Submit #795506: IhateCreatingUserNames2 AiraHub2 3e4b77fd7d48ed811ffe5b8d222068c17c76495e Server-Side Request Forgery [Accepted] Vuldb Submit 1 week 2 days ago Submit #795506 / VDB-359524 Winegee
Submit #795502: Divyanshu-hash GitPilot-MCP 9ed9f153ba4158a2ad230ee4871b25130da29ffd Command Injection [Accepted] Vuldb Submit 1 week 2 days ago Submit #795502 / VDB-359523 BigW
Submit #795416: devlikeapro WAHA 0.0.1 Server-Side Request Forgery [Accepted] Vuldb Submit 1 week 2 days ago Submit #795416 / VDB-359522 BigW
Submit #795348: JizhiCMS JiZhiCMS v2.5.6 SQL injection [Accepted] Vuldb Submit 1 week 2 days ago Submit #795348 / VDB-359521 qingyunsec
Submit #795331: vanna-ai vanna 2.0.2 Unauthorized access to all API endpoints [Accepted] Vuldb Submit 1 week 2 days ago Submit #795331 / VDB-359520 York Shen
Submit #795330: Vanna AI Vanna 2.0.2 Direct SQL Injection via Legacy Flask API in Vanna [Duplicate] Vuldb Submit 1 week 2 days ago Submit #795330 / VDB-351153 York Shen
Submit #795257: Bytedance verl <=0.7.0 Arbitrary Code Execution [Accepted] Vuldb Submit 1 week 4 days ago Submit #795257 / VDB-359040 ZAST.AI
Submit #795212: ericc-ch copilot-api 0.7.0 DNS Rebinding Attack [Accepted] Vuldb Submit 1 week 4 days ago Submit #795212 / VDB-359039 Yu_Bao
Submit #795203: Comfast CF-N1-S V2.6.0.1 Authenticated Command Injection [Accepted] Vuldb Submit 1 week 5 days ago Submit #795203 / VDB-358492 xxyNB
Submit #794798: PublicCMS V6.202506.d Improper Handling of Highly Compressed Data (Data Amplification) [Accepted] Vuldb Submit 1 week 5 days ago Submit #794798 / VDB-358491 LeyNn3H
Submit #794797: PublicCMS V6.202506.d Insertion of Sensitive Information Into Log Code [Accepted] Vuldb Submit 1 week 5 days ago Submit #794797 / VDB-358490 LeyNn3H
Submit #794681: bagisto v2.3.15 Cross Site Scripting [Accepted] Vuldb Submit 1 week 5 days ago Submit #794681 / VDB-358436 hai271120
Submit #794680: bagisto v2.3.15 Server-Side Request Forgery [Accepted] Vuldb Submit 1 week 5 days ago Submit #794680 / VDB-358435 hai271120
Submit #794617: WebSystems WebTOTUM (2026) Cross Site Scripting [Accepted] Vuldb Submit 1 week 5 days ago Submit #794617 / VDB-358434 acme
Submit #794601: ericc-ch copilot-api 0.7.0 Cross-Origin Token Theft via Wildcard CORS & Open Token Endpoint [Accepted] Vuldb Submit 1 week 6 days ago Submit #794601 / VDB-358300 Yu_Bao
Submit #794186: Pagekit CMS framework <= 1.0.18 Remote Code Execution [Accepted] Vuldb Submit 2 weeks ago Submit #794186 / VDB-358286 s4nnty
Submit #793806: Devs Palace ERP Online 4.0.0 Code Injection [Accepted] Vuldb Submit 2 weeks ago Submit #793806 / VDB-358285 acme
Submit #793451: Z-Blog Z-BlogPHP 1.7.5 Upload any file [Accepted] Vuldb Submit 2 weeks ago Submit #793451 / VDB-358284 qingyunsec
Submit #793510: Guangzhou Qibo Network Technology Co., Ltd. Qibo CMS (x1_of_cms) X1.0 SSRF [Accepted] Vuldb Submit 2 weeks ago Submit #793510 / VDB-358283 EthX0_
Submit #793450: Guangzhou Qibo Network Technology Co., Ltd. Qibo CMS (x1_of_cms) X1.0 XSS [Accepted] Vuldb Submit 2 weeks ago Submit #793450 / VDB-358282 EthX0_