Skip to content

Known CVE

DbGate - Remote Code Execution via Dynamic Import Bypass

DbGate versions <= 7.1.8 are vulnerable to authenticated remote code execution via the POST /runners/load-reader endpoint. The functionName parameter is directly interpolated into a JavaScript code template without sanitization. The require=null mitigation is bypassed via dynamic import().

CVE-2026-47670

Critical2026CVSS 9.4CWE-77

cve2026 · dbgate · rce · vuln · auth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website