on default installations.</description>
            </item>

            <item>
              <title>CVE-2026-75843: ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authe</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75843</link>
              <guid isPermaLink="false">nvd:CVE-2026-75843</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:34 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts.</description>
            </item>

            <item>
              <title>CVE-2026-75842: ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticate</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75842</link>
              <guid isPermaLink="false">nvd:CVE-2026-75842</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:34 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.</description>
            </item>

            <item>
              <title>CVE-2026-75840: ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses une</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75840</link>
              <guid isPermaLink="false">nvd:CVE-2026-75840</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:34 +0000</pubDate>
              <source>NVD CVE</source>
              <description>ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes and read arbitrary files on the host system as the ArcadeDB server process.</description>
            </item>

            <item>
              <title>CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A deleg</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75837</link>
              <guid isPermaLink="false">nvd:CVE-2026-75837</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:33 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.</description>
            </item>

            <item>
              <title>CVE-2026-75836: The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav&#x27;s admin-next/API stack) before 1.0.14 fails to enforce the authorize require</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75836</link>
              <guid isPermaLink="false">nvd:CVE-2026-75836</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:33 +0000</pubDate>
              <source>NVD CVE</source>
              <description>The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav&#x27;s admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters menubar items via userPassesAuthorize(), the POST /api/v1/menubar/actions/{plugin}/{action} endpoint only checks the baseline api.access permission and never evaluates the authorize field a plugin registered for that action. Any authenticated caller with api.access can therefore invoke a privileged menubar action directly, bypassing the intended authorization. No plugin bundled with core Grav currently registers a privileged authorize handler, so on a stock install the impact is latent; the flaw affects any first- or third-party plugin relying on the documented authorize semantics.</description>
            </item>

            <item>
              <title>CVE-2026-75831: Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownEl</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75831</link>
              <guid isPermaLink="false">nvd:CVE-2026-75831</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:33 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers&#x27; sessions.</description>
            </item>

            <item>
              <title>CVE-2026-75830: grav-plugin-api (getgrav/grav-plugin-api) versions &gt;= 1.0.0-beta.10 and &lt;= 1.0.14 contain a path traversal vulnerability in the PagesControl</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75830</link>
              <guid isPermaLink="false">nvd:CVE-2026-75830</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:32 +0000</pubDate>
              <source>NVD CVE</source>
              <description>grav-plugin-api (getgrav/grav-plugin-api) versions &gt;= 1.0.0-beta.10 and &lt;= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled &#x27;suffix&#x27; parameter (via POST /api/v1/pages/batch) unvalidated. An authenticated user with the api.pages.write permission (editor-level, not super-admin) can supply path traversal sequences (e.g. /../../../) in the suffix parameter to escape the intended user/pages/ directory and write attacker-controlled page content and page media to arbitrary filesystem locations writable by the web server process. The vulnerability is fixed in 1.0.15.</description>
            </item>

            <item>
              <title>CVE-2026-75829: grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write pe</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75829</link>
              <guid isPermaLink="false">nvd:CVE-2026-75829</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:32 +0000</pubDate>
              <source>NVD CVE</source>
              <description>grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.</description>
            </item>

            <item>
              <title>CVE-2026-75828: Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attrib</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75828</link>
              <guid isPermaLink="false">nvd:CVE-2026-75828</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:32 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that pass validation and execute in visitor browsers when page content is rendered.</description>
            </item>

            <item>
              <title>CVE-2026-75827: Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomp</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75827</link>
              <guid isPermaLink="false">nvd:CVE-2026-75827</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:32 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.</description>
            </item>

            <item>
              <title>CVE-2026-74906: SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results usi</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74906</link>
              <guid isPermaLink="false">nvd:CVE-2026-74906</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:30 +0000</pubDate>
              <source>NVD CVE</source>
              <description>SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the visibility list instead of the disabled list. Anonymous visitors can discover and read content from documents explicitly marked as forbidden from publishing by accessing search, backlink, asset content, saved criteria, recent documents, graph, and tag endpoints.</description>
            </item>

            <item>
              <title>CVE-2026-74905: SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by </title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74905</link>
              <guid isPermaLink="false">nvd:CVE-2026-74905</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:30 +0000</pubDate>
              <source>NVD CVE</source>
              <description>SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeDialer to enforce SSRF protection in SafeMode. The function only checks for loopback, link-local unicast, private, and unspecified addresses and does not recognize IPv6 transition addresses (NAT64 64:ff9b::/96, 6to4 2002::/16, Teredo 2001::/32) that embed private IPv4 destinations. When SafeMode is enabled, an authenticated attacker can bypass the SSRF guard via the network forward proxy, WebSocket proxy, or SSE proxy endpoints by supplying a URL whose hostname resolves to such a transition address, reaching internal services and cloud metadata endpoints (e.g., 169.254.169.254). Because the forward proxy returns the full response body, this is a full-read SSRF that can be used to steal instance credentials, reach internal services, and port-scan internal infrastructure.</description>
            </item>

            <item>
              <title>CVE-2026-74904: SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, ch</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74904</link>
              <guid isPermaLink="false">nvd:CVE-2026-74904</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:30 +0000</pubDate>
              <source>NVD CVE</source>
              <description>SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access filtering, allowing anonymous publish-mode readers to disclose private block content-derived text, structural metadata, and existence information for arbitrary block IDs across the workspace.</description>
            </item>

            <item>
              <title>CVE-2026-74902: SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before </title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74902</link>
              <guid isPermaLink="false">nvd:CVE-2026-74902</guid>
              <pubDate>Tue, 18 Aug 2026 12:19:30 +0000</pubDate>
              <source>NVD CVE</source>
              <description>SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor.</description>
            </item>

            <item>
              <title>CVE-2026-15585: Improper Limitation of a Pathname to a Restricted Directory (&#x27;Path Traversal&#x27;) vulnerability in AKIN Software Computer Import Export Industr</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15585</link>
              <guid isPermaLink="false">nvd:CVE-2026-15585</guid>
              <pubDate>Tue, 18 Aug 2026 12:17:23 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Improper Limitation of a Pathname to a Restricted Directory (&#x27;Path Traversal&#x27;) vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal.

This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.</description>
            </item>

            <item>
              <title>CVE-2026-15585: Improper Limitation of a Pathname to a Restricted Directory (&#x27;Path Traversal&#x27;) vulnerability in AKIN Software Computer Import Export Industr (Akın Software Computer Import Export Industry and Trade Ltd.)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60617</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60617</guid>
              <pubDate>Tue, 18 Aug 2026 11:23:26 +0000</pubDate>
              <source>EUVD</source>
              <description>Improper Limitation of a Pathname to a Restricted Directory (&#x27;Path Traversal&#x27;) vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal.

This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.</description>
            </item>

            <item>
              <title>CVE-2026-75855: ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint&#x27;s create database and drop database comm (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60616</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60616</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:57 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint&#x27;s create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configured database directory. Attackers can supply database names containing ../ sequences to create databases at arbitrary filesystem paths or recursively delete directories the server process can access.</description>
            </item>

            <item>
              <title>CVE-2026-75854: ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60615</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60615</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:57 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on the server without providing credentials, bypassing all security gates.</description>
            </item>

            <item>
              <title>CVE-2026-75853: ArcadeDB&#x27;s Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions &lt;= 26.7.3 enforces authentication (SASL PLAIN) but perfo (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60614</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60614</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:56 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB&#x27;s Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions &lt;= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and never binds the authenticated principal into the engine. As a result, any valid server credential — even one provisioned for zero or one unrelated database — can read, write, and drop data in any database on the server by selecting a target database via a traversal-source alias, completely bypassing the engine&#x27;s per-type/read-only/UPDATE_SCHEMA ACLs. The issue is fixed in version 26.8.1.</description>
            </item>

            <item>
              <title>CVE-2026-75852: ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated at (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60613</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60613</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:55 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.</description>
            </item>

            <item>
              <title>CVE-2026-75851: ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60612</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60612</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:55 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. A user with only read access to a single database can submit an asynchronous JavaScript (language=js) command via the /api/v1/command endpoint to run code with unrestricted host access (e.g., database.getSecurity().createUser) and create a server-wide administrator, escalating to full administrative control. Fixed in 26.8.1.</description>
            </item>

            <item>
              <title>CVE-2026-75846: ArcadeDB before 26.8.1 (affected versions &lt;= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. De (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60610</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60610</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:53 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB before 26.8.1 (affected versions &lt;= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a server-side function without any checkPermissionsOnDatabase (UPDATE_SCHEMA) check. Any user with database access can execute DELETE FUNCTION via the command API (POST /api/v1/command/{db}) to permanently remove any registered server-side function, including security-relevant logic, impacting integrity and availability.</description>
            </item>

            <item>
              <title>CVE-2026-75844: ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security valida (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60608</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60608</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:51 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud metadata endpoints, internal services, or read arbitrary local files on default installations.</description>
            </item>

            <item>
              <title>CVE-2026-75843: ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authe (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60607</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60607</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:51 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a transaction ID to run unrestricted JavaScript that creates server-wide administrator accounts.</description>
            </item>

            <item>
              <title>CVE-2026-75842: ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticate (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60606</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60606</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:50 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.</description>
            </item>

            <item>
              <title>CVE-2026-75840: ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses une (ArcadeData)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60604</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60604</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:49 +0000</pubDate>
              <source>EUVD</source>
              <description>ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile classes and read arbitrary files on the host system as the ArcadeDB server process.</description>
            </item>

            <item>
              <title>CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A deleg (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60601</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60601</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:47 +0000</pubDate>
              <source>EUVD</source>
              <description>Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities.</description>
            </item>

            <item>
              <title>CVE-2026-75836: The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav&#x27;s admin-next/API stack) before 1.0.14 fails to enforce the authorize require (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60600</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60600</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:46 +0000</pubDate>
              <source>EUVD</source>
              <description>The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav&#x27;s admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters menubar items via userPassesAuthorize(), the POST /api/v1/menubar/actions/{plugin}/{action} endpoint only checks the baseline api.access permission and never evaluates the authorize field a plugin registered for that action. Any authenticated caller with api.access can therefore invoke a privileged menubar action directly, bypassing the intended authorization. No plugin bundled with core Grav currently registers a privileged authorize handler, so on a stock install the impact is latent; the flaw affects any first- or third-party plugin relying on the documented authorize semantics.</description>
            </item>

            <item>
              <title>CVE-2026-75835: Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApi (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60599</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60599</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:45 +0000</pubDate>
              <source>EUVD</source>
              <description>Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request&#x27;s API key scopes, relying instead on the account&#x27;s raw super-admin flag and ACL grants. As a result, an authenticated attacker holding a scoped API key minted on a privileged account can bypass their declared scope restrictions to access authorize-gated UI metadata and item definitions (sidebar/menubar/widget items and users-list columns/row-actions/filter-tabs) that their key scope should deny, resulting in information disclosure.</description>
            </item>

            <item>
              <title>CVE-2026-75833: The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0&#x27;s admin-next/API stack) before version 1.0.14 contains an open redirect  (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60597</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60597</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:44 +0000</pubDate>
              <source>EUVD</source>
              <description>The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0&#x27;s admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal &#x27;//&#x27; prefix but does not account for browsers normalizing backslashes to slashes in special (http/https) schemes, so a returnTo value such as &#x27;/\evil.com&#x27; passes the guard and is later resolved by the browser as the protocol-relative URL &#x27;//evil.com&#x27;. Following a legitimate OAuth login flow, an attacker-supplied returnTo parameter could redirect an authenticated victim to an attacker-controlled site for post-login phishing. Full browser-side exploitability depends on the admin-next SPA&#x27;s client-side oauth-callback handler and was not independently verified by the reporter.</description>
            </item>

            <item>
              <title>CVE-2026-75832: The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorizatio (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60596</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60596</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:43 +0000</pubDate>
              <source>EUVD</source>
              <description>The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/&lt;name&gt; scope on the account&#x27;s raw super-admin ACL flag (access.api.super) instead of validating the presented API key&#x27;s actual scope. An attacker holding an API key scoped only to api.media.write minted on a super-admin account can bypass the authorization check and, via POST /blueprint-upload or GET /blueprint-files, write a file into another user&#x27;s scope (in the shared user/accounts/ directory, constrained to image extensions by assertSafeExtension()) and browse that scope&#x27;s file listing, despite the key not being granted api.users.write.</description>
            </item>

            <item>
              <title>CVE-2026-75830: grav-plugin-api (getgrav/grav-plugin-api) versions &gt;= 1.0.0-beta.10 and &lt;= 1.0.14 contain a path traversal vulnerability in the PagesControl (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60594</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60594</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:42 +0000</pubDate>
              <source>EUVD</source>
              <description>grav-plugin-api (getgrav/grav-plugin-api) versions &gt;= 1.0.0-beta.10 and &lt;= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled &#x27;suffix&#x27; parameter (via POST /api/v1/pages/batch) unvalidated. An authenticated user with the api.pages.write permission (editor-level, not super-admin) can supply path traversal sequences (e.g. /../../../) in the suffix parameter to escape the intended user/pages/ directory and write attacker-controlled page content and page media to arbitrary filesystem locations writable by the web server process. The vulnerability is fixed in 1.0.15.</description>
            </item>

            <item>
              <title>CVE-2026-75829: grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write pe (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60593</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60593</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:41 +0000</pubDate>
              <source>EUVD</source>
              <description>grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameters to execute server-side template injection payloads that are evaluated at render time.</description>
            </item>

            <item>
              <title>CVE-2026-75828: Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attrib (getgrav)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60592</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60592</guid>
              <pubDate>Tue, 18 Aug 2026 11:19:41 +0000</pubDate>
              <source>EUVD</source>
              <description>Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that pass validation and execute in visitor browsers when page content is rendered.</description>
            </item>

          </channel>
        </rss>
