CVE-2026-103592Medium· 6.5▾ Sunlitsimple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-For…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102630Medium· 4.7UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages
CVE-2026-101277Medium· 6.5A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0
CVE-2026-102275Medium· 6.5PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-100653Medium· 6.5vLLM is an inference and serving engine for large language models
CVE-2026-80514Medium· 5.3The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to byp…
CVE-2026-97404Critical· 9.2In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header