Vulnerabilities in thorsten

118 results
Vexday analysis

Com 115 CVEs catalogadas e 24 surgidas nos últimos 90 dias, o vendor Thorsten apresenta um volume de vulnerabilidades recente que merece atenção contínua. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada no CISA KEV, o que sugere menor pressão imediata de ataques em curso — embora 7 falhas de severidade crítica e 4 com PoC pública representem superfície de ataque concreta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), indicando lacunas persistentes em validação e sanitização de entrada. A CVE mais perigosa no momento, CVE-2022-3766, registra EPSS de 0.0574, valor relativamente contido, mas que deve ser monitorado especialmente em ambientes onde atualizações não são aplicadas de forma sistemática.

CVE-2026-45008HIGHphpMyFAQ - Path Traversal in Client::deleteClientFolder via URL ParameterEPSS 0.3%CVE-2026-32629MEDIUMphpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ EditorEPSS 0.3%CVE-2026-46366HIGHphpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission BypassEPSS 0.3%CVE-2026-46361HIGHphpMyFAQ - Stored Cross-Site Scripting via raw Filter in search.twigEPSS 0.2%CVE-2026-66398CRITICALphpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIEPSS 0.2%CVE-2026-35676HIGHphpMyFAQ - Unauthenticated Password Reset via User Password Update EndpointEPSS 0.2%CVE-2026-34729MEDIUMphpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes()EPSS 0.2%CVE-2025-68951MEDIUMphpMyFAQ has stored XSS in admin "List of users" via display_name HTML entity decoding (html_entity_decode) + Twig |rawEPSS 0.2%CVE-2026-66399HIGHphpMyFAQ before 4.1.6 Privilege Escalation via Group MembershipEPSS 0.2%CVE-2026-45007MEDIUMphpMyFAQ - Missing Permission Check on 12 Configuration API Endpoints Allows Information DisclosureEPSS 0.2%CVE-2026-46367HIGHphpMyFAQ - Stored XSS via Utils::parseUrl() in Comment RenderingEPSS 0.2%CVE-2026-46359HIGHphpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token FieldsEPSS 0.2%CVE-2026-48488LOWphpMyFAQ has Weak Cryptography - SHA1 for Password HashingEPSS 0.2%CVE-2026-46365MEDIUMphpMyFAQ - Missing Authorization in Tag Deletion EndpointEPSS 0.2%CVE-2026-34974MEDIUMphpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege EscalationEPSS 0.2%CVE-2026-45009MEDIUMphpMyFAQ - Insufficient Authorization Check in Admin API EndpointsEPSS 0.2%CVE-2026-46363MEDIUMphpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode BypassEPSS 0.2%CVE-2026-46360MEDIUMphpMyFAQ - Stored XSS via Entity Decoding Depth Limit Bypass in SVG SanitizerEPSS 0.2%