Known Vulnerabilities for Frontend by Otrs
Listed below are 10 of the newest known vulnerabilities associated with "Frontend" by "Otrs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66338 json | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that sil... | Not Provided | 2026-07-24 | 2026-07-27 |
| CVE-2026-63264 json | Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerabl... | Not Provided | 2026-07-22 | 2026-07-23 |
| CVE-2026-62414 json | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK do... | Not Provided | 2026-07-20 | 2026-07-23 |
| CVE-2026-62391 json | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend pro... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-62236 json | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret f... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-60027 json | The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticat... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-60025 json | The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-59102 json | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arb... | Not Provided | 2026-07-02 | 2026-07-06 |
| CVE-2026-58652 json | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-ap... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-57334 json | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | Not Provided | 2026-06-29 | 2026-06-29 |