CVEs for: ['2026-07-23']

CVE-2025-68081Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2025-71389Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.
CVE-2026-10697Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-12353An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
CVE-2026-15037Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
CVE-2026-15611Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
CVE-2026-15612Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.
CVE-2026-15614Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
CVE-2026-15615Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.
CVE-2026-15616Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
CVE-2026-15617Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.
CVE-2026-15966Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-15967Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-15968Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
CVE-2026-16287Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.
CVE-2026-16723A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
CVE-2026-16733A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-16735A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-16756Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
CVE-2026-16763A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-16764A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.
CVE-2026-16767A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-16768A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.
CVE-2026-21653Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
CVE-2026-21655Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
CVE-2026-21723The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
CVE-2026-24537Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
CVE-2026-24552Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.
CVE-2026-24628Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
CVE-2026-24639Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVE-2026-25800Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buffer overhead, enabling memory exhaustion. Version 0.11.15 fixes the issue.
CVE-2026-27064Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-27355Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
CVE-2026-27403Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
CVE-2026-38764An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
CVE-2026-39155Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.
CVE-2026-40430Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
CVE-2026-43820NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
CVE-2026-43823When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.
CVE-2026-44210Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue.
CVE-2026-47668DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.
CVE-2026-47669DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.
CVE-2026-47769APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSlug/:eventName` endpoint accepts arbitrary unauthenticated JSON and stores it in Redis and the `webhook_events` PostgreSQL table without any signature check or authentication requirement. The root cause is that `createWebhookRouter` is called at `server.ts:188` without a `validators` map, so `receivers.ts:80`'s optional-chaining guard evaluates to `undefined` and the signature-validation block (`receiver.ts:81–95`) is unconditionally skipped. Any unauthenticated network client that knows a valid server slug can inject arbitrary payloads, which are subsequently served as trusted resource state to legitimate MCP clients. Commit 7f19b52280f414f57af2b79a95333d1c8fbeece5 patches the issue.
CVE-2026-48012Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's `Referer` header and uses that value as the redirect destination. In the validated behavior, the server does not restrict that fallback target to same-origin URLs, does not require a relative path, and does not reject dangerous schemes such as `javascript:`. As a result, an unauthenticated request can turn this endpoint into a reusable redirect primitive whose destination is fully controlled by attacker-supplied request metadata. The security problem is not limited to a harmless navigation mismatch. The endpoint sits under `/api/oauth/`, which gives the redirect a trustworthy application-controlled origin and makes it suitable for phishing chains, branded redirect abuse, and cases where client software automatically follows redirects issued by a trusted host. The attached evidence also shows that the response is not only an HTTP `302` with a user-controlled `Location` header. The HTML body contains a matching meta refresh tag and redirect link built from the same attacker-controlled value. In the validated proof, the endpoint redirects to `https://attacker.example/poc` when that URL is supplied through `Referer`, and it also reflects `javascript:alert(1)` into `Location` and the HTML redirect body without any scheme filtering. This report therefore stays conservative and claims an open redirect with arbitrary redirect targets, while noting that the lack of scheme restrictions makes the behavior materially worse than a same-scheme external redirect. Version 6.7.10.1 fixes the issue.
CVE-2026-48013Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates target IPs against private/reserved ranges via `FileUrlValidator`, the `linkURL` flow only performs a URL format check (regex for `http://` or `https://` prefix), allowing SSRF to internal network services and cloud metadata endpoints. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
CVE-2026-49035The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
CVE-2026-52439An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism
CVE-2026-57370Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
CVE-2026-57373Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
CVE-2026-57374Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-57384Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
CVE-2026-57427Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
CVE-2026-57428Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
CVE-2026-57696Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
CVE-2026-57699Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
CVE-2026-57701Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
CVE-2026-57703Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
CVE-2026-57704Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
CVE-2026-57716Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
CVE-2026-57717Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
CVE-2026-57767Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CVE-2026-57769Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
CVE-2026-59513Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
CVE-2026-59514Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-59517Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-59522Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-59524Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
CVE-2026-59525Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-59526Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59540Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVE-2026-59541Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVE-2026-59542Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVE-2026-59543Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVE-2026-59544Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVE-2026-59545Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-61943Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61944Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61946Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
CVE-2026-61947Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-61948Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61949Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61950Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-61951Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61954Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61972Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61973Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61981Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
CVE-2026-62234Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers.
CVE-2026-63359The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
CVE-2026-637329router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host header to reach local-only routes, and register a malicious MCP plugin (e.g. node -e <payload>) to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.
CVE-2026-6390A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
CVE-2026-65449Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
CVE-2026-65450Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65451Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65452Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65453Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65454Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
CVE-2026-65455Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-65458Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
CVE-2026-65460Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
CVE-2026-65461Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
CVE-2026-65462Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
CVE-2026-65463Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
CVE-2026-65464Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
CVE-2026-65465Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
CVE-2026-65466Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
CVE-2026-65467Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
CVE-2026-65468Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
CVE-2026-65469Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
CVE-2026-65470Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
CVE-2026-65471Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
CVE-2026-65472Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
CVE-2026-65473Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
CVE-2026-65474Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
CVE-2026-65475Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
CVE-2026-65476Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
CVE-2026-65477Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-65478Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
CVE-2026-65479Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-65480Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.
CVE-2026-65481Contributor Local File Inclusion in Vino <= 1.9 versions.
CVE-2026-65482Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
CVE-2026-65483Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
CVE-2026-65484Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
CVE-2026-65485Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65486Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65487Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
CVE-2026-65488Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
CVE-2026-65489Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
CVE-2026-65490Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
CVE-2026-65491Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65492Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
CVE-2026-65493Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-65494Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-65495Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVE-2026-65496Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
CVE-2026-65497Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
CVE-2026-65498Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
CVE-2026-65499Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65510Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65512Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.
CVE-2026-65514Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65516Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65518Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-65519Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-65521Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-65524Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65525Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65526Contributor SQL Injection in Visualizer <= 4.0.6 versions.
CVE-2026-65527Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65528Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
CVE-2026-65529Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
CVE-2026-65530Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-65531Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65533Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65534Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65535Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65536Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65537Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65538Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65539Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65540Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65550Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
CVE-2026-65761Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
CVE-2026-65762Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65763Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-6924A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
CVE-2026-7120@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.
CVE-2026-8287Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026.