All 5 CVE vulnerabilities found in faction, with AI-generated Chinese analysis, references, and POCs.
Vendor: factionsecurity
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44668 | Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates CWE-306 | 9.8 | Critical | 2026-05-26 |
| CVE-2026-44669 | Faction: Stored XSS in Assessment Attachment Filename Preview Rendering CWE-79 | 8.7 | High | 2026-05-26 |
| CVE-2026-44667 | Faction: Stored XSS in Remediation Verification Attachment Filename Preview Rendering CWE-79 | 8.7 | High | 2026-05-26 |
| CVE-2025-66022 | FACTION Unauthenticated Custom Extension Upload leads to RCE CWE-829 | 9.7 | Critical | 2025-11-26 |
| CVE-2025-27422 | FACTION Allows Authentication Bypass via User Creation CWE-287 | 7.5 | High | 2025-03-03 |
All 5 known CVE vulnerabilities affecting faction with full Chinese analysis, references, and POCs where available.