A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | chatwoot | 4.17.0 |
cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92380 | 7.3 HIGH | WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery |
| CVE-2026-92399 | 7.3 HIGH | GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow |
| CVE-2026-92417 | 6.5 MEDIUM | Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference |
| CVE-2026-92475 | 5.3 MEDIUM | GPAC downloader.c wait_for_header_and_parse out-of-bounds |
| CVE-2026-92416 | 4.3 MEDIUM | Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request asse |
| CVE-2026-92383 | 4.3 MEDIUM | PbootCMS User Management UserController.php mod cross-site request forgery |
| CVE-2026-92381 | 3.5 LOW | PbootCMS Template Rendering ContentController.php decode_string cross site scripting |
| CVE-2026-92474 | 3.3 LOW | GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free |
| CVE-2026-92472 | 3.3 LOW | GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free |
| CVE-2026-92473 | 3.3 LOW | GPAC BIFS commands.c gf_sg_command_del use after free |
| CVE-2026-51990 | 搜狗输入法16.3.0.3498前任意代码执行漏洞 | |
| CVE-2026-88593 | CVE-2026-88593 | |
| CVE-2026-38999 | CVE-2026-38999 | |
| CVE-2026-79298 | Howyar SysReturn 11.3.034前任意代码执行漏洞 | |
| CVE-2026-88592 | CVE-2026-88592 | |
| CVE-2025-56563 | CVE-2025-56563 | |
| CVE-2025-56566 | CVE-2025-56566 | |
| CVE-2025-56565 | CVE-2025-56565 |
No comments yet