Vulnerabilities

Summary — last 7 days

New vulnerabilities2,740▼ 482 vs. last week
Critical / high1,306▼ 184 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)226▼ 276 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.3)0.35%—Yetanotherforum Yaf.netAI5/12/20266/17/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This…
DeferredHigh (8.1)0.38%—Yetanotherforum.netAI5/12/20266/17/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header into a JObject, serializes it with JsonConvert, and stores the result in the EventLog.Description column whenever an event…
DeferredHigh (8.8)0.64%—Yetanotherforum Yaf.netAI5/12/20266/17/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSql, whose OnPostRunQuery binds Editor from the POST body and passes it straight to…
ModifiedMedium (5.4)0.67%—Yetanotherforum Yaf.net2/2/20236/17/2026
A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to…
ModifiedMedium (5.4)0.69%—Yetanotherforum Yaf.net1/27/20236/17/2026
A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subject/message leads to cross site scripting. The attack may be…
ModifiedMedium (4.3)2.7%💥 ExploitDatemill Etano9/6/20126/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12)…
Orbitaley — Vulnerabilities