ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-25614
+2 in the same advisory: …25615 …25616
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

NVD description · AI analysis pending
7.5
group max
<1%
  • phillipsdata blesta
CVE-2024-25859
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.

A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.

NVD description · AI analysis pending
7.1<1%
  • phillipsdata blesta