L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
Storm9 menções
krybit9 menções
thegentlemen9 menções
akira7 menções
Booba Project6 menções
incransom6 menções
qilin5 menções
rhysida5 menções
Wallstreet3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
thegentlemenCenter State EngineeringUS · Manufacturing · 2026-10-04
qilinGenesis Credit ManagementUS · Financial Services · 2026-10-03
netrunnerPrecon Marine Inc— · Transportation · 2026-10-03
rhysidaSkaff Group— · Other · 2026-10-03
WallstreetSt. Francis Healthcare Systems of HawaiiUS · Healthcare · 2026-10-03
WallstreetWorld Cup 2034SA · Other · 2026-10-03
akiraThe Official Collegeof Architects of León (COAL)MX · Professional Services · 2026-10-03
Spiralsseven seas groupAE · Transportation · 2026-10-03
qilinThai Lion AirTH · Transportation · 2026-10-02
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-94174HIGH

Administrator SQL Injection in Email Log <= 2.63 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.29%
CVE-2026-94168MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94124HIGH

Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.22%
CVE-2026-94118MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94080MEDIUM

Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-94079MEDIUM

Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-93774HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.19%
CVE-2026-93773HIGH

Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.22%
CVE-2026-93772MEDIUM

Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.22%
CVE-2026-93623MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.23%
CVE-2026-93622HIGH

Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-93620MEDIUM

Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.19%
CVE-2026-93618MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.16%
CVE-2026-93529MEDIUM

Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.21%
CVE-2026-93527HIGH

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.21%
CVE-2026-93526HIGH

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-93513MEDIUM

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.18%
CVE-2026-93421MEDIUM

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py, which prints them to standard output without neutralizing terminal control sequences. When an operator views the resulting logs in an ANSI-capable terminal, injected ANSI or VT100 sequences can clear or reposition the display, hide text, or present forged messages, reducing the integrity of monitoring and incident-response output. This issue is fixed in version 1.3.4.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.40%
CVE-2026-92730HIGH

LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.39%
CVE-2026-92700MEDIUM

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case variants can bypass hide rules on case-insensitive filesystems or when mixed-case paths coexist and expose files intended to be hidden.

AFFECTED SURFACEProduct not specified
CVSS 6.3EPSS 0.41%
CVE-2026-92692MEDIUM

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.33%
CVE-2026-92284MEDIUM

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body reads the complete request body with an unbounded io.Copy before request-body middleware limits apply, allowing memory exhaustion and process termination.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.39%
CVE-2026-90905HIGH

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core Joomla mail configuration (fromname, mailfrom) in configuration.php without verifying anti-CSRF tokens or checking for administrative permissions (canAdmin). A malicious site could silently modify the site's sender name and email address via forged requests from an admin's browser. Resolved by enforcing Session::checkToken('request') / Session::checkToken('post') and adding explicit administrative authorization verification via AccessControl::create()->canAdmin().

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.26%
CVE-2026-90904HIGH

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-level and asset-level ACL permission checks. Any authenticated backend user could edit any EasyStore record, regardless of specific ACL permission grants. Resolved by replacing the hardcoded boolean with proper ACL authorization checks via AccessControl::create()->canEdit()`.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 0.31%