Vulnerabilidades em FOSSBilling
38 resultadosAnálise Vexday
FOSSBilling apresenta 27 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente e massiva de falhas. Embora nenhuma esteja sob ataque ativo conhecido, 4 são críticas e a fragilidade dominante (CWE-306: Missing Authentication) aponta para problemas estruturais de controle de acesso que demandam remediação urgente.
CVE-2026-28496CRITICALFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCEEPSS 17.6%CVE-2023-3393HIGHCode Injection in fossbilling/fossbillingEPSS 1.0%CVE-2023-3490CRITICALSQL Injection in fossbilling/fossbillingEPSS 0.9%CVE-2023-3521MEDIUMCross-site Scripting (XSS) - Reflected in fossbilling/fossbillingEPSS 0.9%CVE-2023-3491HIGHUnrestricted Upload of File with Dangerous Type in fossbilling/fossbillingEPSS 0.9%CVE-2026-43920MEDIUMFOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance executionEPSS 0.5%CVE-2023-3493HIGHImproper Neutralization of Formula Elements in a CSV File in fossbilling/fossbillingEPSS 0.5%CVE-2023-3229MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2023-3394MEDIUMSession Fixation in fossbilling/fossbillingEPSS 0.5%CVE-2023-4005LOWInsufficient Session Expiration in fossbilling/fossbillingEPSS 0.5%CVE-2023-3228MEDIUMBusiness Logic Errors in fossbilling/fossbillingEPSS 0.5%CVE-2026-53647MEDIUMFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpointEPSS 0.4%CVE-2026-27604CRITICALFOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin FunctionsEPSS 0.4%CVE-2023-3230MEDIUMMissing Authorization in fossbilling/fossbillingEPSS 0.4%CVE-2023-3227MEDIUMInsufficient Granularity of Access Control in fossbilling/fossbillingEPSS 0.4%CVE-2026-43925MEDIUMFOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code useEPSS 0.3%CVE-2026-33543CRITICALFOSSBilling: Authentication bypass allows unauthenticated administrator creationEPSS 0.3%CVE-2026-53641MEDIUMFOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literalEPSS 0.3%CVE-2026-23513HIGHFOSSBilling: Broken Authorization in Client Transaction and Order ListingsEPSS 0.3%CVE-2026-40495MEDIUMFOSSBilling version exposed via asset cache busterEPSS 0.3%