CVE-2026-100900
Published 28 September 2026 · tracked since 28 September 2026
Description
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is p
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-91206 MEDIUM 6.1
- CVE-2026-82382 MEDIUM 6.1
- CVE-2026-82383 HIGH 8.2
- CVE-2026-82384 CRITICAL 9.8
- CVE-2026-82385 MEDIUM 6.5
- CVE-2026-82386 HIGH 7.7
- CVE-2026-82387 MEDIUM 5.4
- CVE-2026-82546 MEDIUM 6.1
- CVE-2026-91204 MEDIUM 6.1
- CVE-2026-82375 HIGH 7.4