tag
Backdoor
High
ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167·
ProFTPD (with mod_sql and SQL-backed logging configured)
patched
High
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f·
Kanboard (project management application)
patched
Critical
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p)·
SP Page Builder extension for Joomla (joomshaper.net)
patched