PatchSiren

Furion CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Furion CVE published 2026-10-11

CVE-2026-108570

A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View Engine. The manipulation of the argument content results in improper neutralization of special elements used in a template engine. The attack can be executed remotely.

MEDIUM Furion CVE published 2026-10-11

CVE-2026-108569

A vulnerability was identified in Furion .NET Framework up to 4.9.9.92, specifically in the String.Replace function of the StringRenderExtensions.cs file, which is susceptible to SQL injection. The exploit is publicly available, and remote exploitation is possible. The CVSS score is 5.3, with a severity rating of MEDIUM. This vulnerability allows for remote exploitation and could lead to SQL injection att [truncated]