Daily High-Risk Vuln Digest 2026-09-26 (3)
Daily High-Risk Vulnerability Digest · 2026-09-26
3 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-100717 —
9.9— froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and … - CVE-2026-92161 —
9.8— FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OA… - CVE-2026-18143 —
9.8— The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via theafrfq_submit_quote_via_popup()function. This is due to missing file e…
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.