Six software vulnerabilities disclosed, including remote code execution flaws

Between 2026-09-18 and 2026-09-21, six CVEs affecting web and productivity software were publicly disclosed: Browsertrix versions 1.15.0–1.22.7 allow OS command execution via Git URL sanitization failures; SiYuan 3.8.3 and earlier allow code execution through notebook bookmark labels and document titles; Netcore NBR200V2 router allows remote code execution via VLAN memory overwrite; NivoCart permits script upload to public folders by low-privilege users; and openEQUELLA pre-2026.1.0 allows authenticated code injection in reports.

19 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-54501: Browsertrix lets privileged users run OS commands

stream:bsky-jetstreamother11d ago kagi ↗

CVE-2026-54501 - browsertrix Versions 1.15.0 through 1.22.7 of Browsertrix do not properly clean Git URLs used in custom behavior settings, so someone with crawler or admin rights can make the system… Too many irrelevant or confusing CVEs? Use stackflag.com #browsertrix #webrecorder #CVE #infosec Versions 1.15.0 through 1.22.7 of Browsertrix do not properly clean Git URLs used in custom behavior s

CVE-2026-92985: SiYuan before 3.8.4 lets malicious notebook files run code

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-92985 - siyuan Older versions of SiYuan do not properly clean up the text used for bookmark labels when a notebook file is opened. A specially crafted notebook can contain hidden code that runs on… Too many irrelevant or confusing CVEs? Use stackflag.com #siyuan #siyuannote #CVE #infosec Older versions of SiYuan do not properly clean up the text used for bookmark labels when a notebook fi

CVE-2026-92986: SiYuan before 3.8.4 can run code via document titles

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-92986 - siyuan The SiYuan note‑taking app lets a note's title be displayed without cleaning out special characters. An attacker who can change a title could insert code that runs on the user’s… Too many irrelevant or confusing CVEs? Use stackflag.com #siyuan #siyuannote #CVE #infosec The SiYuan note‑taking app lets a note's title be displayed without cleaning out special characters.

CVE-2026-92980: HortusFox-Web allows admins to run any command

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-92980 - hortusfox-web In versions before 6.1, an admin who uses the Import/Export feature can cause the web server to execute any operating‑system command. This could let an attacker… Too many irrelevant or confusing CVEs? Use stackflag.com #hortusfoxweb #danielbrendel #CVE #infosec In versions before 6.1, an admin who uses the Import/Export feature can cause the web server to execute any

CVE-2026-77929: ClipBucket lets attackers run code through photo upload

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-77929 - clipbucket-v5 The ClipBucket video sharing software lets logged‑in users upload files. Because the system does not correctly change the file type after checking the content, a user… Too many irrelevant or confusing CVEs? Use stackflag.com #clipbucketv5 #macwarrior #CVE #infosec The ClipBucket video sharing software lets logged‑in users upload files.

CVE-2026-62943: btrbk backup tool lets SSH users run extra commands

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-62943 - btrbk Versions 0.29.0 through 0.32.6 of the btrbk backup utility allow a user who connects via SSH to add extra commands after the expected backup command. This can let an attacker run any… Too many irrelevant or confusing CVEs? Use stackflag.com #btrbk #digint #CVE #infosec Versions 0.29.0 through 0.32.6 of the btrbk backup utility allow a user who connects via SSH to add extra c

CVE-2026-89274: WP Recipe Maker can run malicious shortcodes

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-89274 The WP Recipe Maker plugin for WordPress lets anyone who can post a comment that gets approved add code that runs on every recipe page. This could cause hidden data or other site content to be shown to… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec The WP Recipe Maker plugin for WordPress lets anyone who can post a comment that gets approved add code that ru

CVE-2026-93741: Totolink A3002MU remote buffer overflow via submit URL

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-93741 - a3002mu The Totolink A3002MU router can be tricked into overflowing memory when a specially crafted web request is sent to its configuration page. This could let an attacker take control of… Too many irrelevant or confusing CVEs? Use stackflag.com #a3002mu #totolink #CVE #infosec The Totolink A3002MU router can be tricked into overflowing memory when a specially crafted web reques

CVE-2026-93922: SiYuan up to 3.8.4 lets malicious notebook names run code

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-93922 - siyuan The SiYuan note‑taking app (versions 3.8.4 and earlier) shows notebook names without cleaning them first. If an attacker creates a notebook with specially crafted HTML in its name,… Too many irrelevant or confusing CVEs? Use stackflag.com #siyuan #siyuannote #CVE #infosec The SiYuan note‑taking app (versions 3.8.4 and earlier) shows notebook names without cleaning them firs

CVE-2026-86591: Botiga Pro plugin lets anyone change site settings

stream:bsky-jetstreamother10d ago kagi ↗

CVE-2026-86591 - botiga pro The Botiga Pro add‑on for WordPress allows people who are not logged in to use a special web address to modify the site’s configuration, add malicious code that runs on every… Too many irrelevant or confusing CVEs? Use stackflag.com #botigapro #unknown #CVE #infosec The Botiga Pro add‑on for WordPress allows people who are not logged in to use a special web address to m

CVE-2026-78030: libdbi-perl DBM driver can load arbitrary files

stream:bsky-jetstreamother9d ago kagi ↗

CVE-2026-78030 - libdbi-perl The Perl DBI DBM driver (libdbi-perl) lets users specify a file name that the system will load and run without checking it. If an attacker can influence… Too many irrelevant or confusing CVEs? Use stackflag.com #libdbiperl #canonical #UbuntuPro1404LTS #CVE #infosec The Perl DBI DBM driver (libdbi-perl) lets users specify a file name that the system will load and run wi

CVE-2026-93992: Gopeed can write files outside intended folder via malicious archive

stream:bsky-jetstreamother9d ago kagi ↗

CVE-2026-93992 - gopeed Gopeed up to version 2.0.0-beta.3 may place files anywhere on the system when a user downloads a crafted archive and has the AutoExtract feature turned on. This lets an attacker add… Too many irrelevant or confusing CVEs? Use stackflag.com #gopeed #gopeedlab #CVE #infosec Gopeed up to version 2.0.0-beta.3 may place files anywhere on the system when a user downloads a crafte

CVE-2026-90817: REDCap allows remote code execution via public survey

stream:bsky-jetstreamother9d ago kagi ↗

CVE-2026-90817 The REDCap system (version 13.3.0 and later) can be tricked into running any code an attacker provides, without needing a login, by sending specially crafted requests to a public survey link. This could let an… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec The REDCap system (version 13.3.0 and later) can be tricked into running any code an attacker provides,

CVE-2026-88856: OrdaSoft Joomla Gallery extension lets attackers run code

stream:bsky-jetstreamother9d ago kagi ↗

CVE-2026-88856 - ordasoft joomla gallery free extension for joomla The free OrdaSoft Joomla Gallery add‑on for Joomla versions before 6.2.7 lets a logged‑in user tell the system to execute any command it chooses. This can let… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec The free OrdaSoft Joomla Gallery add‑on for Joomla versions before 6.2.7 lets a logged‑in user tell th

CVE-2026-94095: Netcore NBR200V2 traceroute feature allows remote code execution

stream:bsky-jetstreamother9d ago kagi ↗

CVE-2026-94095 - nbr200v2 The traceroute diagnostic tool on Netcore NBR200V2 can be tricked into running any command by sending a specially crafted URL. An attacker on the network could use this to take… Too many irrelevant or confusing CVEs? Use stackflag.com #nbr200v2 #netcore #CVE #infosec The traceroute diagnostic tool on Netcore NBR200V2 can be tricked into running any command by sending a sp

CVE-2026-94097: Netcore NBR200V2 allows remote command injection via network tools

stream:bsky-jetstreamother9d ago kagi ↗

CVE-2026-94097 - nbr200v2 The Netcore NBR200V2 device version 1.3.241127.071246 contains a flaw in its web-based network tools page that lets an attacker run arbitrary commands on the system. This can be… Too many irrelevant or confusing CVEs? Use stackflag.com #nbr200v2 #netcore #CVE #infosec The Netcore NBR200V2 device version 1.3.241127.071246 contains a flaw in its web-based network tools page

CVE-2026-94101: Netcore NBR200V2 router allows remote code execution

stream:bsky-jetstreamother8d ago kagi ↗

CVE-2026-94101 - nbr200v2 The router's software component that handles VLAN settings can be tricked into overwriting memory when a specially crafted WAN number is sent. An attacker on the network could… Too many irrelevant or confusing CVEs? Use stackflag.com #nbr200v2 #netcore #CVE #infosec The router's software component that handles VLAN settings can be tricked into overwriting memory when a sp

CVE-2026-94104: NivoCart lets attackers upload malicious files

stream:bsky-jetstreamother8d ago kagi ↗

CVE-2026-94104 If someone with view‑only back‑office access logs in, they can place a script file in the public image folder and make the server run it. This could let an attacker take control of the web site. Upgrade… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec Versions of NivoCart up to 2.4.0 let users who only have view rights in the admin area upload files without ch

CVE-2026-94109: openEQUELLA before 2026.1.0 lets logged‑in users run code

stream:bsky-jetstreamother8d ago kagi ↗

CVE-2026-94109 - openequella Versions of openEQUELLA released before 2026.1.0 allow someone who has a valid account to insert specially crafted text into reports or dashboards that causes the system to execute… Too many irrelevant or confusing CVEs? Use stackflag.com #openequella #CVE #infosec Versions of openEQUELLA released before 2026.1.0 allow someone who has a valid account to insert speciall