search
HortusFox
Trends
- 1HortusFox patches SQL injection flaw in versions before 6.2โ๐จ EUVD-2026-95791 ๐ Score: 7.1/10 (CVSS v3.1) ๐ฆ Product: hortusfox-web ๐ข Vendor: danielbrendel ๐ Updated: 2026-10-09 ๐ H
A medium-severity SQL injection vulnerability, tracked as EUVD-2026-95791 with a CVSS score of 7.1, has been disclosed in HortusFox (hortusfox-web), the self-hosted plant management application by developer danielbrendel. Versions before 6.2 allow API token holders to inject SQL through a crafted include_info parameter. Users are advised to update to 6.2 or later.
- 2HortusFox vulnerability allows authenticated file upload attacksโ๐จ EUVD-2026-95792 ๐ Score: 7.7/10 (CVSS v3.1) ๐ฆ Product: hortusfox-web ๐ข Vendor: danielbrendel ๐ Updated: 2026-10-09 ๐ H
A medium-to-high severity vulnerability, tracked as EUVD-2026-95792 with a CVSS score of 7.7, has been disclosed in HortusFox (hortusfox-web), a self-hosted plant management application by developer danielbrendel. Versions through 6.3 contain an unrestricted file upload flaw in the PlantAttachmentModel, letting authenticated users store arbitrary files on the server. Admins running the app are advised to check for updates and restrict uploads.