cve.li

Recent

CVE-2026-107724CWE-347

fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery

Published 2026-10-08 by GitHub_M

CVE-2026-107831CWE-352

Jivejdon through 5.0 CSRF via GET-based Account and Thread Actions

Published 2026-10-08 by VulnCheck

CVE-2026-107830CWE-799

Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint

Published 2026-10-08 by VulnCheck

CVE-2026-107829CWE-916

Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql

Published 2026-10-08 by VulnCheck

CVE-2026-107828CWE-1391

Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login

Published 2026-10-08 by VulnCheck

CVE-2026-107801CWE-79

Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type

Published 2026-10-08 by VulnCheck

CVE-2026-107800CWE-79

Jivejdon through 5.0 Stored XSS via Private Short Messages

Published 2026-10-08 by VulnCheck

CVE-2026-107799CWE-79

Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering

Published 2026-10-08 by VulnCheck

CVE-2026-107798CWE-79

Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter

Published 2026-10-08 by VulnCheck

CVE-2026-107797CWE-79

Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters

Published 2026-10-08 by VulnCheck

Load more ↓