CVE-2026-24639
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVSS
4.4
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-918
Sin historial EPSS suficiente todavía.
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-655167.2 ALT—
——0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.5hCVE-2026-654964.4 MED—
——0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.5hCVE-2026-654674.9 MED—
——0Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.5hCVE-2026-654664.9 MED—
——0Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.5hCVE-2026-64873—7.8%
——2Custom query URLs could access internal or reserved network services.7hCVE-2026-64799—9.6%
——3Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.7h