Xerte Online Toolkits versions 3.15 and earlier have multiple security vulnerabilities that can be exploited by unauthenticated attackers.
Claims
Xerte Online Toolkits versions 3.15 and earlier have multiple security vulnerabilities that can be exploited by unauthenticated attackers.
Parent: CybersecurityEntity: Xerte Online ToolkitsImpact: negativeDate: Apr 23, 2026Target: Xerte Online Toolkits versions 3.15 and earlier have multiple security vulnerabilities that can be exploited by unauthenticated attackers.
Source posts
๐ด CVE-2026-34415 - Critical (9.8)
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attacker...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-34415/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
๐ CVE-2026-34413 - High (8.6)
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die()...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-34413/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cve#vulnerability#infosec#cybersecurity#security#tenda
๐จ EUVD-2026-25067
๐ Score: 8.8/10 (CVSS v3.1)
๐ฆ Product: xerteonlinetoolkits, xerteonlinetoolkits, xerteonlinetoolkits (+3 more)
๐ข Vendor: thexerteproject
๐
Updated: 2026-04-22
๐ Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redi...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25067
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25073
๐ Score: 6.9/10 (CVSS v3.1)
๐ฆ Product: xerteonlinetoolkits, xerteonlinetoolkits
๐ข Vendor: thexerteproject
๐
Updated: 2026-04-22
๐ Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25073
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25068
๐ Score: 7.1/10 (CVSS v3.1)
๐ฆ Product: xerteonlinetoolkits, xerteonlinetoolkits, xerteonlinetoolkits (+3 more)
๐ข Vendor: thexerteproject
๐
Updated: 2026-04-22
๐ Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name pa...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25068
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25069
๐ Score: 9.3/10 (CVSS v3.1)
๐ฆ Product: xerteonlinetoolkits, xerteonlinetoolkits, xerteonlinetoolkits (+3 more)
๐ข Vendor: thexerteproject
๐
Updated: 2026-04-22
๐ Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25069
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability