PatchSiren

xenocrat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL xenocrat CVE published 2026-04-06

CVE-2026-35174

CVE-2026-35174 is a path traversal vulnerability in Chyrp Lite, a ultra-lightweight blogging engine. An administrator or a user with Change Settings permission can change the uploads path to any folder, allowing them to download any file on the server, including config.json.php with database credentials, and overwrite critical system files, leading to remote code execution. The vulnerability is fixed in v [truncated]

MEDIUM xenocrat CVE published 2026-04-06

CVE-2026-35173

CVE-2026-35173 is an IDOR / Mass Assignment issue in Chyrp Lite, a blogging engine, that allows authenticated users with post editing permissions to modify posts they do not own. The vulnerability exists prior to version 2026.01 and is fixed in 2026.01. This issue can lead to post takeover. Users should be cautious and update to the latest version.