|
CVE-2026-39576
|
|
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39560
|
|
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2025-69164
|
|
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-9570
|
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9570)
cross-site scripting in wordpress (CVE-2026-9570). Risk of unauthorized operations or information disclosure.
|
High
|
JavaScript
WordPress
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-9690
|
|
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
|
High
|
Cwe 22
|
2 months ago
|
|
CVE-2025-66391
|
|
Vulnerability in CVE-2025-66391 (CVE-2025-66391)
vulnerability in CVE-2025-66391 (CVE-2025-66391). Successful exploitation can lead to full system takeover.
|
High
|
Cwe 284
|
2 months ago
|
|
CVE-2026-52696
|
|
Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
|
High
|
Cwe 1258
|
2 months ago
|
|
CVE-2026-52698
|
|
Vulnerability in CVE-2026-52698 (CVE-2026-52698)
vulnerability in CVE-2026-52698 (CVE-2026-52698). Risk of unauthorized operations or information disclosure.
|
High
|
Cwe 201
|
2 months ago
|
|
CVE-2026-53876
|
|
OS Command Injection in CVE-2026-53876 (CVE-2026-53876)
OS command injection in CVE-2026-53876 (CVE-2026-53876). Successful exploitation can lead to full system takeover.
|
High
|
Cwe 78
|
2 months ago
|
|
CVE-2026-54184
|
|
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
|
High
|
Cwe 639
|
2 months ago
|
|
CVE-2026-54185
|
|
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
|
High
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-54189
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-54195
|
|
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-54192
|
|
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-54188
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-54805
|
|
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-54802
|
|
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-54804
|
|
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
|
High
|
Cwe 288
|
2 months ago
|
|
CVE-2026-8089
|
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8089)
cross-site scripting in wordpress (CVE-2026-8089). Risk of unauthorized operations or information disclosure.
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49057
|
|
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-48869
|
|
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49081
|
|
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-49073
|
|
SQL Injection in sqli (CVE-2026-49073)
SQL injection in sqli (CVE-2026-49073). Confidential information can be exposed externally.
|
High
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-49074
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-48967
|
|
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
|
High
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-48929
|
|
Authentication Bypass in rocketchat (CVE-2026-48929)
authentication bypass in rocketchat (CVE-2026-48929). Risk of unauthorized operations or information disclosure.
|
High
|
Cwe 287
Rocketchat
|
2 months ago
|
|
CVE-2026-49778
|
|
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49113
|
|
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
|
High
|
Cwe 94
|
2 months ago
|
|
CVE-2026-40754
|
|
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40753
|
|
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40726
|
|
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-40731
|
|
Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-40736
|
|
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40735
|
|
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40751
|
|
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40758
|
|
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40759
|
|
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40739
|
|
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40768
|
|
Vulnerability in CVE-2026-40768 (CVE-2026-40768)
vulnerability in CVE-2026-40768 (CVE-2026-40768). Risk of unauthorized operations or information disclosure.
|
High
|
Cwe 639
|
2 months ago
|
|
CVE-2026-40755
|
|
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-42385
|
|
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-41557
|
|
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-40760
|
|
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40761
|
|
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40765
|
|
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-42629
|
|
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
|
High
|
Cwe 288
|
2 months ago
|
|
CVE-2026-39539
|
|
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39545
|
|
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39546
|
|
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-39547
|
|
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
|
High
|
Cwe 98
|
2 months ago
|