Vulnerabilidades en fossbilling

38 resultados
Análisis Vexday

O FossBilling apresenta 11 vulnerabilidades catalogadas, com 1 classificada como crítica, porém nenhuma encontra-se sob ataque ativo no momento. A fraqueza dominante (CWE-840) sugere problemas estruturais no controle de acesso, sendo o principal vetor de risco. Sem novas vulnerabilidades nos últimos 90 dias, o perfil atual indica risco moderado e estável.

CVE-2026-28496CRITICALFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEEPSS 17.6%CVE-2023-3393HIGHCode Injection in fossbilling/fossbillingEPSS 1.0%CVE-2023-3490CRITICALSQL Injection in fossbilling/fossbillingEPSS 0.9%CVE-2023-3521MEDIUMCross-site Scripting (XSS) - Reflected in fossbilling/fossbillingEPSS 0.9%CVE-2023-3491HIGHUnrestricted Upload of File with Dangerous Type in fossbilling/fossbillingEPSS 0.9%CVE-2026-43920MEDIUMFOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance executionEPSS 0.5%CVE-2023-3493HIGHImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingEPSS 0.5%CVE-2023-3229MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2023-3394MEDIUMSession Fixation in fossbilling/fossbillingEPSS 0.5%CVE-2023-4005LOWInsufficient Session Expiration in fossbilling/fossbillingEPSS 0.5%CVE-2023-3228MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.4%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.4%CVE-2023-3230MEDIUMMissing Authorization in fossbilling/fossbillingEPSS 0.4%CVE-2023-3227MEDIUMInsufficient Granularity of Access Control in fossbilling/fossbillingEPSS 0.4%CVE-2026-43925MEDIUMFOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code useEPSS 0.3%CVE-2026-33543CRITICALFOSSBilling: Authentication bypass allows unauthenticated administrator creationEPSS 0.3%CVE-2026-53641MEDIUMFOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literalEPSS 0.3%CVE-2026-23513HIGHFOSSBilling: Broken Authorization in Client Transaction and Order ListingsEPSS 0.3%CVE-2026-40495MEDIUMFOSSBilling version exposed via asset cache busterEPSS 0.3%