#hubzerocms
CVE-2026-92984 - hubzero-cms
The HUBzero CMS platform can accept session IDs from the web address instead of only from secure cookies. This lets an attacker create a link with a known session ID, send it…

Too many irrelevant or confusing CVEs? Use stackflag.com

#hubzerocms #hubzero #CVE #infosec
CVE-2026-92984: HUBzero CMS lets attackers hijack user sessions
The HUBzero CMS platform can accept session IDs from the web address instead of only from secure cookies.
stackflag.com
September 19, 2026 at 5:20 AM
CVE-2026-92970 - hubzero-cms
When users upload project files in HUBzero CMS version 2.2.32 or earlier, they can trick the system into saving those files outside the intended folder. This lets a signed‑in…

Too many irrelevant or confusing CVEs? Use stackflag.com

#hubzerocms #hubzero #CVE #infosec
CVE-2026-92970: HUBzero CMS allows uploaded files to be placed anywhere
When users upload project files in HUBzero CMS version 2.2.32 or earlier, they can trick the system into saving those files outside the intended folder.
stackflag.com
September 19, 2026 at 5:10 AM