Authenticated (Administrator+) SQL Injection via `order_by` Parameter vulnerability
3 days ago
Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion vulnerability
1 July, 2025
Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion vulnerability
1 July, 2025
Authenticated (Contributor+) Stored DOMBased CrossSite Scripting via id and datasize Parameters vulnerability
5 June, 2025
Order Replay vulnerability
17 April, 2025