CVE-2026-78202
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manip
CVSS
7.3
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 24 ago 2026 · Última mod.: 24 ago 2026 · CWE-284 · CWE-434
Sin historial EPSS suficiente todavía.
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-78337——
——0Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.3hCVE-2026-782457.3 ALT—
——0A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.3hCVE-2026-198526.1 MED—
——0NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.10hCVE-2026-76609—34.0%
——10Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.2dCVE-2026-76608—34.0%
——10Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.2dCVE-2026-76607—34.0%
——10Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.1d