All 5 CVE vulnerabilities found in frogman, with AI-generated Chinese analysis, references, and POCs.
Vendor: mwtcmi
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-46516 | Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments) CWE-79 | - | - | 2026-07-20 |
| CVE-2026-46515 | Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution CWE-862 | - | - | 2026-07-16 |
| CVE-2026-46512 | Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping CWE-94 | 9.9 | Critical | 2026-07-16 |
| CVE-2026-46513 | Frogman: API tokens stored in plaintext CWE-256 | 7.4 | High | 2026-07-16 |
| CVE-2026-46514 | Frogman: Plaintext passwords and secrets persisted to audit log CWE-532 | 6.5 | Medium | 2026-07-16 |
All 5 known CVE vulnerabilities affecting frogman with full Chinese analysis, references, and POCs where available.