ZeroHour

CVE-2026-30404

PoC
CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
Description

The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations.

Vendors
wgstart
Products
wgcloud
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.