CVE-2026-66564
Description détaillée
Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
Vecteur d'attaque (CVSS)
Dernières Vulnérabilités
CVE-2026-104841
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-108680
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to send template notifications by calling POST /sys/api/sendTemplateAnnouncement. Low-privileged attackers can supply forged sender, recipients, title, and template parameters to deliver messages appearing to come from admin or system accounts.
CVE-2026-108679
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.
