|
CVE-2026-39442
|
|
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-39556
|
|
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-9690
|
|
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
|
High
|
Cwe 22
|
il y a 2 mois
|
|
CVE-2025-66391
|
|
Vulnérabilité dans CVE-2025-66391 (CVE-2025-66391)
vulnérabilité dans CVE-2025-66391 (CVE-2025-66391). L'exploitation peut entraîner la prise de contrôle totale du système.
|
High
|
Cwe 284
|
il y a 2 mois
|
|
CVE-2026-9570
|
|
XSS (Cross-Site Scripting) dans wordpress (CVE-2026-9570)
XSS dans wordpress (CVE-2026-9570). Risque d'opérations non autorisées ou de divulgation.
|
High
|
JavaScript
WordPress
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2025-69164
|
|
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
|
High
|
Cwe 98
|
il y a 2 mois
|
|
CVE-2026-54185
|
|
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
|
High
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-54188
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-54184
|
|
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
|
High
|
Cwe 639
|
il y a 2 mois
|
|
CVE-2026-54802
|
|
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-54805
|
|
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
|
High
|
Privilege Escalation
Cwe 266
|
il y a 2 mois
|
|
CVE-2026-54195
|
|
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-52698
|
|
Vulnérabilité dans CVE-2026-52698 (CVE-2026-52698)
vulnérabilité dans CVE-2026-52698 (CVE-2026-52698). Risque d'opérations non autorisées ou de divulgation.
|
High
|
Cwe 201
|
il y a 2 mois
|
|
CVE-2026-53876
|
|
Injection de commande OS dans CVE-2026-53876 (CVE-2026-53876)
injection de commande OS dans CVE-2026-53876 (CVE-2026-53876). L'exploitation peut entraîner la prise de contrôle totale du système.
|
High
|
Cwe 78
|
il y a 2 mois
|
|
CVE-2026-54192
|
|
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-52696
|
|
Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
|
High
|
Cwe 1258
|
il y a 2 mois
|
|
CVE-2026-54189
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-8089
|
|
XSS (Cross-Site Scripting) dans wordpress (CVE-2026-8089)
XSS dans wordpress (CVE-2026-8089). Risque d'opérations non autorisées ou de divulgation.
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-54804
|
|
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
|
High
|
Cwe 288
|
il y a 2 mois
|
|
CVE-2026-48869
|
|
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-49074
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-49057
|
|
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-49113
|
|
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
|
High
|
Cwe 94
|
il y a 2 mois
|
|
CVE-2026-49778
|
|
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-48967
|
|
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
|
High
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-48929
|
|
Contournement d'authentification dans rocketchat (CVE-2026-48929)
contournement d'authentification dans rocketchat (CVE-2026-48929). Risque d'opérations non autorisées ou de divulgation.
|
High
|
Cwe 287
Rocketchat
|
il y a 2 mois
|
|
CVE-2026-49073
|
|
Injection SQL dans sqli (CVE-2026-49073)
injection SQL dans sqli (CVE-2026-49073). Des informations confidentielles peuvent être exposées.
|
High
|
SQL Injection
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-49081
|
|
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-40753
|
|
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40751
|
|
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40754
|
|
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40736
|
|
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40739
|
|
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40758
|
|
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-41557
|
|
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-40759
|
|
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40735
|
|
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40765
|
|
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-40768
|
|
Vulnérabilité dans CVE-2026-40768 (CVE-2026-40768)
vulnérabilité dans CVE-2026-40768 (CVE-2026-40768). Risque d'opérations non autorisées ou de divulgation.
|
High
|
Cwe 639
|
il y a 2 mois
|
|
CVE-2026-40755
|
|
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40731
|
|
Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
|
High
|
Cwe 98
|
il y a 2 mois
|
|
CVE-2026-40760
|
|
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40761
|
|
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-40726
|
|
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
|
High
|
Cwe 862
|
il y a 2 mois
|
|
CVE-2026-42385
|
|
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-42629
|
|
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
|
High
|
Cwe 288
|
il y a 2 mois
|
|
CVE-2026-39547
|
|
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
|
High
|
Cwe 98
|
il y a 2 mois
|
|
CVE-2026-39546
|
|
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
|
High
|
Privilege Escalation
Cwe 266
|
il y a 2 mois
|
|
CVE-2026-39539
|
|
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|
|
CVE-2026-39545
|
|
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
|
High
|
PHP
Cwe 502
|
il y a 2 mois
|