Project Black
First CVE: Feb 18, 2026Active for: 1 year
12
CVEs Published
More CVEs Published than 30% of tracked CNAs
12.0
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 33% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Project Black over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2026
5 months ago
Most Recent CVE
Jul 4, 2026
20 days ago
Top CVEs
All CVEs published by Project Black as a CNA, regardless of affected vendor or product.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12196HIGH HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts | Jul 4, 2026 | 8.3 | 37 | NO | NO |
CVE-2026-12195HIGH myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting | Jul 4, 2026 | 8.5 | 36 | NO | NO |
CVE-2026-8208HIGH Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user | May 9, 2026 | 8.9 | 33 | NO | NO |
CVE-2025-15586CRITICAL OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without k | Feb 19, 2026 | 10.0 | 30 | NO | NO |
CVE-2026-8209MEDIUM Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction result | May 9, 2026 | 6.9 | 28 | NO | NO |
CVE-2026-8207HIGH Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874a | May 9, 2026 | 7.0 | 28 | NO | NO |
CVE-2026-6204HIGH LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful e | Apr 13, 2026 | 7.2 | 28 | NO | NO |
CVE-2026-12673MEDIUM Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modi | Jun 20, 2026 | 5.9 | 25 | NO | NO |
CVE-2025-15585MEDIUM Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to u | Feb 19, 2026 | 6.7 | 23 | NO | NO |
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file | Jul 4, 2026 | 2.3 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA12 CVEs
8%
42%
42%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low5 (41.7%)
High6 (50.0%)
None1 (8.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Project Black as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Project Black as a CNA — matched by CVE ID, not by organization name.