Application Security Detections Published in January 2026

Hitesh Kadu

Table of Contents

In January, Qualys Web Application Scanning and API Security released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:

React Router, Next.js, Billboard.js, OpenSSL, Drupal, WordPress, Mattermost, Cacti, Digiever, RustFS, Apache Tomcat, Dify, Zimbra, N8n, Langflow, JetBrains, SeaCMS, GitLab, MLflow, Mailpit, Adobe ColdFusion, Fortinet, Cisco, SAP, Oracle, Apache Airflow, BentoML, Apache Solr, vLLM

Details about the following QIDs can be found in our knowledge base. Please review the reports for the scanned applications for these detections and, if any are identified, follow the steps in the knowledge base to ensure the applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. If left unaddressed, these vulnerabilities can pose security risks, including breaches, unauthorized access, and various malicious activities.

Application Security Detections Published in January 2026

In January, Qualys Web Application Scanning and API Security released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:

React Router, Next.js, Billboard.js, OpenSSL, Drupal, WordPress, Mattermost, Cacti, Digiever, RustFS, Apache Tomcat, Dify, Zimbra, N8n, Langflow, JetBrains, SeaCMS, GitLab, MLflow, Mailpit, Adobe ColdFusion, Fortinet, Cisco, SAP, Oracle, Apache Airflow, BentoML, Apache Solr, vLLM

Details about the following QIDs can be found in our knowledge base. Please review reports of the scanned applications for these detections and, if any are identified, follow the steps provided in the knowledge base to ensure applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. If not addressed, these vulnerabilities can pose security risks, such as breaches, unauthorized access, and various malicious activities.

QIDTitle
151073React Router Arbitrary File Read/Write Vulnerability (CVE-2025-61686)
151074React Router Cross Site Scripting (XSS) Vulnerabilities (CVE-2026-21884,CVE-2026-22029)
151075React Router Cross Site Scripting (XSS) Vulnerability (CVE-2025-59057)
151076Next.js Denial of Service (DoS) Vulnerability (CVE-2025-59471)
151077Next.js Denial of Service (DoS) Vulnerability (CVE-2025-59472)
151078Billboard.js Cross Site Scripting (XSS) Vulnerability (CVE-2026-1513)
520100Open Secure Sockets Layer (OpenSSL) Stack Buffer Overflow Vulnerability (CVE-2025-15467)
520101Open Secure Sockets Layer (OpenSSL) Improper Validation Vulnerability (CVE-2025-11187)
530640Drupal Simple OAuth (OAuth2) and OpenID Connect: Access Bypass Vulnerability (CVE-2025-12466)
530641WordPress Academy LMS Plugin: PHP Object Injection Vulnerability (CVE-2025-12099)
530651WordPress Asgaros Forum Plugin: SQL Injection Vulnerability (CVE-2025-11452)
530652WordPress Alex Reservations Plugin: Arbitrary File Upload Vulnerability (CVE-2025-12399)
530715Drupal CivicTheme: Cross-site Scripting (XSS) Vulnerability (CVE-2025-12083)
530716Drupal Currency Module: Cross Site Request Forgery (CSRF) Vulnerability (CVE-2025-10930)
530759WordPress Elementor Website Builder Plugin: Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2025-11220)
530763WordPress Multi Uploader Plugin: Arbitrary File Deletion Vulnerability (CVE-2025-14344)
530764WordPress LazyTasks Plugin: Arbitrary Account Takeover Vulnerability (CVE-2025-12963)
530765WordPress Newsletter Plugin: SQL Injection Vulnerability (CVE-2025-67999)
530781WordPress wpForo Forum Plugin: SQL Injection Vulnerability (CVE-2025-13126)
530782WordPress Blaze Demo Importer Plugin: Unauthorized Database Reset Vulnerability (CVE-2025-13334)
530783Mattermost Jira Plugin: Authentication Bypass Vulnerability (CVE-2025-14273)
530794Cacti Command Injection Vulnerability (CVE-2025-66399)
530795WordPress WP Directory Kit Plugin: SQL Injection Vulnerability (CVE-2025-13089)
530796WordPress FunnelKit Plugin: SQL Injection Vulnerability (CVE-2025-14169)
530797WordPress SureForms Plugin: Cross-Site Scripting Vulnerability (CVE-2025-14855)
530798Digiever DS-2105 Pro Command Injection Vulnerability (CVE-2023-52163)
530799RustFS gRPC Hardcoded Token Authentication Bypass Vulnerability (CVE-2025-68926)
530800Apache Tomcat UTF-8 Decoder Denial of Service (DoS) Vulnerability (CVE-2018-1336)
530801Apache Tomcat TLS Security Constraint Bypass Vulnerability (CVE-2018-8034)
530802Dify API Key Exposure Vulnerability (CVE-2025-67732)
530803Zimbra Local File Inclusion (LFI) Vulnerability (CVE-2025-68645)
530804WordPress Advanced Ads Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2025-13592)
530805N8n Arbitrary Command Execution Vulnerability (CVE-2025-68668)
530806Langflow Missing Authentication Vulnerability (CVE-2026-21445
530807Zimbra Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2025-66376)
530808Zimbra Hardcoded Flickr Credentials Vulnerability (CVE-2025-67809)
530809WordPress Fancy Product Designer Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-12570)
530810JetBrains TeamCity Path Traversal Vulnerability (CVE-2025-67742)
530811WordPress Image Gallery Plugin: Path Traversal Vulnerability (CVE-2025-13891)
530812WordPress Blocksy Companion Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-12475)
530813SeaCMS SQL Injection Vulnerability (CVE-2025-15002)
530814WordPress Frontend Admin Plugin: Multiple Security Vulnerabilities (CVE-2025-14736, CVE-2025-14741)
530815WordPress Frontend Admin Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-14937)
530816GitLab CE/EE Denial of Service Vulnerability (CVE-2025-14157)
530817GitLab EE Information Disclosure Vulnerability (CVE-2025-11247)
530818GitLab CE/EE Information Disclosure Vulnerability (CVE-2025-13978)
530819GitLab CE/EE HTML Injection Vulnerability (CVE-2025-12734)
530820N8n Unauthenticated File Access Vulnerability (CVE-2026-21858)
530821WordPress SlimStat Analytics Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-15057)
530822WordPress SlimStat Analytics Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-15055)
530823WordPress Eventin Plugin: Missing Authorization Vulnerability (CVE-2025-14657)
530824MLflow DNS Rebinding Vulnerability (CVE-2025-14279)
530826Mailpit Server Side Request Forgery Vulnerability (CVE-2026-21859)
530827WordPress Brevo for WooCommerce Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-14436)
530828WordPress WooCommerce Square Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2025-13457)
530829WordPress Opvius AI Plugin: Path Traversal Vulnerability (CVE-2025-14301)
530830Adobe ColdFusion Arbitrary Code Execution Vulnerability via Apache Tika Dependency (APSB26-12)
530831Mailpit Cross-Site WebSocket Hijacking Vulnerability (CVE-2026-22689)
530832Fortinet FortiSIEM OS Command Injection Vulnerability (CVE-2025-64155)
530833Cisco Identity Services Engine (ISE) XML External Entity Vulnerability (CVE-2026-20029)
530834WordPress GeekyBot Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-15266)
530835WordPress Name Directory Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-15283)
530836WordPress Appointment Booking Calendar Plugin: SQL Injection Vulnerability (CVE-2025-12166)
530837WordPress News and Blog Designer Bundle Plugin: Local File Inclusion (LFI) Vulnerability (CVE-2025-14502)
530838WordPress Uploadify Plugin: Arbitrary File Upload Vulnerability (CVE-2011-10041)
530840GitLab CE/EE Cross-Site Scripting Vulnerability (CVE-2025-9222)
530841GitLab CE/EE Cross-Site Scripting Vulnerability (CVE-2025-13761)
530842SAP S/4HANA SQL Injection Vulnerability (CVE-2026-0501)
530843FortiClientEMS SQL Injection Vulnerability (CVE-2025-59922)
530844SAP S/4HANA Code Injection Vulnerability (CVE-2026-0498)
530845WordPress RegistrationMagic Plugin: Privilege Escalation Vulnerability (CVE-2025-15403)
530846WordPress Registration Login with Mobile Phone Number Plugin: Authentication Bypass Vulnerability (CVE-2025-10484)
530847WordPress Supreme Modules Lite Plugin: Arbitrary File Upload Vulnerability (CVE-2025-13062)
530848WordPress Video Gallery Plugin: Arbitrary File Upload Vulnerability (CVE-2025-12957)
530849Apache Airflow Rendered Templates Information Disclosure Vulnerability (CVE-2025-68438)
530850Oracle WebLogic Server Multiple Vulnerabilities (CPU-JAN2026)
530851WordPress Cinerama Theme: Local File Inclusion Vulnerability (CVE-2025-68987)
530857GitLab EE Missing Authorization Vulnerability (CVE-2025-13772)
530858GitLab EE Missing Authorization Vulnerability (CVE-2025-13781)
530859vLLM Denial of Service (DoS) Vulnerability (CVE-2026-22773)
530860GitLab CE/EE Denial of Service Vulnerability (CVE-2025-10569)
530861GitLab CE/EE Insufficient Access Control Vulnerability (CVE-2025-11246)
530862GitLab CE/EE Information Disclosure Vulnerability (CVE-2025-3950)
530867vLLM Remote Code Execution (RCE) Vulnerability (CVE-2026-22807)
530868vLLM Denial of Service (DoS) Vulnerability (CVE-2025-62372)
530869GitLab CE/EE Denial of Service Vulnerability (CVE-2025-13927)
530870GitLab CE/EE Incorrect Authorization Vulnerability (CVE-2025-13928)
530871BentoML Path Traversal Vulnerability (CVE-2026-24123)
530872GitLab CE/EE Unchecked Return Value Vulnerability (CVE-2026-0723)
530873GitLab CE/EE Denial of Service Vulnerability (CVE-2025-13335)
530877Fortinet FortiOS Authentication Bypass Vulnerability (CVE-2026-24858)
530878vLLM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-24779)
530881Apache Solr Improper Authorization Vulnerability (CVE-2026-22022)
530882Apache Solr Improper Input Validation Vulnerability (CVE-2026-22444)
530883N8n Remote Code Execution Vulnerability (CVE-2026-1470)
530884N8n Arbitrary Code Execution Vulnerability (CVE-2026-0863)
530888N8n Remote Code Execution Vulnerability (CVE-2026-21877)
530889GitLab CE/EE Denial of Service Vulnerability (CVE-2026-1102)
580899Bypass Product Bundle Creations
580902GraphQL CSRF via Manipulated Content-Type Header
580904Exploiting Default Values for Loan Calculation
580905Authentication Bypass via Malformed Auth Headers
580906Improper Amount Transfer Handling
580907Business Logic Flaw in Inventory / Stock Management

What’s Next

Leverage the QID list to guide your remediation efforts and strengthen your risk posture.

Looking for more context or remediation tips? Head to Qualys KnowledgeBase for detailed analysis, actionable guidance, and expert-backed support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *