Daily High-Risk Vuln Digest 2026-09-26 (3)

Daily High-Risk Vulnerability Digest · 2026-09-26

3 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-100717 — 9.9 — froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and …
  • CVE-2026-92161 — 9.8 — FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OA…
  • CVE-2026-18143 — 9.8 — The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the afrfq_submit_quote_via_popup() function. This is due to missing file e…

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.