CVE-2026-42539
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28
CVSS
6.5
Medio
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 4 jun 2026 · Última mod.: 22 jul 2026 · CWE-201
0.2%EPSS · 30 días0.2%
2026-07-282026-08-24
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-665857.5 ALT—
——0Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.2dCVE-2026-598094.9 MED15.3%
——5SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.4dCVE-2026-63481—38.3%
——12Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but it carries RequestSpec.cookies created from the dedicated [Cookies] section into the redirected request. An attacker-controlled redirect can therefore receive authentication or session cookies that should remain scoped to the original host. Cookies supplied through a raw Cookie header are stripped and are not affected by this specific path. This issue is reported as fixed in version 8.1.0.4dCVE-2026-75953—4.4%
——1Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.7dCVE-2026-733867.5 ALT15.5%
——5Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.6dCVE-2026-733847.5 ALT15.5%
——5Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.6d