↓Skip to main content
  1. Posts/

[ RESEARCH ] - CVE overview

·173 words·1 min·
RESEARCH CVE OVERVIEW
Table of Contents

Summary
#

An overview of discovered Common Vulnerabilities and Exposures (CVE), through security research by HEKK.ONE, that are currently available for public disclosure.

2026
#

GITHUB: https://github.com/hekk-one/CVE

Bacularis
#

[+] CVE-2026-95165 - Bacularis 5.4.0 - 6.5.1 is vulnerable to stored Cross Site Scripting (XSS) via the Organization name.

[+] CVE-2026-95166 - Bacularis 1.0.0 - 6.5.1 is vulnerable to stored Cross Site Scripting (XSS) via the Pool LabelFormat field.

[+] CVE-2026-88742 - Bacularis 1.0.0 - 6.5.0 is vulnerable to stored Cross Site Scripting (XSS) via the add client / client address field.

[+] CVE-2026-88743 - Bacularis 4.7.0 - 6.5.0 is vulnerable to stored Cross Site Scripting (XSS) via the director tags.

Silverpeas
#

[+] CVE-2026-78738 - Silverpeas Core 6.4.6 is vulnerable to stored Cross Site Scripting (XSS) via the Document management file upload feature.

[+] CVE-2026-78741 - Silverpeas Core <=6.4.6 is vulnerable to stored Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

[+] CVE-2026-78742 - Silverpeas Core <=6.4.6 is vulnerable to stored Cross Site Scripting (XSS) via the Multimedia library application introduction.

Related

[ RESEARCH ] - CVE-2026-78738 - Stored XSS Silverpeas Core 6.4.6 - File upload feature
·384 words·2 mins
RESEARCH CVE-2026-78738 SILVERPEAS
Stored XSS in Silverpeas Document Management. By modifying the X-FULL-PATH header during file upload with an XSS payload, the payload executes when the file’s preview button is clicked.
[ RESEARCH ] - CVE-2026-78741 - Stored XSS in wysiwyg-CKEditor image upload feature (Silverpeas <= 6.4.6)
·235 words·2 mins
RESEARCH CVE-2026-78741 SILVERPEAS
Stored XSS in Silverpeas’ CKEditor image upload feature allows attackers to replace the filename with a JavaScript payload that executes after the file is uploaded.
[ RESEARCH ] - CVE-2026-78742 - Stored Cross Site Scripting (XSS) in introduction Multimedia library application (Silverpeas Core <=6.4.6)
·343 words·2 mins
RESEARCH CVE-2026-78742 SILVERPEAS
Stored XSS in the Multimedia library introduction allows attackers to inject a JavaScript payload via the editor1 parameter, executing when users visit the application.
OFFSEC - Proving Grounds - FLINK
·1835 words·9 mins
OFFSEC PG PRACTICE APACHE FLINK MSFCONSOLE PACK2THEROOT CVE-2026-41651
Apache Flink 2.0.0 on port 8081 is exploited via Metasploit’s JAR Upload RCE module for initial access. LinPEAS identifies Pack2TheRoot (CVE-2026-41651), enabling privilege escalation to root.
OFFSEC - Proving Grounds - CARRYOVER
·3043 words·15 mins
OFFSEC PG PRACTICE SQLMAP LD_PRELOAD
Carvilla on port 80 is vulnerable to SQL injection, providing initial access via SQLmap. An exposed LD_PRELOAD variable enables a custom shared object to be executed with sudo, escalating privileges to root.
OFFSEC - Proving Grounds - ZAB
·1473 words·7 mins
OFFSEC PG PRACTICE MAGE PACK2THEROOT CVE-2026-41651
Gobuster finds local.txt on port 80. A Mage web app on port 6789 provides browser-based terminal access. The server is vulnerable to Pack2TheRoot (CVE-2026-41651), enabling privilege escalation to root.