Known Vulnerabilities for Commander Pro by Corsair
Listed below are 1 of the newest known vulnerabilities associated with "Commander Pro" by "Corsair".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Corsair Commander Pro
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82460 json | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints tha... | Not Provided | 2026-08-29 | 2026-08-31 |
| CVE-2026-76367 json | In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a n... | Not Provided | 2026-08-19 | 2026-08-26 |
| CVE-2026-66493 json | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for ... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-66492 json | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in t... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-66491 json | Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSou... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-65765 json | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for ... | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-65764 json | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs... | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2022-24573 json | A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenti... | Not Provided | 2022-03-03 | 2026-07-09 |
| CVE-2018-19592 json | The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivi... | 7.8 - HIGH | 2019-09-27 | 2019-10-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Corsair | Commander Pro | - |