CVE-2026-31049
CVSS Score
9.8
EPSS Score
0.1%
EPSS Percentile
28th
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
| Vendor | n/a |
| Product | n/a |
| Published | Apr 14, 2026 |
| Last Updated | Apr 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a n/a
Be the first to know when new critical vulnerabilities affecting n/a n/a are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / n/a
n/a
References
hostbillapp.com: https://hostbillapp.com/changelog hostbillapp.com: https://hostbillapp.com/release-notes/11-27-2025.html blog.hostbillapp.com: https://blog.hostbillapp.com/2025/12/03/hostbill-security-advisory/ hostbillapp.com: https://hostbillapp.com/responsible-disclosure hostbillapp.com: https://hostbillapp.com/release-notes/12-01-2025.html github.com: https://github.com/Muhammad5235/HostBill-CVEs-2025/blob/main/Missing%20Server-Side%20Validation/Registration%20fields%20%26%20Import%20Csv