Known Vulnerabilities for Cms Server by Microfocus
Listed below are 2 of the newest known vulnerabilities associated with "Cms Server" by "Microfocus".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103757 json | Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl fun... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103542 json | A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/a... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103532 json | A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file ... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103530 json | A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shar... | Not Provided | 2026-10-01 | 2026-09-30 |
| CVE-2026-103474 json | yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated man... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103472 json | restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103471 json | restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated at... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103399 json | A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request bod... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103389 json | MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy ... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-103321 json | MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview ima... | Not Provided | 2026-09-30 | 2026-09-30 |