CVE-2026-108570Medium· 6.3▾ SunlitA security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argumen…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argument content results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14731Medium· 6.3A weakness has been identified in CTCMS Content Management System up to 2.1.2
CVE-2026-103540Medium· 6.3A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1
CVE-2026-102771Medium· 4.7A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7
CVE-2026-75979Medium· 6.3A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta
CVE-2026-19929Medium· 6.3A vulnerability was identified in OpenBoxes up to 0.9.6
CVE-2026-108264Critical· 9.1Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers