PatchSiren

digitaldruid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM digitaldruid CVE published 2026-09-14

CVE-2023-34854

HotelDruid has insufficient file upload sanitation in its backup/restore function, posing a medium-severity risk. This vulnerability, tracked as CVE-2023-34854, affects HotelDruid versions prior to 3.0.6. The issue allows potential attackers to upload malicious files, which could lead to unauthorized access or data breaches. Defenders responsible for HotelDruid installations should assess exposure and pri [truncated]