Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-52608

AI Predicted 9.8 Difficulty: Easy EPSS 0.27% · P19

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
n/an/an/aaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-52608

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2026-52608

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52608

登录查看更多情报信息。

Proof of Concept for CVE-2026-52608 (1)

Vendor Pages for CVE-2026-52608 (1)

Same Patch Batch · n/a · 2026-08-18 · 19 CVEs total

CVE-2024-140466.3 MEDIUMOpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestri
CVE-2024-140456.3 MEDIUMOpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper authorization
CVE-2021-43716EPSON EasyMP Ver.1.20 验证绕过漏洞
CVE-2026-57826openHiTLS 0.2.0-0.3.2证书链验证逻辑漏洞
CVE-2026-71675Open5GS v2.7.0 ngap-path.c拒绝服务漏洞
CVE-2026-71676Open5GS v2.7.0 NAS 5GS解码器缓冲区溢出导致拒绝服务
CVE-2026-52480SJRC F11 GPS-PRO固件敏感信息泄露漏洞
CVE-2026-52481SJRC F11 SJ-GPS-PRO信息泄露漏洞
CVE-2021-43718爱普生EH-TW5350身份验证绕过导致拒绝服务
CVE-2026-52606reportico-web <=8.1.0 反射型XSS漏洞
CVE-2021-43717Epson iProjection v3.2.6 硬编码认证漏洞
CVE-2026-67921Halo CMS<2.25.4 CSRF漏洞致远程代码执行
CVE-2026-67846BOOM v3/v4 NBDTLB权限分配漏洞
CVE-2026-30250ANOW! Automate v.3.3.1.90存在跨站脚本漏洞
CVE-2026-67920Halo 2.25.4远程代码执行漏洞
CVE-2026-52610Reportico Web <=8.1.0 远程任意文件写入漏洞
CVE-2026-52609Reportico-web<=8.1.0反射型XSS漏洞
CVE-2026-52607Reportico-web<=8.1.0目录穿越漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-52608

No comments yet


Leave a comment