Cve

3 posts
2026

CVE-2026-49344 Mercator : Leak PII via JSON DSL

PII Extraction via JSON DSL query For PoC, check my github : https://github.com/hadhub/CVE-2026-49344-Mercator-JSON-DSL The advisory : …
Read more

CVE-2026-49345 Mercator : SSRF To Conditional RCE

SSRF inside Provider feature For PoC, check my github : https://github.com/hadhub/CVE-2026-49345-Mercator-SSRF The advisory : …
Read more

CVE-2026-27639 Mercator : Account Takeover via Stored XSS

Description A low-privileged user (with the User role) can achieve a full administrator account takeover on Mercator by injecting a …
Read more