🔓 VULNERABILITIES & CVEs
-
CVE-2026-16219 Path Traversal in Croogo CMS Admin File Manager — CVSS 6.3 A path traversal vulnerability in the FileManager.php component of Croogo CMS Admin File Manager allows attackers to access unauthorized files.
- detail: This flaw could enable attackers to read arbitrary files on the server by manipulating the isEditable parameter.
-
CVE-2026-16220 Cross-Site Scripting in Online Examination System — CVSS 4.3 A cross-site scripting (XSS) vulnerability was discovered in the account.php file of the code-projects Online Examination System.
- detail: This could allow attackers to inject malicious scripts affecting users of the system.
-
CVE-2026-16223 Third Party Edit Endpoint Issue in 1Panel-dev CordysCRM A vulnerability exists in the Third Party Edit Endpoint IntegrationConfigService.java of 1Panel-dev CordysCRM.
- detail: The exact impact and CVSS score are not specified.
-
CVE-2026-16222 Server-Side Request Forgery in 1Panel-dev CordysCRM TokenService.java A server-side request forgery (SSRF) vulnerability was found in the TokenService.java component of 1Panel-dev CordysCRM.
- detail: This flaw could allow attackers to induce the server to make unauthorized requests.