Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

eteubert — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting eteubert. AI-powered Chinese analysis, POCs, and references for each vulnerability.

eteubert is a software provider whose core use case involves enterprise application development frameworks. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, accounting for all six CVEs on record. The most critical issues involve improper input validation and insecure default configurations that allow attackers to execute arbitrary code or bypass authentication. No major public security incidents have been documented, though the consistent pattern of similar vulnerability types suggests potential systemic weaknesses in their security development lifecycle. Regular security updates and hardening configurations are recommended for implementations using their frameworks.

CVE ID Title CVSS Severity Published
CVE-2026-75966 Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter — Podlove Podcast Publisher CWE-79 6.4 Medium 2026-09-09
CVE-2026-16099 Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter — Podlove Podcast Publisher CWE-502 8.8 High 2026-08-16
CVE-2026-13001 Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter — Podlove Podcast Publisher CWE-20 9.8 Critical 2026-07-14
CVE-2025-10147 Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload — Podlove Podcast Publisher CWE-434 9.8 Critical 2025-09-23
CVE-2025-1383 Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function — Podlove Podcast Publisher CWE-352 4.3 Medium 2025-03-06
CVE-2025-0554 Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name — Podlove Podcast Publisher CWE-79 4.4 Medium 2025-01-18
CVE-2024-1810 Archivist – Custom Archive Templates <= 1.7.5 - Reflected Cross-Site Scripting — Archivist – Custom Archive Templates CWE-79 6.1 Medium 2024-02-24
CVE-2024-1109 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export — Podlove Podcast Publisher CWE-862 5.3 Medium 2024-02-07
CVE-2024-1110 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import — Podlove Podcast Publisher CWE-862 5.3 Medium 2024-02-07

This page lists every published CVE security advisory associated with eteubert. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.