CVE-2025-13787
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of
CVSS
5.4
Medium
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Nov 30, 2025 · Last modified: Sep 3, 2026 · CWE-266 · CWE-269
0.4%EPSS · 30 days0.4%
2026-08-232026-09-20
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
- github.comhttps://github.com/ez-lbz/ez-lbz.github.io/issues/1
- github.comhttps://github.com/ez-lbz/ez-lbz.github.io/issues/1#issuecomment-3540423868
- vuldb.comhttps://vuldb.com/?ctiid.333791
- vuldb.comhttps://vuldb.com/?id.333791
- vuldb.comhttps://vuldb.com/?submit.689892
- www.zentao.nethttps://www.zentao.net/extension-buyext-1601-download.html
- github.comhttps://github.com/ez-lbz/ez-lbz.github.io/issues/1
- github.comhttps://github.com/ez-lbz/ez-lbz.github.io/issues/1#issuecomment-3540423868
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-940486.6 MED—
———A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.10hCVE-2026-940476.3 MED—
———A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template Import Endpoint. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. Upgrading to version 1.0.33 is sufficient to resolve this issue. The identifier of the patch is 18a4467bc4ec6390b1f841d8a468a37e9922f837. It is advisable to upgrade the affected component.10hCVE-2026-940368.8 HIG—
——0A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.14hCVE-2026-865544.3 MED9.7%
——3SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.20hCVE-2026-939683.8 LOW17.7%
——5A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.23hCVE-2026-925417.2 HIG3.2%
——1The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.16h