Vulnerabilities
Summary — last 7 days
New vulnerabilities2,564▼ 301 vs. last week
Critical / high1,351▲ 99 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
9 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.3) | 0.83% | — | Phphtmledit Rich Text Editor | 1/13/2026 | 6/17/2026 | CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal… | |
| Deferred | Medium (6.5) | 0.38% | — | Richtexteditor Rich Text EditorAI | 4/3/2025 | 6/17/2026 | Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Deferred | High (7.1) | 0.14% | — | Richtexteditor Rich Text EditorAI | 3/31/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor richtexteditor allows Stored XSS.This issue affects Rich Text Editor: from n/a through <= 1.0.1. | |
| Modified | Medium (5.4) | 0.61% | — | Summernote Rich Text Editor | 9/18/2023 | 6/17/2026 | Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component. | |
| Modified | Medium (4.3) | 1.3% | — | Webwizguide WEB WIZ Rich Text Editor | 7/30/2008 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modified | Medium (6.4) | 2.6% | — | WEB WIZ Rich Text Editor | 1/29/2008 | 6/16/2026 | RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors. | |
| Modified | Medium (5) | 3.9% | — | WEB WIZ Rich Text Editor | 1/29/2008 | 6/16/2026 | Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action. | |
| Modified | Medium (5) | 4.9% | — | Webwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor | 1/29/2008 | 6/16/2026 | Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a… | |
| Modified | Medium (4.3) | 1.0% | — | Bruce Corkhill WEB WIZ Rich Text Editor | 6/12/2007 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document. |