Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RansomLook — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in RansomLook, with AI-generated Chinese analysis, references, and POCs.

Vendor: RansomLook

CVE ID Title CVSS Severity Published
CVE-2026-78555 RansomLook API Key Disclosure Through /admin/apikeys HTML Source CWE-522 9.4 Critical 2026-08-24
CVE-2026-78553 Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in RansomLook CWE-276 7.0 High 2026-08-24
CVE-2026-78551 RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication Attempts CWE-307 8.8 High 2026-08-24
CVE-2026-78391 Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook CWE-79 8.8 High 2026-08-24
CVE-2026-78387 RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification CWE-862 9.4 Critical 2026-08-24
CVE-2026-78386 Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook API CWE-200 8.7 High 2026-08-24
CVE-2026-78385 RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File Access CWE-918 8.2 High 2026-08-24
CVE-2026-78381 RansomLook Arbitrary File Read via Path Traversal in Post screen Field CWE-22 8.2 High 2026-08-24
CVE-2026-78380 Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLook CWE-862 8.7 High 2026-08-24
CVE-2026-78378 Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data CWE-200 6.9 Medium 2026-08-24
CVE-2026-78372 RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data CWE-862 9.2 Critical 2026-08-24
CVE-2026-78370 RansomLook Unauthenticated Database Export Exposes Private Data CWE-862 9.2 Critical 2026-08-24
CVE-2026-78369 Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook CWE-306 8.8 High 2026-08-24
CVE-2026-40584 RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information Exposure CWE-200 5.3AI Medium AI 2026-04-21

All 14 known CVE vulnerabilities affecting RansomLook with full Chinese analysis, references, and POCs where available.