|
CVE-2026-54805
|
|
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-8089
|
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8089)
cross-site scripting in wordpress (CVE-2026-8089). Risk of unauthorized operations or information disclosure.
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-54804
|
|
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
|
High
|
Cwe 288
|
2 months ago
|
|
CVE-2026-49057
|
|
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-48929
|
|
Authentication Bypass in rocketchat (CVE-2026-48929)
authentication bypass in rocketchat (CVE-2026-48929). Risk of unauthorized operations or information disclosure.
|
High
|
Cwe 287
Rocketchat
|
2 months ago
|
|
CVE-2026-48869
|
|
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49778
|
|
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-49081
|
|
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-49073
|
|
SQL Injection in sqli (CVE-2026-49073)
SQL injection in sqli (CVE-2026-49073). Confidential information can be exposed externally.
|
High
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-49074
|
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-48967
|
|
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
|
High
|
SQL Injection
Cwe 89
|
2 months ago
|
|
CVE-2026-49113
|
|
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
|
High
|
Cwe 94
|
2 months ago
|
|
CVE-2026-40735
|
|
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-41557
|
|
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-40726
|
|
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
|
High
|
Cwe 862
|
2 months ago
|
|
CVE-2026-40731
|
|
Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-40751
|
|
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40753
|
|
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40754
|
|
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40761
|
|
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40765
|
|
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-40739
|
|
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40768
|
|
Vulnerability in CVE-2026-40768 (CVE-2026-40768)
vulnerability in CVE-2026-40768 (CVE-2026-40768). Risk of unauthorized operations or information disclosure.
|
High
|
Cwe 639
|
2 months ago
|
|
CVE-2026-40759
|
|
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40755
|
|
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40758
|
|
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40760
|
|
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40736
|
|
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-42629
|
|
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
|
High
|
Cwe 288
|
2 months ago
|
|
CVE-2026-42385
|
|
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-39548
|
|
Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.
Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-39567
|
|
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39537
|
|
Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.
Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39549
|
|
Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.
Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39546
|
|
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
|
High
|
Privilege Escalation
Cwe 266
|
2 months ago
|
|
CVE-2026-39539
|
|
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39545
|
|
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39547
|
|
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39558
|
|
Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.
Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39573
|
|
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39554
|
|
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39557
|
|
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-39568
|
|
Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.
Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39597
|
|
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
|
2 months ago
|
|
CVE-2026-39582
|
|
Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39580
|
|
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|
|
CVE-2026-40721
|
|
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39598
|
|
Unrestricted File Upload in CVE-2026-39598 (CVE-2026-39598)
vulnerability in CVE-2026-39598 (CVE-2026-39598). Successful exploitation can lead to full system takeover.
|
High
|
Cwe 434
|
2 months ago
|
|
CVE-2026-34895
|
|
Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.
Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.
|
High
|
Cwe 98
|
2 months ago
|
|
CVE-2026-39443
|
|
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
|
High
|
PHP
Cwe 502
|
2 months ago
|