Vulnerabilities

Summary — last 7 days

New vulnerabilities2,564▼ 301 vs. last week
Critical / high1,351▲ 99 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

9 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.3)0.83%—Phphtmledit Rich Text Editor1/13/20266/17/2026
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal…
DeferredMedium (6.5)0.38%—Richtexteditor Rich Text EditorAI4/3/20256/17/2026
Missing Authorization vulnerability in richtexteditor Rich Text Editor richtexteditor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Text Editor: from n/a through <= 1.0.1.
DeferredHigh (7.1)0.14%—Richtexteditor Rich Text EditorAI3/31/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor richtexteditor allows Stored XSS.This issue affects Rich Text Editor: from n/a through <= 1.0.1.
ModifiedMedium (5.4)0.61%—Summernote Rich Text Editor9/18/20236/17/2026
Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component.
ModifiedMedium (4.3)1.3%—Webwizguide WEB WIZ Rich Text Editor7/30/20086/16/2026
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModifiedMedium (6.4)2.6%—WEB WIZ Rich Text Editor1/29/20086/16/2026
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.
ModifiedMedium (5)3.9%—WEB WIZ Rich Text Editor1/29/20086/16/2026
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.
ModifiedMedium (5)4.9%—Webwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor1/29/20086/16/2026
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a…
ModifiedMedium (4.3)1.0%—Bruce Corkhill WEB WIZ Rich Text Editor6/12/20076/16/2026
Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document.