CVE-2026-102630Medium· 4.7▾ SunlitUnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers ca…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101277Medium· 6.5A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0
CVE-2026-102275Medium· 6.5PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-100653Medium· 6.5vLLM is an inference and serving engine for large language models
CVE-2026-80514Medium· 5.3The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to byp…
CVE-2026-97404Critical· 9.2In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header
CVE-2026-92530Medium· 4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request autho…