CVE-2026-105392High· 7.3▾ TwilightA vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY le…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102241Low· 2.7A vulnerability was determined in Netcore NAP930 0.1.241010.141410
CVE-2026-90510High· 8.3A security vulnerability has been detected in dromara orion-visor up to 2.5.7
CVE-2026-86241Medium· 4.3A weakness has been identified in liufee FeehiCMS up to 2.1.1
CVE-2025-15108Low· 3.7A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5
CVE-2025-15107Low· 3.7A security vulnerability has been detected in actiontech sqle up to 4.2511.0
CVE-2025-15105Low· 3.7A security flaw has been discovered in getmaxun maxun up to 0.0.28