skeletonsec
vulnerability research · exploit development · reverse engineering
Independent vulnerability research blog — writeups, research, and open tools. Nothing here yet; it ships when there’s evidence to show.
cve & advisories
- CVE-2026-86197 Grav — stored XSS via the Twig sandbox's assets.addJs/addCss allowlist; page-editor to super-admin escalation, fixed in 2.0.20 nvd · vulncheck · ghsa
- CVE-2026-85586 phpMyFAQ — CAPTCHA bypass via store=now parameter: unauthenticated unlimited question submission, database pollution and mail flood nvd · vulncheck
- CVE-2026-85587 phpMyFAQ — incorrect authorization on admin content pages: lesser-privileged editors read draft and inactive content nvd · vulncheck
- CVE-2026-85588 phpMyFAQ — TOTP shared secrets exported in plaintext in user data-export ZIPs, enabling 2FA bypass nvd · vulncheck
- CVE-2026-85589 phpMyFAQ — missing authorization on dashboard API endpoints (searches, content-health): any authenticated user reads site-wide statistics nvd · vulncheck
- CVE-2026-85590 phpMyFAQ — two-factor authentication disabled without password re-entry or current TOTP code nvd · vulncheck
- CVE-2026-85591 phpMyFAQ — password change without current-password verification via the user API, enabling account takeover including administrators nvd · vulncheck
- CVE-2026-84481 WWBN AVideo — unauthenticated information disclosure in the MobileManager getConfiguration endpoint (TLS key paths, socket config, debug flags) nvd · vulncheck
- CVE-2026-82238 File Browser — race condition in the TUS upload handler: concurrent PATCH requests bypass Upload-Length validation nvd · vulncheck
- CVE-2026-82237 File Browser — share links survive file rename and later serve unrelated content without authentication nvd · vulncheck
- CVE-2026-82236 File Browser — public share links are not cleaned up on privileged deletion, exposing replacement content nvd · vulncheck
- CVE-2026-82235 File Browser — named pipes in archive and public download handlers trigger blocking opens, pinning server goroutines nvd · vulncheck
- CVE-2026-81733 WWBN AVideo — cross-site request forgery in the Live plugin endpoint myLiveControls.save.json.php nvd · vulncheck
- CVE-2026-81732 WWBN AVideo — missing authentication on report4.json.php endpoints exposes user-registration statistics nvd · vulncheck
latest
- CVE-2026-86197 cve