Nicolas Krassas[verified]@DinosnDisclosure
The post discloses an XXE vulnerability (CVE‑2026‑32251) that allows reading /etc/passwd in Tolgee’s cloud platform, includes a high CVSS score, and links to a writeup containing a PoC, but no evidence of active exploitation or patches.
Vivek | Cybersecurity[verified]@VivekIntelDisclosure
The post announces a CVE-2026-32251 exploit in Tolgee's XML translation import that permits arbitrary file reads via XXE; a proof of concept is linked to a writeup.
CVE@CVEnewPatch
The post highlights that Tolgee’s XML parsing before version 3.166.3 fails to disable external entities, implying a vulnerability that is likely addressed in 3.166.3.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces the discovery of an XML External Entity (XXE) vulnerability (CVE‑2026‑32251) in the Tolgee Localization Platform and provides links to detailed notes, but it contains no PoC, exploit, or patch information.
0day Signal@0dayPublishingDisclosure
The post announces the discovery of CVE-2026-32251, a server-side XSS vulnerability in Tolgee that allows filesystem access and SSRF, with a link presumably containing a PoC but no active exploitation or patch info.