v10.3.7

projectdiscovery/nuclei-templatesv10.3.7Jan 11, 2026by princechaddha

AI Summary

Release with 102 new templates and 42 CVEs, featuring critical vulnerabilities like Zimbra Collaboration LFI, SmarterMail unrestricted file upload, and MongoDB info disclosure. Notably rewarded 16 bounties for vulnerability research contributions.

Key Highlights

  • 102 new templates with 42 CVEs, 9 first-time contributions, 16 bounties rewarded
  • Critical CVEs: Zimbra LFI, SmarterMail file upload, MongoDB info disclosure (MongoBleed), Langflow CORS
  • Bounty rewards for multiple CVEs including ThinkPHP RCE, PaperCut NG auth bypass, Emby auth bypass
  • Bug fixes for false negatives in CVE-2025-37164 and improved detection for Django SQLi
  • False positive reductions for Dell iDRAC detection templates

New Features

  • CVE-2025-69200 phpMyFAQ Configuration Backup Disclosure
  • CVE-2025-68926 RustFS Hardcoded gRPC Authentication Token
  • CVE-2025-68645 Zimbra Collaboration Local File Inclusion
  • CVE-2025-52691 SmarterMail Unrestricted File Upload
  • CVE-2025-34291 Langflow AI CORS Misconfiguration
  • CVE-2025-14847 MongoDB Server Info Disclosure (MongoBleed)
  • CVE-2024-28986 SolarWinds Web Help Desk Insecure Deserialization (vKEV)
  • CVE-2024-24882 Masteriyo LMS Privilege Escalation (vKEV)
  • CVE-2023-33193 Emby Server Authentication Bypass (vKEV)
  • CVE-2023-27351 PaperCut NG Authentication Bypass (vKEV)

Full Release Notes

### New Templates Added: `102` | CVEs Added: `42` | First-time contributions: `9` | Bounties rewarded: `16`

### šŸ”„ Release Highlights šŸ”„
- [CVE-2025-69200] phpMyFAQ - Configuration Backup Disclosure (@Louay-075) [high] šŸ”„
- [CVE-2025-68926] RustFS < 1.0.0-alpha.77 - Hardcoded gRPC Authentication Token (@Chocapikk, @bilisheep) [critical] šŸ”„
- [CVE-2025-68645] Zimbra Collaboration - Local File Inclusion (@DhiyaneshDk, @sirifu4k1) [high] šŸ”„
- [CVE-2025-62522] Vite - Information Disclosure (@DhiyaneshDK) [medium] šŸ”„
- [CVE-2025-60188] Atarim < 4.2.2 - Sensitive Information Exposure (@m4sh_wacker) [high] šŸ”„
- [CVE-2025-52691] SmarterMail - Unrestricted File Upload (@DhiyaneshDK, @watchTowr) [critical] šŸ”„
- [CVE-2025-34291] Langflow AI <= 1.6.9 - CORS Misconfiguration (@686f6c61) [critical] šŸ”„
- [CVE-2025-14847] MongoDB Server - Info Disclosure (MongoBleed) (@pussycat0x, @joe-desimone, @DhiyaneshDK) [high] šŸ”„ (vKEV)
- [CVE-2025-8848] LibreChat <= 0.7.9 - HTML Injection via Accept-Language Header (@Kazgangap) [medium] šŸ”„
- [CVE-2024-28986] SolarWinds Web Help Desk < 12.8.3 - Insecure Deserialization (@rxerium) [critical] šŸ”„ (vKEV)
- [CVE-2024-24882] Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation (@riteshs4hu) [critical] šŸ”„ (vKEV)
- [CVE-2024-5057] WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection (@daffainfo) [critical] šŸ”„ (vKEV)
- [CVE-2023-33193] Emby Server - Authentication Bypass (@daffainfo) [critical] šŸ”„ (vKEV)
- [CVE-2023-27351] PaperCut NG - Authentication Bypass (@daffainfo, @jjcho) [high] šŸ”„ (vKEV)
- [CVE-2022-27924] Zimbra Collaboration Suite - Memcached Command Injection (@rxerium) [high] šŸ”„ (vKEV)
- [CVE-2021-28799] QNAP HBS 3 - Broken Access Control (@daffainfo) [critical] šŸ”„ (vKEV)
- [CVE-2019-11253] Kubernetes API Server - YAML Parsing DoS (Billion Laughs) (@ritikchaddha) [high] šŸ”„
- [CVE-2018-9206] Blueimp jQuery-File-Upload v9.22.0 - Unrestricted File Upload (@thewindghost) [critical] šŸ”„ (vKEV)
- [CVE-2018-6961] VMware NSX SD-WAN Edge - Command Injection (@D3nverNg, @thewindghost) [critical] šŸ”„ (vKEV)
- [CVE-2016-15043] WP Mobile Detector <= 3.5 - Unrestricted File Upload (@D3nverNg, @thewindghost) [critical] šŸ”„ (vKEV)

## What's Changed

šŸ’° **Bounties Rewarded** šŸ’°
  * CVE-2019-14206 - Nevma Adaptive Images - Arbitrary File Deletion (Issue #14693, PR #14694)
  * CVE-2016-15043 - WP Mobile Detector - Unrestricted File Upload (Issue #14673, PR #14674)
  * CVE-2018-6961 - VMware NSX SD-WAN Edge - Command Injection (Issue #14623, PR #14626)
  * CVE-2018-9206 - Blueimp jQuery-File-Upload - Unrestricted File Upload (Issue #14587, PR #14588)
  * CVE-2017-20192 - Formidable Form Builder - Stored XSS (Issue #14544, PR #14548)
  * CVE-2012-10018 - Mapplic & Mapplic Lite - SSRF & Stored XSS (Issue #14478, PR #14479)
  * CVE-2021-4448 - Kaswara Modern VC Addons - Missing Authorization (PR #14637)
  * CVE-2024-5057 - WordPress Easy Digital Downloads - SQL Injection (PR #14601)
  * CVE-2020-13125 - Ultimate Addons for Elementor - Registration Bypass (PR #14597)
  * CVE-2024-4455 - YITH WooCommerce Ajax Search - XSS (PR #14564)
  * CVE-2023-33193 - Emby Server - Authentication Bypass (PR #14490)
  * CVE-2023-27351 - PaperCut NG - Authentication Bypass (PR #14225)
  * CVE-2019-9082 - ThinkPHP - Command Injection (Issue #14501)
  * CVE-2025-34299 - Monsta FTP - Unrestricted File Upload (Issue #14328)
  * CVE-2025-13486 - Advanced Custom Fields Extended - RCE (Issue #14212)
  * CVE-2021-23394 - studio-42/elfinder - RCE (Issue #14132)

**Bug Fixes**
  * Fixed boolean type for verified metadata in BitRAT C2 template (PR #14777)
  * Corrected reference list formatting in SeaDuke malware hash template (PR #14776)
  * Updated CVE-2024-2473 template (PR #14748)
  * Resolved WordPress FPD template placement confusion (Issue #14608, PR #14740)
  * Fixed max-request metadata in CVE-2019-9082 (PR #14715)
  * Corrected CVE-2024-6753 YAML configuration (PR #14688)
  * Fixed string literal quoting in CVE-2015-3224 (PR #14518)
  * Removed duplicate CVE-2019-14206 template file (PR #14706)
 
**False Negatives**
  * Improved detection for CVE-2025-37164 (PR #14606)
  * Changed CVE-2020-9402 and CVE-2021-35042 to DAST templates to reduce false negatives (Issue #14502, PR #14534)
 
**False Positives**
  * Reduced false positives in Dell iDRAC detection templates for iDRAC 6, 7, and 8 (Issue #14723, PRs #14739, #14738)

**Enhancements**
  * None in this release

## Templates Added
- [CVE-2025-69200] phpMyFAQ - Configuration Backup Disclosure (@Louay-075) [high] šŸ”„
- [CVE-2025-68926] RustFS < 1.0.0-alpha.77 - Hardcoded gRPC Authentication Token (@Chocapikk, @bilisheep) [critical] šŸ”„
- [CVE-2025-68645] Zimbra Collaboration - Local File Inclusion (@DhiyaneshDk, @sirifu4k1) [high] šŸ”„
- [CVE-2025-62522] Vite - Information Disclosure (@DhiyaneshDK) [medium] šŸ”„
- [CVE-2025-60188] Atarim < 4.2.2 - Sensitive Information Exposure (@m4sh_wacker) [high] šŸ”„
- [CVE-2025-52691] SmarterMail - Unrestricted File Upload (@DhiyaneshDK, @watchTowr) [critical] šŸ”„
- [CVE-2025-34291] Langflow AI <= 1.6.9 - CORS Misconfiguration (@686f6c61) [critical] šŸ”„
- [CVE-2025-14847] MongoDB Server - Info Disclosure (MongoBleed) (@pussycat0x, @joe-desimone, @DhiyaneshDK) [high] šŸ”„ (vKEV)
- [CVE-2025-8848] LibreChat <= 0.7.9 - HTML Injection via Accept-Language Header (@Kazgangap) [medium] šŸ”„
- [CVE-2024-43971] Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting (@0xanis) [medium]
- [CVE-2024-30194] Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting (@0xanis) [medium]
- [CVE-2024-29931] WP Go Maps <= 9.0.29 - Cross-Site Scripting (@Shivam Kamboj) [medium]
- [CVE-2024-29792] Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting (@Shivam Kamboj) [medium]
- [CVE-2024-29138] WordPress Restrict User Access <= 2.5 - Cross-Site Scripting (@Shivam Kamboj) [medium]
- [CVE-2024-28986] SolarWinds Web Help Desk < 12.8.3 - Insecure Deserialization (@rxerium) [critical] šŸ”„ (vKEV)
- [CVE-2024-24882] Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation (@riteshs4hu) [critical] šŸ”„ (vKEV)
- [CVE-2024-6753] Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting (@Shivam Kamboj) [high]
- [CVE-2024-5057] WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection (@daffainfo) [critical] šŸ”„ (vKEV)
- [CVE-2024-4455] YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting (@Shivam Kamboj) [high]
- [CVE-2024-3469] GP Premium <= 2.4.0 - Cross-Site Scripting (@Shivam Kamboj) [medium]
- [CVE-2023-33193] Emby Server - Authentication Bypass (@daffainfo) [critical] šŸ”„ (vKEV)
- [CVE-2023-27351] PaperCut NG - Authentication Bypass (@daffainfo, @jjcho) [high] šŸ”„ (vKEV)
- [CVE-2022-27924] Zimbra Collaboration Suite - Memcached Command Injection (@rxerium) [high] šŸ”„ (vKEV)
- [CVE-2022-4940] WCFM Membership <= 2.10.0 - Broken Access Control (@0xanis) [high]
- [CVE-2021-36754] PowerDNS Authoritative Server - Denial of Service (@daffainfo) [high]
- [CVE-2021-28799] QNAP HBS 3 - Broken Access Control (@daffainfo) [critical] šŸ”„ (vKEV)
- [CVE-2021-24213] GiveWP <= 2.9.7 - Cross-Site Scripting (@Shivam Kamboj) [medium]
- [CVE-2021-4448] Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization (@daffainfo) [high]
- [CVE-2020-13125] Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass (@daffainfo) [high]
- [CVE-2019-15823] WPS Hide Login <= 1.5.2.2  - Login Page Bypass (@pussycat0x) [high]
- [CVE-2019-11253] Kubernetes API Server - YAML Parsing DoS (Billion Laughs) (@ritikchaddha) [high] šŸ”„
- [CVE-2018-10245] AWStats <= 7.5 - Full Path Disclosure (@0x_Akoko) [medium]
- [CVE-2018-9206] Blueimp jQuery-File-Upload v9.22.0 - Unrestricted File Upload (@thewindghost) [critical] šŸ”„ (vKEV)
- [CVE-2018-8011] Apache HTTP Server - NULL Pointer Dereference (@daffainfo) [high]
- [CVE-2018-6961] VMware NSX SD-WAN Edge - Command Injection (@D3nverNg, @thewindghost) [critical] šŸ”„ (vKEV)
- [CVE-2017-20192] Formidable Forms < 2.05.02 - Cross-Site Scripting (@0xanis) [medium]
- [CVE-2017-11107] phpLDAPadmin <= 1.2.3 - Reflected XSS (@0x_Akoko) [medium]
- [CVE-2016-15043] WP Mobile Detector <= 3.5 - Unrestricted File Upload (@D3nverNg, @thewindghost) [critical] šŸ”„ (vKEV)
- [CVE-2016-15041] MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting (@flame) [high]
- [CVE-2012-10018] WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Stored XSS via SVG File Upload (@KrE80r) [high]
- [CVE-2011-3600] Apache OFBiz - XML External Entity Injection (@daffainfo, @pikpikcu) [high]
- [CVE-2006-3392] Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure (@s4e-io) [medium]
- [gcloud-service-account-keys-rotation] GCP Service Account Keys - No Rotation Configured (@kelu27) [high]
- [cloudinary-csp-bypass] Content-Security-Policy Bypass - cloudinary (@pussycat0x) [medium]
- [bitbucket-panel] Bitbucket Panel - Detect (@Shivam Kamboj) [info]
- [ekoapi-admin-panel] EkoAPI Admin Panel - Detect (@rxerium) [info]
- [librechat-login-panel] LibreChat Login Panel - Detection (@Kazgangap) [info]
- [victoriametrics-panel] VictoriaMetrics Panel - Detect (@Shivam Kamboj) [info]
- [woodpecker-ci-panel] Woodpecker CI Panel - Detect (@Shivam Kamboj) [info]
- [xspeeder-login] XSpeeder Login - Detect (@rxerium) [info]
- [bash-config-exposure] Bash Configuration - Exposure (@theamanrawat) [low]
- [exposed-gitmodules] .gitmodules File Exposed (@pussycat0x) [high]
- [flow-config-exposure] Flow Configuration - Exposure (@theamanrawat) [medium]
- [grafana-metrics-exposure] Grafana Metrics Endpoint - Information Disclosure (@0x_Akoko) [low]
- [jfrog-artifactory-build-exposure] JFrog Artifactory Build - Exposure (@theamanrawat) [medium]
- [keycloak-admin-console-config] Keycloak Admin Console Configuration Disclosure (@0x_Akoko) [low]
- [makefile-exposure] Makefile - Exposure (@0x_Akoko) [low]
- [mysql-config-exposure] MySQL Conifg - Exposure (@theamanrawat) [high]
- [prettier-ignore-disclosure] Prettier - Ignore File Disclosure (@ritikchaddha) [info]
- [smtp-credentials-exposure] SMTP Credentials Exposure - Detection (@pussycat0x) [high]
- [jolokia-config-exposure] Jolokia Configuration - Exposure (@theamanrawat) [medium]
- [kcfinder-exposure] KCFinder - Exposure (@theamanrawat) [high]
- [npmignore-disclosure] NPM .npmignore File Disclosure (@0x_Akoko) [info]
- [postgres-credentials-exposure] PostgreSQL Credentials - Exposure (@theamanrawat) [high]
- [python-requirements-disclosure] Python Requirements File Disclosure (@0x_Akoko) [low]
- [rails-history-exposure] Rails/Ruby Console History - Exposure (@theamanrawat) [medium]
- [oracle-ebs-sqllog-exposure] Oracle EBS SQL Log - Exposure (@theamanrawat) [medium]
- [wp-enable-media-replace-log] WordPress Plugin Enable Media Replace - Log File Exposure (@DhiyaneshDk) [medium]
- [wp-newsletter-log-exposure] WordPress Newsletter - Log File Exposure (@pussycat0x) [medium]
- [flock-safety-camera-panel] Flock Safety Camera Admin Panel - Detect (@inokii) [info]
- [aem-jcr-exposure] Adobe AEM JCR Compare Exposure (@pussycat0x) [medium]
- [bitrix-fpd] Bitrix Path Disclosure (@DhiyaneshDk) [low]
- [drupal-directory-listing] Drupal Directory Listing (@ritikchaddha) [low]
- [grafana-unauth-access] Grafana Unauthenticated Access (@ritikchaddha) [high]
- [icinga-dashboard-exposure] Icinga Exposed Dashboard (@DhiyaneshDk) [medium]
- [imageresizer-debug-exposure] ImageResizer Debug - Information Exposure (@ritikchaddha) [low]
- [roundcube-installer-exposure] Roundcube Webmail Installer - Exposure (@theamanrawat) [high]
- [jboss-jmx-console-unauth] JBoss JMX Console - Unauthenticated Access (@0x_Akoko) [high]
- [joomla-fpd] Joomla! - Full Path Disclosure (@pussycat0x) [low]
- [mamp-phpinfo-exposure] MAMP - PHP Info Exposure (@0x_Akoko) [low]
- [phpmyadmin-fpd] phpMyAdmin Full Path Disclosure (@DhiyaneshDk) [low]
- [renovate-config-exposure] Renovate Configuration Exposure (@ritikchaddha) [info]
- [wordfence-config-disclosure] WordPress Wordfence - Configuration File Disclosure (@ritikchaddha) [medium]
- [wordpress-elementor-fpd] WordPress Elementor Page Builder - Full Path Disclosure (@DhiyaneshDk) [low]
- [wordpress-menu-image-fpd] WordPress Menu Image - Full Path Disclosure (@DhiyaneshDk) [low]
- [wordpress-twentynineteen-fpd] WordPress Twenty Nineteen - Full Path Disclosure (@pussycat0x) [low]
- [wp-better-wp-security-fpd] WordPress Plugin iThemes Security - Full Path Disclosure (@DhiyaneshDk) [low]
- [wp-custom-post-type-ui-fpd] WordPress Custom Post Type UI - Full Path Disclosure (@0x_Akoko) [low]
- [wp-elementor-pro-fpd] WordPress Elementor Pro - Full Path Disclosure (@DhiyaneshDk) [low]
- [wp-members-log-disclosure] WordPress Members Plugin - Debug/Error Log Disclosure (@ritikchaddha) [low]
- [wp-nextgen-gallery-log] WordPress Gallery Plugin / NextGEN Gallery (nextgen-gallery) Error Log Disclosure (@DhiyaneshDk) [low]
- [wp-popup-maker-fpd] Popup Maker - Full Path Disclosure (@theamanrawat) [low]
- [wp-simple-custom-css-fpd] WordPress Simple Custom CSS Plugin - Full Path Disclosure (@0x_Akoko) [low]
- [wp-user-role-editor-fpd] User Role Editor - Full Path Disclosure (@theamanrawat) [low]
- [adonisjs-detect] AdonisJS - Detect (@rxerium) [info]
- [newrelic-rum-detect] New Relic Browser Monitoring (RUM) - Tech Detect (@Shivam Kamboj) [info]
- [wordpress-passive-detection] WordPress Passive Detection - Plugins & Themes (@princechaddha) [info]
- [acme-challenge-path-xss] ACME Challenge Path - Reflected Cross-Site Scripting (@pussycat0x) [low]
- [magento-downloader-fpd] Magento Downloader - Full Path Disclosure (@0x_Akoko) [low]
- [jetpack-stored-xss] Jetpack < 6.5 - Stored Cross-Site Scripting (@0x_Akoko) [medium]
- [wp-instagram-feed-xss] Instagram Feed < 1.6 - Cross-Site Scripting (@theamanrawat) [medium]
- [wp-jetpack-ssrf] Wordpress Jetpack plugin - Server Side Request Forgery (@pussycat0x) [medium]

## New Contributors
* @todb made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14518
* @Eren-Akdag made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14686
* @thewindghost made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14626
* @D3nverNg made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14674
* @rodtvs made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14748
* @m4sh-wacker made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14752
* @segunakinfenwa-sketch made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14776
* @louay-075 made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14650
* @flame-11 made their first contribution in https://github.com/projectdiscovery/nuclei-templates/pull/14560

**Full Changelog**: https://github.com/projectdiscovery/nuclei-templates/compare/v10.3.6...v10.3.7