PatchSiren

priyanshumittal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL priyanshumittal CVE published 2026-04-08

CVE-2026-39620

A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the Appointment theme, potentially allowing attackers to upload a web shell to a web server. The issue affects Appointment theme versions from n/a through <= 3.5.5. This vulnerability has been assigned a CVSS score of 9.6, indicating a high severity level. The vulnerability could allow an attacker to trick authenticated users into perfor [truncated]

CRITICAL priyanshumittal CVE published 2026-04-08

CVE-2026-39619

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Busiprof theme, version 2.5.2 and earlier. This vulnerability allows an attacker to upload a Web Shell to a Web Server. The issue affects Busiprof from n/a through <= 2.5.2. Administrators and users of the Busiprof theme should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability has a CVSS score of 9.6 [truncated]

CRITICAL priyanshumittal CVE published 2026-04-08

CVE-2026-39617

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Bluestreet theme, affecting versions from n/a through 1.7.3. This issue allows for Cross Site Request Forgery. The vulnerability has a CVSS score of 9.6 and is considered Critical. Users of the Bluestreet theme, particularly those with versions 1.7.3 or earlier, should be aware of this vulnerability and take necessary precautions to prevent exploitation.