Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2026-42440 Vulnerability in org.apache.opennlp:opennlp-tools (CVE-2026-42440)
vulnerability in org.apache.opennlp:opennlp-tools (CVE-2026-42440). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-M3` or later.
CVE-2026-41471 Vulnerability in wordpress (CVE-2026-41471)
vulnerability in wordpress (CVE-2026-41471). Confidential information can be exposed externally.
CVE-2026-32834 Vulnerability in wordpress (CVE-2026-32834)
vulnerability in wordpress (CVE-2026-32834). Confidential information can be exposed externally.
CVE-2026-40075 Path Traversal in org.openmrs.web:openmrs-web (CVE-2026-40075)
path traversal in org.openmrs.web:openmrs-web (CVE-2026-40075). Confidential information can be exposed externally. Exploitable via ``ModuleResourcesServlet``. Mitigation: upgrade to `2.8.6` or later.
CVE-2026-6229 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-6229)
SSRF in wordpress (CVE-2026-6229). Risk of unauthorized operations or information disclosure.
CVE-2026-41654 Vulnerability in weblate (CVE-2026-41654)
vulnerability in weblate (CVE-2026-41654). Confidential information can be exposed externally. Exploitable via ``project.add``. Mitigation: upgrade to `5.17.1` or later.
CVE-2026-41940 KEV [KEV] Vulnerability in Webpros cpanel-whm-and-wp2-wordpress-squared (CVE-2026-41940)
vulnerability in Webpros cpanel-whm-and-wp2-wordpress-squared (CVE-2026-41940). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-44015 SSRF (Server-Side Request Forgery) in github.com/0xJacky/Nginx-UI (CVE-2026-44015)
SSRF in github.com/0xJacky/Nginx-UI (CVE-2026-44015). Confidential information can be exposed externally. Exploitable via `GET /api/settings`.
CVE-2026-41603 Vulnerability in apache (CVE-2026-41603)
vulnerability in apache (CVE-2026-41603). Confidential information can be exposed externally.
CVE-2026-41604 Out-of-Bounds Read in apache (CVE-2026-41604)
vulnerability in apache (CVE-2026-41604). Risk of unauthorized operations or information disclosure.
CVE-2026-41605 Vulnerability in apache (CVE-2026-41605)
vulnerability in apache (CVE-2026-41605). Risk of unauthorized operations or information disclosure.
CVE-2025-48431 Vulnerability in apache (CVE-2025-48431)
vulnerability in apache (CVE-2025-48431). Risk of unauthorized operations or information disclosure.
CVE-2026-41602 Vulnerability in apache (CVE-2026-41602)
vulnerability in apache (CVE-2026-41602). Risk of unauthorized operations or information disclosure.
CVE-2026-40973 Vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973)
vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973). Successful exploitation can lead to full system takeover. Exploitable via ``ApplicationTemp``.
CVE-2026-40972 Vulnerability in spring (CVE-2026-40972)
vulnerability in spring (CVE-2026-40972). Successful exploitation can lead to full system takeover.
CVE-2026-40022 Vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022)
vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022). Confidential information can be exposed externally. Mitigation: upgrade to `4.20.0` or later.
CVE-2026-27172 Unsafe Deserialization in apache (CVE-2026-27172)
vulnerability in apache (CVE-2026-27172). Successful exploitation can lead to full system takeover.
CVE-2026-40858 Unsafe Deserialization in apache (CVE-2026-40858)
vulnerability in apache (CVE-2026-40858). Successful exploitation can lead to full system takeover.
CVE-2026-40048 Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
CVE-2026-40473 Unsafe Deserialization in apache (CVE-2026-40473)
vulnerability in apache (CVE-2026-40473). Successful exploitation can lead to full system takeover.
CVE-2026-40466 Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
CVE-2026-41044 Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
CVE-2026-40542 Vulnerability in apache (CVE-2026-40542)
vulnerability in apache (CVE-2026-40542). Risk of unauthorized operations or information disclosure.
CVE-2026-5718 Unrestricted File Upload in wordpress (CVE-2026-5718)
vulnerability in wordpress (CVE-2026-5718). Successful exploitation can lead to full system takeover.
CVE-2026-34197 KEV [KEV] Vulnerability in Apache activemq (CVE-2026-34197)
vulnerability in Apache activemq (CVE-2026-34197). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-40316 OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflo...
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with...
CVE-2026-33715 Vulnerability in symfony (CVE-2026-33715)
vulnerability in symfony (CVE-2026-33715). Risk of unauthorized operations or information disclosure.
CVE-2026-34481 Vulnerability in apache (CVE-2026-34481)
vulnerability in apache (CVE-2026-34481). Data can be tampered with by attackers.
CVE-2026-39304 Vulnerability in activemq (CVE-2026-39304)
vulnerability in activemq (CVE-2026-39304). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.4, 6.2.4` or later.
CVE-2026-34486 KEV [KEV] Vulnerability in Apache tomcat (CVE-2026-34486)
vulnerability in Apache tomcat (CVE-2026-34486). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `9.0.117, 10.1.54, 11.0.21` or later.
CVE-2026-29146 Vulnerability in apache (CVE-2026-29146)
vulnerability in apache (CVE-2026-29146). Confidential information can be exposed externally.
CVE-2026-39976 Authentication Bypass in laravel (CVE-2026-39976)
authentication bypass in laravel (CVE-2026-39976). Confidential information can be exposed externally. Mitigation: upgrade to `13.7.1` or later.
CVE-2026-4326 The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate...
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check...
CVE-2026-5436 Path Traversal in wordpress (CVE-2026-5436)
path traversal in wordpress (CVE-2026-5436). Successful exploitation can lead to full system takeover.
CVE-2026-39362 SSRF (Server-Side Request Forgery) in django (CVE-2026-39362)
SSRF in django (CVE-2026-39362). Data can be tampered with by attackers. Mitigation: upgrade to `1.2.7` or later.
CVE-2026-23869 Vulnerability in react (CVE-2026-23869)
vulnerability in react (CVE-2026-23869). Risk of unauthorized operations or information disclosure.
CVE-2026-3243 The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
CVE-2026-39466 SQL Injection in wordpress (CVE-2026-39466)
SQL injection in wordpress (CVE-2026-39466). Confidential information can be exposed externally.
CVE-2026-4808 Unrestricted File Upload in wordpress (CVE-2026-4808)
vulnerability in wordpress (CVE-2026-4808). Successful exploitation can lead to full system takeover.
CVE-2026-4338 Vulnerability in wordpress (CVE-2026-4338)
vulnerability in wordpress (CVE-2026-4338). Confidential information can be exposed externally.
CVE-2026-3499 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-3499)
vulnerability in wordpress (CVE-2026-3499). Successful exploitation can lead to full system takeover.
CVE-2026-39371 Cross-Site Request Forgery (CSRF) in react (CVE-2026-39371)
vulnerability in react (CVE-2026-39371). Data can be tampered with by attackers. Mitigation: upgrade to `1.0.6` or later.
CVE-2026-35554 Vulnerability in apache (CVE-2026-35554)
vulnerability in apache (CVE-2026-35554). Confidential information can be exposed externally.
CVE-2019-25673 Unrestricted File Upload in laravel (CVE-2019-25673)
vulnerability in laravel (CVE-2019-25673). Successful exploitation can lead to full system takeover.
CVE-2019-25671 Path Traversal in c (CVE-2019-25671)
path traversal in c (CVE-2019-25671). Successful exploitation can lead to full system takeover.
CVE-2026-5577 Vulnerability in flask (CVE-2026-5577)
vulnerability in flask (CVE-2026-5577). Risk of unauthorized operations or information disclosure.
CVE-2026-2936 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2936)
cross-site scripting in wordpress (CVE-2026-2936). Risk of unauthorized operations or information disclosure.
CVE-2026-3666 Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
CVE-2026-1233 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing...
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TT...
CVE-2026-3445 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass i...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →