Known Vulnerabilities for User Import by User Import Project
Listed below are 1 of the newest known vulnerabilities associated with "User Import" by "User Import Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61835 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Dire... | Not Provided | 2026-07-15 | 2026-07-21 |
| CVE-2026-60125 json | MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enfor... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-60124 json | An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with e... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-59236 json | Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductI... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-59095 json | LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to ... | Not Provided | 2026-07-02 | 2026-07-14 |
| CVE-2026-58174 json | Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the... | Not Provided | 2026-06-30 | 2026-07-14 |
| CVE-2026-57940 json | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function ge... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-56422 json | Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) an... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-55477 json | 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the dat... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-55475 json | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import ca... | Not Provided | 2026-07-10 | 2026-07-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | User Import Project | User Import | 6.x-4.x | |||
| Application | User Import Project | User Import | 6.x-4.3 | |||
| Application | User Import Project | User Import | 6.x-4.2 | |||
| Application | User Import Project | User Import | 6.x-4.1 | |||
| Application | User Import Project | User Import | 6.x-4.0 |