|
CVE-2026-57321
|
|
Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.
Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.
|
High
|
Cwe 22
|
il y a 2 mois
|
|
CVE-2026-57316
|
|
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
|
Medium
|
Cwe 497
|
il y a 2 mois
|
|
CVE-2026-57633
|
|
Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions.
Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions.
|
Medium
|
Cwe 497
|
il y a 2 mois
|
|
CVE-2026-56060
|
|
Vulnérabilité dans CVE-2026-56060 (CVE-2026-56060)
vulnérabilité dans CVE-2026-56060 (CVE-2026-56060). Des informations confidentielles peuvent être exposées.
|
High
|
Cwe 497
|
il y a 2 mois
|
|
CVE-2026-56027
|
|
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
|
Critical
|
Cwe 434
|
il y a 2 mois
|
|
CVE-2026-56058
|
|
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
|
Critical
|
Cwe 434
|
il y a 2 mois
|
|
CVE-2026-56059
|
|
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
|
Critical
|
Cwe 434
|
il y a 2 mois
|
|
CVE-2026-56034
|
|
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-56036
|
|
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-56064
|
|
Subscriber SQL Injection in Tourfic <= 2.22.5 versions.
Subscriber SQL Injection in Tourfic <= 2.22.5 versions.
|
High
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-56062
|
|
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-56039
|
|
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56040
|
|
Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56043
|
|
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56041
|
|
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56047
|
|
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56044
|
|
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56045
|
|
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56046
|
|
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
|
Medium
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-56029
|
|
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
|
High
|
Cwe 288
|
il y a 2 mois
|
|
CVE-2026-56038
|
|
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
|
High
|
Privilege Escalation
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-56061
|
|
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-56063
|
|
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-56032
|
|
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
|
Critical
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-56055
|
|
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-56031
|
|
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-56057
|
|
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
|
Critical
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-56026
|
|
Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.
Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.
|
Medium
|
Server-Side Request Forgery
Cwe 918
|
il y a 2 mois
|
|
CVE-2026-56066
|
|
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
|
Medium
|
Cwe 22
|
il y a 2 mois
|
|
CVE-2026-3472
|
|
Vulnérabilité dans mattermost (CVE-2026-3472)
vulnérabilité dans mattermost (CVE-2026-3472). Risque d'opérations non autorisées ou de divulgation.
|
Low
|
Cwe 693
Mattermost
Mattermost Server
|
il y a 2 mois
|
|
CVE-2026-30041
|
|
Vulnérabilité dans dos (CVE-2026-30041)
vulnérabilité dans dos (CVE-2026-30041). Risque d'opérations non autorisées ou de divulgation.
|
High
|
Denial of Service
Cwe 400
|
il y a 2 mois
|
|
CVE-2026-54840
|
|
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-54847
|
|
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-54837
|
|
Vulnérabilité dans CVE-2026-54837 (CVE-2026-54837)
vulnérabilité dans CVE-2026-54837 (CVE-2026-54837). Des informations confidentielles peuvent être exposées.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-54835
|
|
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-56025
|
|
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-54846
|
|
Vulnérabilité dans CVE-2026-54846 (CVE-2026-54846)
vulnérabilité dans CVE-2026-54846 (CVE-2026-54846). Des informations confidentielles peuvent être exposées.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-52701
|
|
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
|
Medium
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-54832
|
|
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-4339
|
|
SSRF (Falsification de requête côté serveur) dans ssrf (CVE-2026-4339)
SSRF dans ssrf (CVE-2026-4339). Des informations confidentielles peuvent être exposées.
|
Medium
|
Server-Side Request Forgery
Cwe 918
Mattermost
Mattermost Server
|
il y a 2 mois
|
|
CVE-2026-54820
|
|
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-54825
|
|
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-54831
|
|
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-54827
|
|
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
|
Critical
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-56011
|
|
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-54824
|
|
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
|
High
|
Cwe 497
|
il y a 2 mois
|
|
CVE-2026-54833
|
|
Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
|
High
|
Cwe 321
|
il y a 2 mois
|
|
CVE-2026-45256
|
|
Élévation de privilèges dans dos (CVE-2026-45256)
vulnérabilité dans dos (CVE-2026-45256). Risque d'opérations non autorisées ou de divulgation.
|
Medium
|
Denial of Service
Cwe 269
FreeBSD
|
il y a 2 mois
|
|
CVE-2025-64637
|
|
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
|
Medium
|
Cwe 80
|
il y a 2 mois
|
|
CVE-2025-68052
|
|
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
|
High
|
Cross-Site Request Forgery
Cwe 352
|
il y a 2 mois
|