github projectdiscovery/nuclei-templates v10.4.9
Nuclei Templates v10.4.9 - Release Notes

8 hours ago

New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15

🔥 Release Highlights 🔥

What's Changed

Bug Fixes

False Negatives

  • CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185).
  • CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235).
  • CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236).
  • CVE-2024-52433 — the My Geo Posts Free template could never match a genuine install (PR #16971).
  • CVE-2026-72898 — Metabase instances serving localised responses are now detected (PR #17159, Issue #17046).

False Positives

  • CVE-2025-29927 — no longer fires on benign Next.js i18n and locale middleware redirects (PR #17043, Issue #17019).
  • hp-printer-default-login — stopped treating any HTTP 200 response as a successful login (PR #17032).
  • CVE-2026-33017 — tightened the request limits on the Langflow RCE template to stop spurious matches (PR #17165, Issue #17151).

Enhancements

  • Reclassified vuln and discovery tags across 100 templates, including misclassified discovery tags on exposure and misconfiguration templates (PR #15122).
  • Rewrote the AI/ML exposure templates to use raw requests, DSL matchers and proper metadata, dropping the redundant Ray, Qdrant and ChromaDB variants (PR #17234).
  • Shortened verbose descriptions across four newly added panel and API exposure templates (PR #17030, from PR #17027).
  • Refined the login placeholders in empirec2-default-login.yaml (PR #16940).

Templates Added

  • [CVE-2026-88062] OmniRoute < 3.8.49 - Unauthenticated RCE (@0x_Akoko) [critical]
  • [CVE-2026-87820] CyberPanel 2.4.3-2.4.5 - AI Scanner Debug Disclosure (@0x_Akoko) [medium]
  • [CVE-2026-86426] LibreNMS <= 26.7.0 - Unauthenticated API Access (@0x_Akoko) [critical]
  • [CVE-2026-86207] N-able N-central - Authentication Bypass (@rapid7, @dhiyaneshdk) [critical] (vKEV) 🔥
  • [CVE-2026-86206] N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header Spoofing (@rapid7, @dhiyaneshdk) [critical] (vKEV)
  • [CVE-2026-85706] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read (@flx) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-85200] GEO my WP <=4.5.5.3 - Unauthenticated Local File Inclusion (@0x_Akoko) [high]
  • [CVE-2026-83548] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB (@rapid7, @dhiyaneshdk) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-82329] JFrog Artifactory Access Blank Join Key Authentication Bypass (@johnk3r, @pruva) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-82222] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam) [critical] (vKEV) 🔥
  • [CVE-2026-81578] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct (@darses, @dhiyaneshdk) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-81199] MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure (@0x_Akoko) [medium]
  • [CVE-2026-77806] SPIP < 4.4.22 - Unauthenticated RCE (@0x_Akoko) [critical] (vKEV)
  • [CVE-2026-73570] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha) [high] (kev) (vKEV) 🔥
  • [CVE-2026-73034] DB-GPT <= 0.8.1 - Arbitrary File Write (@iacker) [critical]
  • [CVE-2026-65761] Joomla Easy Store - SQL Injection (@yeswehack) [critical]
  • [CVE-2026-62382] PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass (@dhiyaneshdk) [medium]
  • [CVE-2026-61736] LightRAG <= 1.5.3 - Credentialed CORS Wildcard (@str4k3r) [high]
  • [CVE-2026-60105] Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass (@Chocapikk, @dhiyaneshdk) [high] (vKEV)
  • [CVE-2026-59726] ruflo MCP Bridge - Unauthenticated RCE via terminal_execute (@dhiyaneshdk) [critical]
  • [CVE-2026-59509] cve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection (@str4k3r) [critical]
  • [CVE-2026-59177] ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard Access (@str4k3r) [high]
  • [CVE-2026-58191] Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting (@str4k3r) [medium]
  • [CVE-2026-58123] Hermes WebUI < 0.51.788 - Remote Code Execution (@str4k3r) [critical]
  • [CVE-2026-57582] GeoNetwork - Reflected Cross-Site Scripting (@dhiyaneshdk) [high]
  • [CVE-2026-56292] AcyMailing < 10.11.1 - Unauthenticated SQL Injection (@str4k3r) [critical]
  • [CVE-2026-55229] Gotenberg < 8.34.0 - Local File Disclosure (@str4k3r) [high]
  • [CVE-2026-55040] Microsoft SharePoint Server - JWT Authentication Bypass (@sfewer-r7, @dhiyaneshdk) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-53595] FreeScout < 1.8.224 - Invite Hash Authorization Bypass (@str4k3r) [critical]
  • [CVE-2026-48558] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-44343] WGDashboard < 4.3.2 - Unauthenticated File Read (@str4k3r) [critical]
  • [CVE-2026-44177] Kirby CMS 5.3.0-5.4.0 - Path Traversal (@str4k3r) [high]
  • [CVE-2026-42878] FacturaScripts - Unauthenticated phpinfo Disclosure (@ChrisJr404) [medium]
  • [CVE-2026-42596] Gotenberg < 8.31.0 - Server-Side Request Forgery (@str4k3r) [critical]
  • [CVE-2026-42221] Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure (@str4k3r) [high]
  • [CVE-2026-41948] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal (@dhiyaneshdk) [critical] (vKEV) 🔥
  • [CVE-2026-41679] Paperclip - Remote Code Execution (@theamanrawat, @pdteam) [critical] (vKEV)
  • [CVE-2026-41456] Bludit CMS <= 3.20.0 - Cross-Site Scripting (@0x_Akoko) [medium]
  • [CVE-2026-41452] Krayin CRM < 2.2.1 - Installer Authentication Bypass (@str4k3r) [critical]
  • [CVE-2026-34234] CtrlPanel <= 1.1.1 - Remote Code Execution (@ritikchaddha) [critical] (vKEV)
  • [CVE-2026-32475] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler (@pdteam) [critical] (vKEV) 🔥
  • [CVE-2026-30849] MantisBT < 2.28.1 - SOAP API Authentication Bypass (@str4k3r) [critical]
  • [CVE-2026-29963] HSC MailInspector - Unauthenticated Arbitrary File Read (@str4k3r) [high]
  • [CVE-2026-29962] HSC MailInspector - Local File Inclusion (@str4k3r) [high]
  • [CVE-2026-28411] WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract() (@str4k3r, @0x_Akoko) [critical]
  • [CVE-2026-28141] NextGEN Gallery <= 4.2.3 - Reflected Cross-Site Scripting (@str4k3r) [high]
  • [CVE-2026-27960] OpenCTI < 6.9.13 - Authentication Bypass via User Impersonation (@dhiyaneshdk) [critical]
  • [CVE-2026-27454] Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass (@str4k3r) [medium]
  • [CVE-2026-26265] Discourse - Private User Field Disclosure via Directory Items IDOR (@str4k3r) [high]
  • [CVE-2026-23693] ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy (@rahulreddykarne) [high]
  • [CVE-2026-23536] Feast Feature Server <=0.58.0 - Arbitrary File Read (@str4k3r) [high] (vKEV)
  • [CVE-2026-23491] InvoicePlane <= 1.6.3 - Arbitrary File Read (@str4k3r) [high]
  • [CVE-2026-21875] ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL Injection (@str4k3r, @0x_Akoko) [critical]
  • [CVE-2026-19632] TranslatePress <= 3.3.1 - Unauthenticated Account Takeover (@0xgh057r3c0n) [critical] (vKEV)
  • [CVE-2026-19092] Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function Invocation (@Aryu-RU) [critical]
  • [CVE-2026-18963] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass (@dhiyaneshdk) [critical] (vKEV) 🔥
  • [CVE-2026-18577] N-able N-central < 2026.3.1.10 - Authentication Bypass (@patrick-threatmate) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-12898] All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write (@iamatownboy) [medium]
  • [CVE-2026-11801] WPAdverts <= 2.3.2 - Information Disclosure (@0x_Akoko) [high]
  • [CVE-2026-9586] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection (@dhiyaneshdk) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-9133] Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read (@ye11oc4t) [high]
  • [CVE-2026-8467] Phoenix Storybook - Remote Code Execution (@0x_Akoko) [critical]
  • [CVE-2026-7467] Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation (@zer0p0int) [high]
  • [CVE-2026-5562] Provectus kafka-ui <=0.7.2 - Remote Code Execution (@christianfl, @0xNayel) [critical]
  • [CVE-2026-5524] Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCE (@dhiyaneshdk) [critical] (vKEV)
  • [CVE-2026-2113] tpadmin <= 1.3.12 - Remote Code Execution (@jankesec) [critical]
  • [CVE-2026-1281] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection (@rxerium) [critical] (kev) (vKEV) 🔥
  • [CVE-2026-0768] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code (@dhiyaneshdk) [critical] (vKEV) 🔥
  • [CVE-2026-0743] WP Content Permission <= 1.2 - Cross-Site Scripting (@iamatownboy) [medium]
  • [CVE-2026-0702] VidShop for WooCommerce <= 1.1.4 - SQL Injection (@str4k3r) [high]
  • [CVE-2026-0650] OpenFlagr <= 1.1.18 - Authentication Bypass (@str4k3r) [critical]
  • [CVE-2026-0561] Shield Security <= 21.0.8 - Unauthenticated Reflected XSS (@str4k3r) [medium]
  • [CVE-2025-57231] Docmost 0.2.1-0.21.0 - Arbitrary File Read (@anirbala98) [high]
  • [CVE-2025-53887] Directus < 11.9.0 - Version Disclosure (@ChrisJr404) [medium]
  • [CVE-2025-51683] mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCE (@0x_Akoko, @pdteam) [critical] (vKEV)
  • [CVE-2025-15403] RegistrationMagic <= 6.0.7.1 - Privilege Escalation (@0x_Akoko, @pdresearch) [critical] (vKEV)
  • [CVE-2025-14998] Branda WordPress plugin - Privilege Escalation (@theamanrawat) [critical] (vKEV)
  • [CVE-2024-1708] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal (@Popy21) [high] (kev) (vKEV) 🔥
  • [CVE-2023-54391] Proxmox VE - Default Credentials with TFA Bypass (@dhiyaneshdk, @0x_Akoko) [critical] (vKEV) 🔥
  • [CVE-2022-39258] Mailcow Dockerized Swagger UI - Cross-Site Scripting (@ritikchaddha) [medium]
  • [CVE-2020-29134] TOTVS Fluig <= 1.7.0 - Arbitrary File Read (@Ls4ss) [high]
  • [CVE-2020-10221] rConfig <= 3.9.4 - Authenticated OS Command Injection (@Jayachandran from Securin Labs (https://securin.io)) [high] (kev) (vKEV) 🔥
  • [CVE-2019-11043] PHP-FPM Path Info Buffer Underflow - Remote Code Execution (@prasath from Securin Labs (https://securin.io)) [critical] (kev) (vKEV) 🔥
  • [CVE-2017-8225] GoAhead Camera - Credential Disclosure (@K3ysTr0K3R) [critical] (vKEV)
  • [CVE-2017-7504] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization (@Jayachandran) [critical] (vKEV) 🔥
  • [johnson-controls-default-login] Johnson Controls Frick Quantum HD Compressors - Default Login (@Mister-Joe) [high]
  • [litellm-default-login] LiteLLM - Default Login (@icarot) [high]
  • [chatwoot-super-admin-panel] Chatwoot Super Admin Panel - Detect (@RootKaito) [info]
  • [docmost-panel] Docmost Panel - Detect (@ChrisJr404) [info]
  • [documenso-panel] Documenso Panel - Detect (@ChrisJr404) [info]
  • [donetick-panel] Donetick Panel - Detect (@ChrisJr404) [info]
  • [inventree-panel] InvenTree Panel - Detect (@ChrisJr404) [info]
  • [karakeep-panel] Karakeep Panel - Detect (@ChrisJr404) [info]
  • [komga-panel] Komga Panel - Detect (@ChrisJr404) [info]
  • [linkding-panel] Linkding Panel - Detect (@ChrisJr404) [info]
  • [mguard-security-appliance-panel] mGuard Security Appliance - Panel (@righettod) [info]
  • [planka-panel] Planka Panel - Detect (@ChrisJr404) [info]
  • [romm-panel] RomM Panel - Detect (@ChrisJr404) [info]
  • [sap-cloud-connector-panel] SAP Cloud Connector Panel (@righettod) [info]
  • [silverbullet-panel] SilverBullet Panel - Detect (@ChrisJr404) [info]
  • [wallabag-panel] Wallabag Panel - Detect (@ChrisJr404) [info]
  • [wallos-panel] Wallos Panel - Detect (@ChrisJr404) [info]
  • [directus-api-exposure] Directus Server Info - Unauthenticated Fingerprint (@RootKaito) [info]
  • [flowise-chatflows-exposure] Flowise AI - Unauthenticated Chatflows API Exposure (@comradezephyr) [high]
  • [grafana-loki-api-exposure] Grafana Loki - Unauthenticated API Access (@RootKaito) [medium]
  • [langflow-api-exposure] Langflow - Unauthenticated API Exposure (@comradezephyr) [high]
  • [victoriametrics-vmagent-api-exposure] VictoriaMetrics vmagent - Unauthenticated Targets Exposure (@RootKaito) [low]
  • [maven-settings-xml-exposure] Apache Maven settings.xml Credentials - Exposure (@ChrisJr404) [high]
  • [nuget-config-exposure] NuGet.config Package Source Credentials - Exposure (@ChrisJr404) [high]
  • [pypirc-credentials-exposure] Python .pypirc Credentials - Exposure (@ChrisJr404) [high]
  • [apache-livy-logs] Apache Livy - Logs Exposed (@icarot) [medium]
  • [gargoyle-router-detect] Gargoyle Router Management Utility - Detect (@K3ysTr0K3R) [info]
  • [nacos-v3-auth-scope-bypass] Nacos 3.x - Unauthenticated Admin Takeover (@0x_Akoko, @mhtsec) [critical]
  • [apache-livy-detect] Apache Livy - Detect (@icarot) [info]
  • [dawarich-detect] Dawarich - Detect (@ChrisJr404) [info]
  • [docuseal-detect] DocuSeal Detect (@ChrisJr404) [info]
  • [drupal-eol] Drupal End-of-Life - Detect (@CyberTechSea) [info]
  • [fiberhome-router-detect] Fiberhome Router - Detect (@K3ysTr0K3R) [info]
  • [homebox-detect] Homebox - Detect (@ChrisJr404) [info]
  • [mealie-detect] Mealie - Detect (@ChrisJr404) [info]
  • [vikunja-detect] Vikunja - Detect (@ChrisJr404) [info]
  • [arangodb-auth-bypass] ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCE (@dhiyaneshdk) [critical]
  • [siemens-s7-detect] Siemens SIMATIC S7 Series PLC - Detect (@SergioCc13) [info]

New Contributors

Don't miss a new nuclei-templates release

NewReleases is sending notifications on new releases.