Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SaturdayDrive — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting SaturdayDrive. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SaturdayDrive is a web-based platform providing vehicle management and fleet tracking services. Historically, the application has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, as evidenced by its four recorded CVEs. These weaknesses often stem from insufficient input validation and improper access controls. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests ongoing security challenges that could potentially allow unauthorized access to sensitive vehicle data or compromise entire fleet operations if exploited.

CVE ID Title CVSS Severity Published
CVE-2026-92820 Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload — Ninja Forms - File Uploads CWE-434 8.1 High 2026-10-02
CVE-2026-15161 Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter — Ninja Forms - Excel Export CWE-79 6.4 Medium 2026-07-17
CVE-2026-15159 Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter — Ninja Forms - Excel Export CWE-639 4.3 Medium 2026-07-17
CVE-2026-15160 Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal — Ninja Forms - Excel Export CWE-22 4.3 Medium 2026-07-17
CVE-2026-12557 Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints — Ninja Forms - File Uploads CWE-862 5.3 Medium 2026-07-03
CVE-2026-13369 Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter — Ninja Forms - File Uploads CWE-22 7.5 High 2026-07-02
CVE-2026-0740 Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload — Ninja Forms - File Uploads CWE-434 9.8 Critical 2026-04-07
CVE-2024-1596 Ninja Forms File Uploads <= 3.3.16 - Unauthenticated Stored Cross-Site Scripting via File Upload — Ninja Forms - File Uploads CWE-79 7.2 High 2024-09-07
CVE-2022-0888 Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload — Ninja Forms - File Uploads CWE-434 9.8 Critical 2022-03-23
CVE-2022-0889 Ninja Forms - File Uploads Extension <= 3.3.12 - Reflected Cross-Site Scripting — Ninja Forms - File Uploads CWE-79 7.2 High 2022-03-23

This page lists every published CVE security advisory associated with SaturdayDrive. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.