Skip to content

Commit 7eeb7fa

Browse files
Sync EUVD catalog: Thu May 28 00:49:20 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 93fad79 commit 7eeb7fa

707 files changed

Lines changed: 59447 additions & 56 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/04/EUVD-2026-23459.json

Lines changed: 19 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,36 @@
11
{
22
"id": "EUVD-2026-23459",
33
"enisaUuid": "b31c4eaf-e8d1-30f6-a6d7-a116b25164f1",
4-
"description": "The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.6. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, which can be leveraged to achieve remote code execution.",
5-
"datePublished": "Apr 17, 2026, 6:31:54 PM",
6-
"dateUpdated": "Apr 17, 2026, 6:31:54 PM",
4+
"description": "The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, which can be leveraged to achieve remote code execution. The vulnerability was originally reported by Leonid Semenenko (lsemenenko) and partially patched in version 1.3.9.7. A bypass for the patch was separately discovered and reported by Nguyen Hung (Mitchell).",
5+
"datePublished": "Apr 17, 2026, 5:25:55 PM",
6+
"dateUpdated": "May 27, 2026, 12:26:11 AM",
77
"baseScore": 8.1,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
10-
"references": "https://www.wordfence.com/threat-intel/vulnerabilities/id/38f95d40-a6d4-429c-9872-9d2531e942eb?source=cve\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L987\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L883\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L970\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L62\nhttps://plugins.trac.wordpress.org/changeset/3508522/drag-and-drop-multiple-file-upload-contact-form-7\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5718\n",
10+
"references": "https://www.wordfence.com/threat-intel/vulnerabilities/id/38f95d40-a6d4-429c-9872-9d2531e942eb?source=cve\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L987\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L883\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L970\nhttps://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/tags/1.3.9.6/inc/dnd-upload-cf7.php#L62\nhttps://plugins.trac.wordpress.org/changeset/3508522/drag-and-drop-multiple-file-upload-contact-form-7\nhttps://plugins.trac.wordpress.org/changeset/3548901/\n",
1111
"aliases": "GHSA-xj7v-jqv6-v48w\nCVE-2026-5718\n",
1212
"assigner": "Wordfence",
13-
"epss": 0.0,
13+
"epss": 3.17,
1414
"enisaIdProduct": [
1515
{
1616
"id": "18b84eac-3653-3749-854b-b59d15dfb3d9",
1717
"product": {
18-
"name": "Drag and Drop Multiple File Upload for Contact Form 7"
18+
"name": "Drag and Drop Multiple File Upload for Contact Form 7",
19+
"vendor": {
20+
"name": "glenwpcoder"
21+
}
1922
},
2023
"product_version": "0 \u22641.3.9.6"
24+
},
25+
{
26+
"id": "85f979f3-2b7f-3667-a789-74c9667d7c6e",
27+
"product": {
28+
"name": "Drag and Drop Multiple File Upload for Contact Form 7",
29+
"vendor": {
30+
"name": "glenwpcoder"
31+
}
32+
},
33+
"product_version": "0 \u22641.3.9.7"
2134
}
2235
],
2336
"enisaIdVendor": [
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2022-55994",
3+
"enisaUuid": "ff79680f-1cb7-3a7d-bb0d-36a0f93b297f",
4+
"description": "Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Account Manager for WooCommerce: from n/a through 2.1.2.",
5+
"datePublished": "May 27, 2026, 3:30:21 PM",
6+
"dateUpdated": "May 27, 2026, 5:31:30 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
10+
"references": "https://patchstack.com/database/wordpress/plugin/account-manager-woocommerce/vulnerability/wordpress-account-manager-for-woocommerce-plugin-2-0-19-broken-access-control-vulnerability?_s_id=cve\n",
11+
"aliases": "GHSA-cr7m-pmfg-ggh9\nCVE-2022-41656\n",
12+
"assigner": "Patchstack",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "29c85982-000c-3f14-a3f9-3fa7650c3511",
17+
"product": {
18+
"name": "Account Manager for WooCommerce",
19+
"vendor": {
20+
"name": "bizswoop"
21+
}
22+
},
23+
"product_version": "n/a \u22642.1.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "1350d077-da7f-3f48-90c1-730d9d31e8fb",
29+
"vendor": {
30+
"name": "bizswoop"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2023-60578",
3+
"enisaUuid": "a5033698-5572-38e4-9448-2a5f70f2023a",
4+
"description": "Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:25:46 AM",
6+
"dateUpdated": "May 27, 2026, 1:41:23 PM",
7+
"baseScore": 7.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_26\n",
11+
"aliases": "GHSA-54vp-8h7p-wfm9\nCVE-2023-52945\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "6c54e507-e8a6-3b38-b057-dc0bd880da14",
17+
"product": {
18+
"name": "BeeDrive for desktop",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <1.3.2-13814"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "201ef171-1ef0-3aed-a21a-9b67d9c8b462",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55592",
3+
"enisaUuid": "0a17cfa0-5c2f-388b-85f9-db533317ab62",
4+
"description": "Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:26:49 AM",
6+
"dateUpdated": "May 27, 2026, 1:41:45 PM",
7+
"baseScore": 6.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_26\n",
11+
"aliases": "CVE-2024-11399\nGHSA-c435-j2qv-j972\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "412f124b-73e2-35e8-934e-571ad7253c81",
17+
"product": {
18+
"name": "BeeDrive for desktop",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <1.3.2-13814"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "87f94393-e85e-3307-afdd-1702cc01ed5a",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
}
33+
]
34+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2024-55593",
3+
"enisaUuid": "941979dd-ff0f-3f27-8039-80e7ea7b391e",
4+
"description": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:29:16 AM",
6+
"dateUpdated": "May 27, 2026, 1:42:06 PM",
7+
"baseScore": 2.7,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_25\n",
11+
"aliases": "GHSA-xgcm-wj22-xmcf\nCVE-2024-47267\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7768b015-e78a-3b21-b7d3-0c35e5b46cea",
17+
"product": {
18+
"name": "Surveillance Station",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <9.2.2-11575"
24+
},
25+
{
26+
"id": "df42eb2b-b0d5-30fd-aa68-76551923e90b",
27+
"product": {
28+
"name": "Surveillance Station",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
},
33+
"product_version": "* <9.2.2-9575"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "3beffe5f-143c-38a4-bfe2-47b64d8e51f7",
39+
"vendor": {
40+
"name": "Synology"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2024-55594",
3+
"enisaUuid": "bd5398d3-529f-337d-86ae-29b93a91fa99",
4+
"description": "Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:29:31 AM",
6+
"dateUpdated": "May 27, 2026, 1:42:28 PM",
7+
"baseScore": 4.9,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_25\n",
11+
"aliases": "GHSA-2w9f-2xp2-w98x\nCVE-2024-47268\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7a2028f6-3a95-33dd-98d9-990a48be037c",
17+
"product": {
18+
"name": "Surveillance Station",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <9.2.2-9575"
24+
},
25+
{
26+
"id": "95843cd9-0063-377c-8524-d292d0eb0cc9",
27+
"product": {
28+
"name": "Surveillance Station",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
},
33+
"product_version": "* <9.2.2-11575"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "bab10115-d1b8-3bad-bbff-b8c65fdc1483",
39+
"vendor": {
40+
"name": "Synology"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2024-55595",
3+
"enisaUuid": "387d3f7a-92ec-3765-b836-f41e16b4b306",
4+
"description": "Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:29:47 AM",
6+
"dateUpdated": "May 27, 2026, 1:43:20 PM",
7+
"baseScore": 4.9,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_25\n",
11+
"aliases": "GHSA-h2xx-8rq3-g9g2\nCVE-2024-47269\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "6649c076-f43a-3861-8671-3c0abf076c79",
17+
"product": {
18+
"name": "Surveillance Station",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <9.2.2-11575"
24+
},
25+
{
26+
"id": "6c1174e1-8e44-33c0-8402-0f22ee53e75d",
27+
"product": {
28+
"name": "Surveillance Station",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
},
33+
"product_version": "* <9.2.2-9575"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "fe105b32-7e6e-3abe-8919-4a57c530118e",
39+
"vendor": {
40+
"name": "Synology"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2024-55596",
3+
"enisaUuid": "0e7363a6-22bf-3882-a8a3-99980ff0cf8a",
4+
"description": "Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:29:56 AM",
6+
"dateUpdated": "May 27, 2026, 1:45:55 PM",
7+
"baseScore": 2.7,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_25\n",
11+
"aliases": "GHSA-cfcq-c7c3-chpj\nCVE-2024-47270\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "6c2c1f7a-9c3e-3a2e-a963-386ee7b387d3",
17+
"product": {
18+
"name": "Surveillance Station",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <9.2.2-9575"
24+
},
25+
{
26+
"id": "b5210403-4597-38e4-a46c-e4756e45e1c8",
27+
"product": {
28+
"name": "Surveillance Station",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
},
33+
"product_version": "* <9.2.2-11575"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "f204d917-cdaf-3160-80f5-4aa782d6b7ab",
39+
"vendor": {
40+
"name": "Synology"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2024-55597",
3+
"enisaUuid": "5018008d-79e2-3239-b3ee-86f8ac6f72a0",
4+
"description": "Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.",
5+
"datePublished": "May 27, 2026, 8:30:12 AM",
6+
"dateUpdated": "May 27, 2026, 1:45:13 PM",
7+
"baseScore": 4.9,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
10+
"references": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_25\n",
11+
"aliases": "GHSA-29jv-pqcq-m927\nCVE-2024-47271\n",
12+
"assigner": "synology",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "07e97f3f-570a-3565-96af-66639f3fbbcc",
17+
"product": {
18+
"name": "Surveillance Station",
19+
"vendor": {
20+
"name": "Synology"
21+
}
22+
},
23+
"product_version": "* <9.2.2-11575"
24+
},
25+
{
26+
"id": "8722cca4-8eb6-3ea2-ad2b-d60951378ee3",
27+
"product": {
28+
"name": "Surveillance Station",
29+
"vendor": {
30+
"name": "Synology"
31+
}
32+
},
33+
"product_version": "* <9.2.2-9575"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "dfc7e1cc-004a-3ac9-882a-0f1c71e2011b",
39+
"vendor": {
40+
"name": "Synology"
41+
}
42+
}
43+
]
44+
}

0 commit comments

Comments
 (0)