| CVE-2025-68081 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |
| CVE-2025-71389 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency. |
| CVE-2026-10697 | Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. |
| CVE-2026-12353 | An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary. |
| CVE-2026-15037 | Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12. |
| CVE-2026-15611 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. |
| CVE-2026-15612 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. |
| CVE-2026-15614 | Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window. |
| CVE-2026-15615 | Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely. |
| CVE-2026-15616 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. |
| CVE-2026-15617 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. |
| CVE-2026-15966 | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. |
| CVE-2026-15967 | Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. |
| CVE-2026-15968 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. |
| CVE-2026-16287 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection.
This issue affects pardus-update: from 0.6.6 before 0.7.0. |
| CVE-2026-16723 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. |
| CVE-2026-16733 | A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-16735 | A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-16756 | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks.
To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later. |
| CVE-2026-16763 | A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-16764 | A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed. |
| CVE-2026-16767 | A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
| CVE-2026-16768 | A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail. |
| CVE-2026-21653 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. |
| CVE-2026-21655 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586.
This issue affects victor: from 2.9 before 3.0. |
| CVE-2026-21723 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled. |
| CVE-2026-24537 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. |
| CVE-2026-24552 | Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions. |
| CVE-2026-24628 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. |
| CVE-2026-24639 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. |
| CVE-2026-25800 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buffer overhead, enabling memory exhaustion. Version 0.11.15 fixes the issue. |
| CVE-2026-27064 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. |
| CVE-2026-27355 | Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. |
| CVE-2026-27403 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS.
This issue affects Hubbub Lite: from n/a through 1.36.3. |
| CVE-2026-38764 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys |
| CVE-2026-39155 | Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service. |
| CVE-2026-40430 | Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. |
| CVE-2026-43820 | NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2. |
| CVE-2026-43823 | When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1. |
| CVE-2026-44210 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue. |
| CVE-2026-47668 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch. |
| CVE-2026-47669 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue. |
| CVE-2026-47769 | APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSlug/:eventName` endpoint accepts arbitrary unauthenticated JSON and stores it in Redis and the `webhook_events` PostgreSQL table without any signature check or authentication requirement. The root cause is that `createWebhookRouter` is called at `server.ts:188` without a `validators` map, so `receivers.ts:80`'s optional-chaining guard evaluates to `undefined` and the signature-validation block (`receiver.ts:81–95`) is unconditionally skipped. Any unauthenticated network client that knows a valid server slug can inject arbitrary payloads, which are subsequently served as trusted resource state to legitimate MCP clients. Commit 7f19b52280f414f57af2b79a95333d1c8fbeece5 patches the issue. |
| CVE-2026-48012 | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's `Referer` header and uses that value as the redirect destination. In the validated behavior, the server does not restrict that fallback target to same-origin URLs, does not require a relative path, and does not reject dangerous schemes such as `javascript:`. As a result, an unauthenticated request can turn this endpoint into a reusable redirect primitive whose destination is fully controlled by attacker-supplied request metadata. The security problem is not limited to a harmless navigation mismatch. The endpoint sits under `/api/oauth/`, which gives the redirect a trustworthy application-controlled origin and makes it suitable for phishing chains, branded redirect abuse, and cases where client software automatically follows redirects issued by a trusted host. The attached evidence also shows that the response is not only an HTTP `302` with a user-controlled `Location` header. The HTML body contains a matching meta refresh tag and redirect link built from the same attacker-controlled value. In the validated proof, the endpoint redirects to `https://attacker.example/poc` when that URL is supplied through `Referer`, and it also reflects `javascript:alert(1)` into `Location` and the HTML redirect body without any scheme filtering. This report therefore stays conservative and claims an open redirect with arbitrary redirect targets, while noting that the lack of scheme restrictions makes the behavior materially worse than a same-scheme external redirect. Version 6.7.10.1 fixes the issue. |
| CVE-2026-48013 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates target IPs against private/reserved ranges via `FileUrlValidator`, the `linkURL` flow only performs a URL format check (regex for `http://` or `https://` prefix), allowing SSRF to internal network services and cloud metadata endpoints. This issue is fixed in versions 6.6.10.18 and 6.7.10.1. |
| CVE-2026-49035 | The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled. |
| CVE-2026-52439 | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism |
| CVE-2026-57370 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. |
| CVE-2026-57373 | Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. |
| CVE-2026-57374 | Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. |
| CVE-2026-57384 | Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. |
| CVE-2026-57427 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. |
| CVE-2026-57428 | Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. |
| CVE-2026-57696 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. |
| CVE-2026-57699 | Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. |
| CVE-2026-57701 | Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. |
| CVE-2026-57703 | Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. |
| CVE-2026-57704 | Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. |
| CVE-2026-57716 | Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. |
| CVE-2026-57717 | Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. |
| CVE-2026-57767 | Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. |
| CVE-2026-57769 | Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. |
| CVE-2026-59513 | Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. |
| CVE-2026-59514 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. |
| CVE-2026-59517 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. |
| CVE-2026-59522 | Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. |
| CVE-2026-59524 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. |
| CVE-2026-59525 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. |
| CVE-2026-59526 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. |
| CVE-2026-59540 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. |
| CVE-2026-59541 | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. |
| CVE-2026-59542 | Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. |
| CVE-2026-59543 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. |
| CVE-2026-59544 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. |
| CVE-2026-59545 | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. |
| CVE-2026-61943 | Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. |
| CVE-2026-61944 | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. |
| CVE-2026-61946 | Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. |
| CVE-2026-61947 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. |
| CVE-2026-61948 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. |
| CVE-2026-61949 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. |
| CVE-2026-61950 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. |
| CVE-2026-61951 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. |
| CVE-2026-61954 | Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. |
| CVE-2026-61972 | Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. |
| CVE-2026-61973 | Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. |
| CVE-2026-61981 | Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. |
| CVE-2026-62234 | Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers. |
| CVE-2026-63359 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database. |
| CVE-2026-63732 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host header to reach local-only routes, and register a malicious MCP plugin (e.g. node -e <payload>) to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered. |
| CVE-2026-6390 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes. |
| CVE-2026-65449 | Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. |
| CVE-2026-65450 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| CVE-2026-65451 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| CVE-2026-65452 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| CVE-2026-65453 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| CVE-2026-65454 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. |
| CVE-2026-65455 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. |
| CVE-2026-65458 | Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions. |
| CVE-2026-65460 | Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. |
| CVE-2026-65461 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. |
| CVE-2026-65462 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. |
| CVE-2026-65463 | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. |
| CVE-2026-65464 | Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. |
| CVE-2026-65465 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. |
| CVE-2026-65466 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. |
| CVE-2026-65467 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. |
| CVE-2026-65468 | Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. |
| CVE-2026-65469 | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. |
| CVE-2026-65470 | Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. |
| CVE-2026-65471 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. |
| CVE-2026-65472 | Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. |
| CVE-2026-65473 | Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions. |
| CVE-2026-65474 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. |
| CVE-2026-65475 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. |
| CVE-2026-65476 | Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. |
| CVE-2026-65477 | Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. |
| CVE-2026-65478 | Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. |
| CVE-2026-65479 | Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. |
| CVE-2026-65480 | Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions. |
| CVE-2026-65481 | Contributor Local File Inclusion in Vino <= 1.9 versions. |
| CVE-2026-65482 | Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| CVE-2026-65483 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. |
| CVE-2026-65484 | Contributor Broken Access Control in Style Kits <= 2.6.5 versions. |
| CVE-2026-65485 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. |
| CVE-2026-65486 | Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. |
| CVE-2026-65487 | Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |
| CVE-2026-65488 | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| CVE-2026-65489 | Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| CVE-2026-65490 | Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions. |
| CVE-2026-65491 | Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. |
| CVE-2026-65492 | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. |
| CVE-2026-65493 | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. |
| CVE-2026-65494 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. |
| CVE-2026-65495 | Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. |
| CVE-2026-65496 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. |
| CVE-2026-65497 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| CVE-2026-65498 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. |
| CVE-2026-65499 | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-65510 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-65512 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. |
| CVE-2026-65514 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. |
| CVE-2026-65516 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-65518 | Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. |
| CVE-2026-65519 | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. |
| CVE-2026-65521 | Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. |
| CVE-2026-65524 | Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. |
| CVE-2026-65525 | Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. |
| CVE-2026-65526 | Contributor SQL Injection in Visualizer <= 4.0.6 versions. |
| CVE-2026-65527 | Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. |
| CVE-2026-65528 | Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. |
| CVE-2026-65529 | Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. |
| CVE-2026-65530 | Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. |
| CVE-2026-65531 | Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. |
| CVE-2026-65533 | Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. |
| CVE-2026-65534 | Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. |
| CVE-2026-65535 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. |
| CVE-2026-65536 | Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. |
| CVE-2026-65537 | Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. |
| CVE-2026-65538 | Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. |
| CVE-2026-65539 | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. |
| CVE-2026-65540 | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. |
| CVE-2026-65550 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system. |
| CVE-2026-65761 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. |
| CVE-2026-65762 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability. |
| CVE-2026-65763 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability. |
| CVE-2026-6924 | A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated. |
| CVE-2026-7120 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2. |
| CVE-2026-8287 | Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation.
This issue affects Online Pre-Accounting Software: through 17072026. |