Application Security Detections Published in March 2026

Hitesh Kadu

Table of Contents

In March, Qualys Web Application Scanning released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:

Underscore.js, Angular, Next.js, Atlassian, ClipBucket, OpenSSL, Nginx, WordPress, JetBrains, DNN, Drupal, Gradio, GitLab, Grafana, Keycloak, Apache Tomcat, Omnissa, Strapi, Apache Ranger, Microsoft SharePoint, F5, Craft CMS, Langflow, Apache Superset, Apache Spark, Apache Camel, Zimbra, Apache Airflow, Hoverfly, EasyCVR, Glances

Details about the following QIDs can be found in our knowledge base. Please review the reports for the scanned applications associated with these detections and, if any are identified, follow the steps in the Knowledge Base to ensure the applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. If left unaddressed, these vulnerabilities can pose security risks, including breaches, unauthorized access, and various malicious activities.

QIDTitle
151081Underscore.js Denial of Service (DOS) Vulnerability (CVE-2026-27601)
151082Angular Cross-Site Scripting (XSS) Vulnerability (CVE-2026-22610)
151083Angular Cross-Site Scripting (XSS) Vulnerability (CVE-2026-27970)
151084Angular Cross-Site Scripting (XSS) Vulnerability (CVE-2026-32635)
151085Next.js HTTP Request Smuggling Vulnerability (CVE-2026-29057)
151086Next.js Uncontrolled Resource Consumption Vulnerability (CVE-2026-27980)
151087Next.js Potential Denial of Service Vulnerability (CVE-2026-27979)
151088Next.js React Server Components (RSC) Denial of Service (DoS) Vulnerability (CVE-2026-23864)
520116EOL/Obsolete Software: Atlassian Confluence 5.x Detected
520117EOL/Obsolete Software: Atlassian Confluence 6.x Detected
520118ClipBucket V5 Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-28354)
520119EOL/Obsolete Software: Atlassian Confluence 7.x Detected
520120EOL/Obsolete Software: Atlassian Confluence 8.x Detected
520121OpenSSL CBC Timing Side-Channel Plaintext Recovery Vulnerability (CVE-2013-0169) (Lucky Thirteen)
520122Atlassian Bamboo Data Center Remote Code Execution (RCE) Vulnerability (CVE-2026-21570)
520123Nginx ngx_http_dav_module Buffer Overflow Vulnerability (CVE-2026-27654)
520124Nginx ngx_http_mp4_module Buffer Overflow Vulnerabilities (CVE-2026-27784,CVE-2026-32647)
520125Nginx ngx_mail_auth_http_module NULL Pointer Dereference Vulnerability (CVE-2026-27651)
520126NGINX ngx_mail_smtp_module CRLF Injection Vulnerability (CVE-2026-28753)
520127NGINX ngx_stream_ssl_module OCSP Revocation Bypass Vulnerability (CVE-2026-28755)
520128NGINX SSL/TLS Upstream Injection Vulnerability (CVE-2026-1642)
530979WordPress S2Member Plugin: Privilege Escalation Vulnerability (CVE-2026-1994)
530980WordPress Clasifico Listing Plugin: Privilege Escalation Vulnerability (CVE-2025-12882)
530981WordPress Prodigy Commerce Plugin: Local File Inclusion Vulnerability (CVE-2026-0926)
530982JetBrains TeamCity Open redirect Vulnerability (CVE-2026-28194)
530983JetBrains TeamCity Missing Authorization Vulnerability (CVE-2026-28195)
530984JetBrains TeamCity Residual Credential File Vulnerability (CVE-2026-28196)
530985WordPress WP Maps Plugin: Local File Inclusion Vulnerability (CVE-2025-12062)
530986WordPress WooCommerce Ajax Filter Plugin: PHP Object Injection Vulnerability (CVE-2026-1426)
530987WordPress ShopLentor Plugin: Email Relay Abuse Vulnerability (CVE-2026-1714)
530988WordPress Tablesome Plugin: Information Exposure Vulnerability (CVE-2025-12845)
530989DNN Stored Cross-Site Scripting Vulnerabilities (CVE-2026-24838, CVE-2026-24833)
530990DNN Stored Cross-Site Scripting Vulnerabilities (CVE-2026-24837, CVE-2026-24836, CVE-2026-24784)
530991DNN Arbitrary File Upload Vulnerabilities (CVE-2025-64095, CVE-2025-62802)
530992WordPress Piotnet Addons Plugin: Cross-site Scripting (XSS) Vulnerability (CVE-2024-33630)
530993WordPress NewsBlogger Theme: Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2025-12821)
530994WordPress Orderable Plugin: Missing Authorization Vulnerability (CVE-2026-0974)
530995PHAR Stream Wrapper Injection Possible
530996WordPress Toret Manager Plugin: Missing Authorization Vulnerability (CVE-2026-0912)
530997WordPress WP AUDIO GALLERY Plugin: Missing Authorization Vulnerability (CVE-2025-13603)
530998WordPress Responsive Lightbox Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2025-15386)
530999WordPress Magic Login Mail Plugin: Privilege Escalation Vulnerability (CVE-2026-2144)
531000Drupal Login Time Restriction Module: Cross Site Request Forgery (CSRF) Vulnerability (CVE-2025-13982)
531001Gradio Server-Side Request Forgery Vulnerability (CVE-2026-28416)
531002Gradio Path Traversal Vulnerability (CVE-2026-28414)
531003Gradio Open Redirect Vulnerability (CVE-2026-28415)
531004Gradio Server Credentials Exposed and Use of Hardcoded Session Secret Vulnerability (CVE-2026-27167)
531007EOL/Obsolete Software: GitLab CE/EE Detected
531008EOL/Obsolete Software: Grafana Detected
531009WordPress Soledad Theme: Local File Inclusion Vulnerability (CVE-2025-68066)
531010Keycloak Broken Access Control Vulnerability (CVE-2024-3656)
531011Keycloak Authorization Bypass Vulnerability (CVE-2017-12160)
531012WordPress Stockholm Core Plugin: Local File Inclusion Vulnerability (CVE-2025-68067)
531013WordPress Sneeit Framework Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2025-6389)
531014WordPress Download Manager Plugin: PHAR Deserialization Vulnerability (CVE-2022-2436)
531015DNN Stored Cross-Site Scripting Vulnerability (CVE-2025-64094)
531016Apache Tomcat Race Condition Vulnerability (CVE-2018-8037)
531017DNN Cross-Site Scripting Vulnerabilities
531018Omnissa Workspace ONE UEM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-25229)
531019Omnissa Workspace ONE UEM Secondary Context Path Traversal Vulnerability (CVE-2025-25231)
531020WordPress Themify Multiple Themes: Arbitrary File Upload Vulnerability (CVE-2025-30996)
531021WordPress User Registration Plugin: Privilege Escalation Vulnerability (CVE-2026-1492)
531022WordPress Modular DS Plugin: Privilege Escalation Vulnerability (CVE-2026-23800)
531023DNN Insufficient Filename Sanitization Vulnerability (CVE-2025-59547)
531024DNN Arbitrary Theme Loading Vulnerability (CVE-2025-59535)
531026Omnissa Workspace ONE UEM Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-22054)
531027WordPress SiteOrigin Panels Plugin: Local File Inclusion Vulnerability (CVE-2026-2448)
531028WordPress Master Addons Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-3132)
531029DNN Login IP Filter Bypass Vulnerability (CVE-2025-52487)
531030DNN Cross-Site Scripting Vulnerabilities (CVE-2025-52486, CVE-2025-52485)
531031Strapi CMS Insufficient Session Expiration Vulnerability (CVE-2025-3930)
531032Strapi CMS CORS Misconfiguration Vulnerability (CVE-2025-53092)
531033Strapi CMS Weak Password Validation Vulnerability (CVE-2025-25298)
531034Strapi CMS Authorization Bypass Vulnerability (CVE-2024-56143)
531035Apache Ranger Remote Code Execution Vulnerability (CVE-2025-59059)
531036Strapi CMS Server Side Request Forgery (SSRF) Vulnerability (CVE-2024-52588)
531037Strapi CMS Authentication Bypass Vulnerability (CVE-2024-34065)
531038WordPress Pojo Accessibility Plugin: SQL Injection Vulnerability (CVE-2026-2413)
531039WordPress Login With Azure Plugin: Authentication Bypass Vulnerability (CVE-2026-2628)
531040WordPress Tutor LMS Plugin: SQL Injection Vulnerability (CVE-2025-13673)
531041Microsoft SharePoint Remote Code Execution (RCE) Vulnerability (CVE-2026-20963)
531042F5 BIG-IP HTTP/2 Denial of Service (DoS) Vulnerability (CVE-2025-54500)
531043Craft CMS Privilege Escalation Vulnerability (CVE-2026-32267)
531044Langflow Remote Code Execution Vulnerability (CVE-2026-33017)
531045Craft CMS Remote Code Execution (RCE) Vulnerability (CVE-2026-32264)
531046Craft CMS Remote Code Execution (RCE) Vulnerability (CVE-2026-32263)
531047Craft CMS Remote Code Execution (RCE) Vulnerability (CVE-2026-25498)
531048Craft CMS Remote Code Execution (RCE) Vulnerability (CVE-2025-68455)
531049Apache Superset Improper Input Validation Vulnerability (CVE-2026-23984)
531050Apache Superset Sensitive Data Exposure Vulnerability (CVE-2026-23983)
531051Apache Superset SQL Injection Vulnerability (CVE-2026-23980)
531052Apache Superset Sensitive Information Exposure Vulnerability (CVE-2026-23969)
531053Craft CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-27127)
531054WordPress Nutrie Theme: Arbitrary File Upload Vulnerability (CVE-2025-68555)
531055WordPress Classter Theme: PHP Object Injection Vulnerability (CVE-2025-54001)
531056Apache Spark Code Execution Vulnerability (CVE-2025-54920)
531057WordPress Charety Theme: Arbitrary File Upload Vulnerability (CVE-2026-24960)
531058WordPress Pets Club Theme: PHP Object Injection Vulnerability (CVE-2026-22453)
531059WordPress Keenarch Theme: Arbitrary File Upload Vulnerability (CVE-2025-68554)
531060Apache Camel Insecure Deserialization Vulnerability (CVE-2026-25747)
531061Zimbra Cross-Site Scripting (XSS) Vulnerabilities (CVE-2026-33368, CVE-2026-33370)
531062Zimbra LDAP Injection Vulnerability (CVE-2026-33369)
531063Zimbra XML External Entity (XXE) Vulnerability (CVE-2026-33371)
531064Zimbra Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2026-33372)
531069Apache Airflow Code Execution Vulnerability (CVE-2024-56373)
531070Apache Airflow Sensitive Value Exposure Vulnerability (CVE-2025-27555)
531071Apache Airflow Missing Authorization Vulnerability (CVE-2026-30911)
580930Weak Credentials
580931API Authentication Endpoint Without Rate Limiting
580932Hoverfly Command Injection Vulnerability (CVE-2025-54123)
580933EasyCVR Information Exposure Vulnerability
580934Username Enumeration via API Login Endpoint
580935OAuth Credentials File Exposure
580936HTTP Verb Tampering
580937Grafana Default Login
580939OTP Disclosure in API Response
580940Glances Unauthenticated API Exposure (CVE-2026-32596)
580941OTP Endpoint Without Rate Limiting
580942Empty OTP Bypass Vulnerability
580943OTP Bypass via Missing OTP Parameter

What’s Next

Leverage the QID list to guide your remediation efforts and strengthen your risk posture.

Looking for more context or remediation tips? Head to Qualys KnowledgeBase for detailed analysis, actionable guidance, and expert-backed support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *