Known Vulnerabilities for Cpo Content Types by Wpchill
Listed below are 1 of the newest known vulnerabilities associated with "Cpo Content Types" by "Wpchill".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49756 json | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smugg... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-46426 json | Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does no... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-44794 json | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-44587 json | CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_den... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-41234 json | Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sa... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-41230 json | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS rec... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-40487 json | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticat... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-39292 json | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder modu... | Not Provided | 2026-05-29 | 2026-06-01 |
| CVE-2026-35413 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION... | Not Provided | 2026-04-06 | 2026-04-08 |
| CVE-2026-34786 json | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evalu... | Not Provided | 2026-04-02 | 2026-04-03 |