A vulnerability was found in MacCMS up to 2025.1000.4052. It has been classified as problematic. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass.
The identification of this vulnerability is CVE-2026-4563. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in MacCMS 2025.1000.4052 and classified as critical. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication.
This vulnerability was named CVE-2026-4562. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability identified as problematic has been detected in NaturalIntelligence fast-xml-parser up to 5.5.5. Affected is the function replaceEntitiesValue. Performing a manipulation results in xml entity expansion.
This vulnerability is identified as CVE-2026-33036. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in alexcrichton tar-rs up to 0.4.44. This impacts an unknown function. Performing a manipulation results in type confusion.
This vulnerability is reported as CVE-2026-33055. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability labeled as critical has been found in strukturag libde265 up to 1.0.16. This vulnerability affects the function ctb_info.log2unitSize of the component Image Parser. Such manipulation of the argument PicWidthInCtbsY/PicHeightInCtbsY leads to out-of-bounds write.
This vulnerability is traded as CVE-2026-33165. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.