|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 4 jours
|
|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 4 jours
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
Remote Code Execution
Cwe 434
+1
|
il y a 4 jours
|
|
CVE-2026-68960
|
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
High
|
Cwe 121
Buffer Overflow
Windows
|
il y a 4 jours
|
|
CVE-2026-75574
|
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
High
|
PHP
Cwe 1336
WordPress
Remote Code Execution
|
il y a 4 jours
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
il y a 4 jours
|
|
CVE-2026-56702
|
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
High
|
PHP
Cwe 434
Remote Code Execution
|
il y a 4 jours
|
|
CVE-2026-34968
|
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
High
|
PHP
C
Cwe 22
Adminer
+1
|
il y a 4 jours
|
|
CVE-2026-71504
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
High
|
Cwe 862
Cwe 915
PHP
|
il y a 5 jours
|
|
CVE-2026-40877
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Remote Code Execution
Cwe 94
Cwe 502
|
il y a 5 jours
|
|
CVE-2026-30819
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Cross-Site Scripting
Cwe 79
|
il y a 1 semaine
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
Privilege Escalation
Cwe 269
PHP
|
il y a 2 semaines
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
Cwe 78
Cockpit
PHP
Command Injection
|
il y a 2 semaines
|
|
CVE-2026-19825
|
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 semaines
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-19764
|
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
+2
|
il y a 2 semaines
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
Authentication Bypass
|
il y a 2 semaines
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|
|
CVE-2026-16636
|
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|
|
CVE-2026-15991
|
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
High
|
PHP
WordPress
Remote Code Execution
Cwe 862
+1
|
il y a 3 semaines
|
|
CVE-2026-67623
|
|
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
|
High
|
Remote Code Execution
Cwe 829
Git
|
il y a 3 semaines
|
|
CVE-2026-71287
|
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|
High
|
PHP
SQL Injection
Cwe 89
Cacti
|
il y a 3 semaines
|
|
CVE-2026-7444
|
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
High
|
WordPress
Cwe 352
PHP
Cross-Site Request Forgery
|
il y a 3 semaines
|
|
CVE-2026-7520
|
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
High
|
WordPress
Cwe 862
PHP
Authentication Bypass
|
il y a 3 semaines
|
|
CVE-2026-6627
|
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
High
|
PHP
WordPress
Cwe 862
Authentication Bypass
|
il y a 3 semaines
|
|
CVE-2026-6147
|
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
High
|
WordPress
Remote Code Execution
Cwe 434
PHP
|
il y a 3 semaines
|
|
CVE-2026-6267
|
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
|
High
|
Cwe 201
Gitlab
Authentication Bypass
Access Control
|
il y a 1 mois
|
|
CVE-2026-66473
|
|
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
il y a 1 mois
|
|
CVE-2026-65447
|
|
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65446
|
|
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65443
|
|
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65442
|
|
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
|
High
|
Server-Side Request Forgery
Cwe 918
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65437
|
|
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-61957
|
|
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-61953
|
|
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
|
High
|
Server-Side Request Forgery
Cwe 918
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-8056
|
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
|
High
|
Cwe 94
Remote Code Execution
Langflow
Apple
+5
|
il y a 1 mois
|
|
CVE-2026-7872
|
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
|
High
|
Cwe 22
Jwt
File Access
Auth Token
+7
|
il y a 1 mois
|
|
CVE-2026-7667
|
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
|
High
|
Cwe 22
Remote Code Execution
Langflow
Apple
+5
|
il y a 1 mois
|
|
CVE-2026-7754
|
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
|
High
|
Server-Side Request Forgery
Cwe 918
Langflow
Apple
+5
|
il y a 1 mois
|
|
CVE-2026-63030
KEV
|
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
Critical
|
WordPress
Remote Code Execution
SQL Injection
Cwe 436
+10
|
il y a 1 mois
|
|
CVE-2026-13521
|
|
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-13498
|
|
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-58054
|
|
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
|
High
|
Cwe 269
Mybb
PHP
Privilege Escalation
|
il y a 2 mois
|
|
CVE-2026-3652
|
|
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 mois
|
|
CVE-2026-9029
|
|
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug....
The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug....
|
High
|
Cross-Site Scripting
Grafana
Cwe 79
|
il y a 2 mois
|
|
CVE-2026-42129
|
|
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An...
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An...
|
High
|
Path Traversal
Cwe 22
Grafana
Loki Datasource
|
il y a 2 mois
|
|
CVE-2026-47906
|
|
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
|
High
|
PHP
Remote Code Execution
Cwe 94
Adobe
+5
|
il y a 2 mois
|
|
CVE-2026-11501
|
|
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 mois
|
|
CVE-2026-11488
|
|
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 mois
|