PatchSiren

Mosasauroidea CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Mosasauroidea CVE published 2026-08-25

CVE-2026-38474

The GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 has a Broken access control vulnerability in the IP lock manager. This allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock. The affected product is GazellePW, which is a PosterWall software. The vulnerability class is Broken Access Control. The likely [truncated]

MEDIUM Mosasauroidea CVE published 2026-08-25

CVE-2026-38473

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T22:17:03.910Z and has not been modified since then. CVE-2026-38473 is a Stored XSS vulnerability in GazellePW (GazellePosterWall). An authenticated user can inject JavaScript via a crafted subtitle filename during upload. The filename is stored and later rendered in /subtitles.php?action=delete, [truncated]

MEDIUM Mosasauroidea CVE published 2026-08-25

CVE-2026-38472

The CVE-2026-38472 vulnerability is a Stored XSS issue in GazellePW (GazellePosterWall) that allows remote attackers to inject arbitrary JavaScript via the c parameter in /forums.php?action=ajax_get_jf. This parameter is later rendered in the data-tooltip attribute in /forums.php?action=viewthread and interpreted as HTML by the Tooltipster configuration. Organizations using GazellePW should be aware of th [truncated]

MEDIUM Mosasauroidea CVE published 2026-08-25

CVE-2026-38470

A Broken Access Control vulnerability exists in GazellePW's API user endpoint, allowing authenticated users with normal privileges to enable or disable arbitrary user accounts using a user-created API token with req=disable or req=enable actions. This medium-severity issue has a CVSS score of 4.3 and affects GazellePW. Developers and administrators of GazellePW, security teams monitoring for access contro [truncated]

MEDIUM Mosasauroidea CVE published 2026-08-25

CVE-2026-38468

The CVE-2026-38468 vulnerability is a SQL injection issue in the country-code lookup endpoint of GazellePW, a component used for posting wall content. This vulnerability allows remote authenticated users with users_view_ips privileges to execute arbitrary SQL commands via the ip parameter in a crafted request to tools.php?action=get_cc. The vulnerability was introduced in GazellePW commit 86c4bedf727691b5 [truncated]

MEDIUM Mosasauroidea CVE published 2026-08-25

CVE-2026-38467

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T22:17:03.280Z and has not been modified since then. CVE-2026-38467 is a SQL injection vulnerability in GazellePW (GazellePosterWall) tags manager. Remote authenticated users with users_mod privileges can execute arbitrary SQL commands via the tagid or type parameter in a crafted POST request to t [truncated]