Retour à la veille
CVE-2026-97150
Score CVSS
7.2
HIGH
Description détaillée
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Dernières Vulnérabilités
CVE-2026-97302
Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
VOIR DÉTAILS
CVE-2026-97301
Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
VOIR DÉTAILS
CVE-2026-97299
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
VOIR DÉTAILS
