VulnCheck batch (11 Oct): Wukong HRM lets anyone act as HR admin with no login (CVSS 9.3), ImageMagick on Windows can run a planted Ghostscript program (7.3), plus CordysCRM, ConvertX, MultiVendorX and other access-control flaws; most have no fix yet
VulnCheck published a batch of about 20 CVEs on 11 October 2026 (CVE-2026-108688 to CVE-2026-108708), mostly broken access-control bugs in open-source business apps. The worst is CVE-2026-108707 in Wukong_HRM, an open-source HR system: its ParamAspect check is skipped when a request simply leaves out the AUTH-TOKEN header, so an attacker with no account can call every HR API as an HR administrator, read payslips, salary history and employee personal data, download attachments, and change or delete company-wide HR records (CVSS 4.0 9.3; CVSS 3.1 9.8). A second Wukong_HRM bug, CVE-2026-108708 (8.7), gives every logged-in caller the HR administrator role, so any low-privileged employee can read payslips, salary and bank-card details and delete employees, departments and contracts company-wide. Both affect code up to commit 186115e and no fixed release is listed. CVE-2026-108693 hits ImageMagick on Windows up to 7.1.2-33 and 6.9.13-58: when Ghostscript isn't registered, ImageMagick launches gswin64c.exe by bare name, so a malicious file of that name placed in the working directory runs with ImageMagick's privileges when PDF, PostScript or EPS files are converted (CVSS 4.0 7.3). 7.1.2-33, released 10 October, is the latest build, so no fixed version exists yet. Others: ConvertX up to 0.19.0 lets logged-in users read server files because it runs Pandoc without --sandbox (CVE-2026-108694, 7.1); the MultiVendorX WordPress plugin up to 5.0.19 lets vendor (store owner) accounts overwrite marketplace-wide commission, payout and onboarding settings through its settings REST endpoint (CVE-2026-108695, 7.1); 1Panel-dev CordysCRM has eight access-control flaws, three fixed in 1.9.2 (CVE-2026-108692 and -108700, 7.1; -108701, 5.3) and five still open in 1.9.3, including a webhook test that allows blind server-side request forgery (CVE-2026-108702 to -108705, 5.3); and lower-rated bugs in eladmin, mall4j, CoreShop and Wukong AICRM. No exploitation has been reported. Primary: CVE records from VulnCheck as CNA.
- Product
- Wukong_HRM; ImageMagick on Windows; ConvertX; MultiVendorX (WordPress); 1Panel-dev CordysCRM; eladmin; mall4j; CoreShop; Wukong AICRM
- Versions
- Wukong_HRM through commit 186115e; ImageMagick 7.0.0-0 to 7.1.2-33 and 6.9.13-58 and earlier (Windows); ConvertX through 0.19.0; MultiVendorX through 5.0.19; CordysCRM before 1.9.2 (three CVEs) and through 1.9.3 (five CVEs); eladmin through 2.7 / commit 55fbf70; mall4j through 4.0; CoreShop through 1.5.5; Wukong AICRM through 20260610
- CVSS
- Wukong_HRM CVE-2026-108707 9.3 (CVSS 4.0) / 9.8 (3.1); CVE-2026-108708 8.7; ImageMagick CVE-2026-108693 7.3; ConvertX 7.1; MultiVendorX 7.1; CordysCRM 7.1 / 5.3; others 5.3 (all CVSS 4.0, VulnCheck)
- Exploited in Australia?
- unknown
- Patch to
- CordysCRM: upgrade to 1.9.2 or later for CVE-2026-108692/-108700/-108701 (the 1.9.3 issues have no listed fix yet). Wukong_HRM, ImageMagick (Windows), ConvertX, MultiVendorX, eladmin, mall4j, CoreShop, Wukong AICRM: no fixed release listed. Until fixes ship, keep Wukong_HRM off the internet or behind an authenticating proxy; on Windows, register Ghostscript properly (or set its full path in delegates.xml) and run ImageMagick conversions from a directory users cannot write to; run ConvertX only for trusted users
Primary: CVE.org — CVE-2026-108707 Wukong_HRM authentication bypass via ParamAspect (VulnCheck CNA, published 11 Oct 2026) · Vendor: VulnCheck advisory — Wukong_HRM through commit 186115e authentication bypass · CVE: CVE-2026-108688, CVE-2026-108708, CVE-2026-108707, CVE-2026-108693, CVE-2026-108694, CVE-2026-108695, CVE-2026-108692, CVE-2026-108702 · VulnCheck advisory — ImageMagick (Windows) uncontrolled search path via Ghostscript delegate, CVE-2026-108693
