PatchSiren

owen2345 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH owen2345 CVE published 2026-08-12

CVE-2026-73331

CVE-2026-73331 is an authenticated SQL injection vulnerability in CamaleonCMS 2.9.1. Attackers with post creation or editing privileges can inject SQL syntax via crafted slug values, allowing extraction of sensitive data from the SQLite database, including administrative credentials and configuration values. This vulnerability can be exploited using boolean- or union-style blind SQL injection techniques. [truncated]

HIGH owen2345 CVE published 2026-08-12

CVE-2026-73330

CVE-2026-73330 is a server-side template injection vulnerability in CamaleonCMS 2.9.1. Authenticated administrators can execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action. The vulnerability allows attackers to submit crafted email parameters containing ERB expressions, which are evaluated when an SMTP rejection reflects the recipient address back in t [truncated]

HIGH owen2345 CVE published 2026-08-12

CVE-2026-73326

CamaleonCMS contains a missing authorization vulnerability, CVE-2026-73326, allowing low-privileged users to access and modify plugin settings without administrator-level authorization. The vulnerability affects the attack, front_cache, cama_meta_tag, and cama_contact_form plugins. This could allow attackers to manipulate plugin configuration parameters at runtime, alter cached page behavior, modify publi [truncated]

HIGH owen2345 CVE published 2026-08-11

CVE-2026-56721

CamaleonCMS version 2.9.2 and earlier contains a high-severity privilege escalation vulnerability via insecure direct object reference (IDOR) and parameter confusion flaw. The vulnerability allows authenticated low-privileged attackers to overwrite any user's credentials, potentially leading to full site takeover. Defenders should verify the presence of affected versions, review user accounts for unauthor [truncated]

MEDIUM owen2345 CVE published 2026-08-11

CVE-2026-56720

CVE-2026-56720 is a missing authorization vulnerability in CamaleonCMS version 2.9.2 and earlier. The vulnerability exists in the admin users controller, allowing any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can exploit this by sending a GET request to the admin profile endpoint with an enumerable sequential integer user ID to disclo [truncated]

MEDIUM owen2345 CVE published 2026-08-03

CVE-2026-67616

CVE-2026-67616 is a missing authorization vulnerability in Camaleon CMS versions through 2.9.2. The issue allows authenticated low-privileged users to create draft posts by bypassing role and permission checks on the drafts endpoint. This vulnerability can be exploited by sending requests to the drafts endpoint using only session authentication, potentially leading to unauthorized drafts appearing in the [truncated]