CVE-2023-36255
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path
CVSS
8.8
High
EPSS
52.8%
p99
KEV
—
Exploit Today
30
0-100
Published: Aug 3, 2023 · Last modified: Jul 9, 2026 · CWE-94
52.8%EPSS · 30 days52.8%
2026-08-022026-08-30
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.
- trovent.github.iohttps://trovent.github.io/security-advisories/TRSA-2303-01/TRSA-2303-01.txt
- trovent.iohttps://trovent.io/security-advisory-2303-01/
- www.eramba.orghttps://www.eramba.org
- trovent.github.iohttps://trovent.github.io/security-advisories/TRSA-2303-01/TRSA-2303-01.txt
- trovent.iohttps://trovent.io/security-advisory-2303-01/
- www.eramba.orghttps://www.eramba.org
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-826014.3 MED—
———A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.4hCVE-2026-825987.3 HIG—
———A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.5hCVE-2026-77956——
———Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code.
AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as an EEx template (Elixir source). Content such as <%= System.cmd(...) %> therefore executes on the server before any model request is made, requiring no authentication beyond reaching a prompt action. The fix stops evaluating function-supplied prompt content as EEx; only statically configured templates are evaluated.
This issue affects ash_ai: from 0.1.0 before 1.0.0.5hCVE-2026-825544.3 MED—
———A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used.12hCVE-2026-824883.5 LOW—
——0A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.19hCVE-2026-824833.5 LOW9.7%
——3A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.6.29 will fix this issue. It is recommended to upgrade the affected component.22h