PatchSiren

reportico-web CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL reportico-web CVE published 2026-08-18

CVE-2026-52610

The CVE-2026-52610 vulnerability is an arbitrary file write/directory traversal issue in reportico-web version 8.1.0 or earlier. This vulnerability allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user. The exploit involves specifying a filename in the 'saveTemplate' parameter in conjunction with 'execute_mode=PREPARE' parameter in the ' [truncated]

MEDIUM reportico-web CVE published 2026-08-18

CVE-2026-52609

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T18:18:20.143Z and has not been modified since then. A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjuncti [truncated]

CRITICAL reportico-web CVE published 2026-08-18

CVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. This critical vulnerability, with a CVSS score of 9.8, affects reportico-web installations and requires immediate attention from security teams and administra [truncated]

MEDIUM reportico-web CVE published 2026-08-18

CVE-2026-52606

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T17:16:59.080Z and has not been modified since then. A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction wit [truncated]