PatchSiren

wavelog CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL wavelog CVE published 2026-09-17

CVE-2026-54237

CVE-2026-54237 is a critical vulnerability in Wavelog, a web-based amateur radio logging software. The vulnerability exists in versions 1.8 through 2.4.2 and allows a remote unauthenticated attacker to read or write log files and place attacker-controlled content into PHP configuration files, potentially leading to code execution on the server. The issue is fixed in version 2.4.2.