CVE-2026-2088
published 2026-02-07CVE-2026-2088: A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.38%
31.2th percentile
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpgurukul | beauty_parlour_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f56p-8g2x-4rg5: A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1
ghsa_unreviewed·2026-02-07
CVE-2026-2088 [MEDIUM] CWE-74 GHSA-f56p-8g2x-4rg5: A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Red Hat
Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
vendor_redhat·2026-09-02·CVSS 8.8
CVE-2026-84647 [HIGH] CWE-915 Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.
A flaw was found in Stapler, a web framework included in Jenkins. This vulnerability allows an attacker with 'Overall/Read' permission to instantiate objects related to configuration through form data binding. The system does not properly restrict the types of objects that can be
Red Hat
jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
vendor_redhat·2026-09-02·CVSS 8.8
CVE-2026-84649 [HIGH] CWE-201 jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.
A flaw was found in Stapler, a web framework used by Jenkins. An HTTP endpoint that serves dynamically generated JavaScript resources inadvertently embeds a us
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-84649 jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
bugzilla·2026-09-02·CVSS 8.8
CVE-2026-84649 [HIGH] CVE-2026-84649 jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
CVE-2026-84649 jenkins: stapler: Stapler: Cross-site request forgery token disclosure allows session hijacking
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.
Bugzilla
CVE-2026-84647 Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
bugzilla·2026-09-02·CVSS 8.8
CVE-2026-84647 [HIGH] CVE-2026-84647 Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
CVE-2026-84647 Stapler: Jenkins: Stapler: Unintended configuration object instantiation via form data binding
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.
2026-02-07
Published