Retour à la veille
CVE-2026-57916
Description détaillée
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.
Dernières Vulnérabilités
CVE-2026-66477
Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
VOIR DÉTAILS
CVE-2026-66476
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
VOIR DÉTAILS
CVE-2026-66475
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions.
VOIR DÉTAILS
