CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-2688

    Last Modified: 2 Sept 2026

    The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.

    Published: 2 Sept 2026
    3.5
    Low

    CVE-2026-19698

    Last Modified: 2 Sept 2026

    The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-17563

    Last Modified: 2 Sept 2026

    The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.

    Published: 2 Sept 2026
    3.8
    Low

    CVE-2026-14326

    Last Modified: 3 Sept 2026

    The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

    Published: 2 Sept 2026
    6.6
    Medium

    CVE-2026-10821

    Last Modified: 2 Sept 2026

    The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution.

    Published: 2 Sept 2026
    3.5
    Low

    CVE-2025-15692

    Last Modified: 3 Sept 2026

    The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.

    Published: 2 Sept 2026
    8.7
    High

    CVE-2026-79989

    Last Modified: 2 Sept 2026

    The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).

    Published: 2 Sept 2026
    7.8
    High

    CVE-2026-84837

    Last Modified: 3 Sept 2026

    A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.

    Published: 2 Sept 2026
    7.8
    High

    CVE-2026-84838

    Last Modified: 3 Sept 2026

    A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

    Published: 2 Sept 2026
    8.1
    High

    CVE-2026-76594

    Last Modified: 2 Sept 2026

    A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the `/private/import_content/` endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems.

    Published: 2 Sept 2026
    Unknown

    CVE-2026-76595

    Last Modified: 2 Sept 2026

    A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants.

    Published: 2 Sept 2026
    4.1
    Medium

    CVE-2026-16647

    Last Modified: 8 Sept 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

    Published: 2 Sept 2026
    4.8
    Medium

    CVE-2026-18986

    Last Modified: 8 Sept 2026

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.

    Published: 2 Sept 2026
    9.1
    Critical

    CVE-2026-73475

    Last Modified: 8 Sept 2026

    Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-73478

    Last Modified: 2 Sept 2026

    Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-73474

    Last Modified: 9 Sept 2026

    Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-73476

    Last Modified: 2 Sept 2026

    Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-73477

    Last Modified: 2 Sept 2026

    Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.

    Published: 2 Sept 2026
    5.9
    Medium

    CVE-2026-76757

    Last Modified: 2 Sept 2026

    Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

    Published: 2 Sept 2026
    5.9
    Medium

    CVE-2026-76756

    Last Modified: 2 Sept 2026

    Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

    Published: 2 Sept 2026
    5.9
    Medium

    CVE-2026-76755

    Last Modified: 3 Sept 2026

    Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

    Published: 2 Sept 2026
    5.9
    Medium

    CVE-2026-76758

    Last Modified: 2 Sept 2026

    Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.

    Published: 2 Sept 2026
    7.3
    High

    CVE-2026-76782

    Last Modified: 3 Sept 2026

    Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.

    Published: 2 Sept 2026
    7.3
    High

    CVE-2026-76759

    Last Modified: 2 Sept 2026

    Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.

    Published: 2 Sept 2026
    4.8
    Medium

    CVE-2026-81167

    Last Modified: 9 Sept 2026

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-81165

    Last Modified: 2 Sept 2026

    Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

    Published: 2 Sept 2026
    3.7
    Low

    CVE-2026-81168

    Last Modified: 9 Sept 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

    Published: 2 Sept 2026
    3.7
    Low

    CVE-2026-81159

    Last Modified: 2 Sept 2026

    Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.

    Published: 2 Sept 2026
    3.3
    Low

    CVE-2026-81161

    Last Modified: 2 Sept 2026

    Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-81269

    Last Modified: 9 Sept 2026

    Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-81166

    Last Modified: 2 Sept 2026

    Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-81162

    Last Modified: 9 Sept 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-81158

    Last Modified: 2 Sept 2026

    Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-81164

    Last Modified: 2 Sept 2026

    Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-81205

    Last Modified: 2 Sept 2026

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

    Published: 2 Sept 2026
    6.1
    Medium

    CVE-2026-81201

    Last Modified: 2 Sept 2026

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.

    Published: 2 Sept 2026
    6.1
    Medium

    CVE-2026-81160

    Last Modified: 2 Sept 2026

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-84217

    Last Modified: 3 Sept 2026

    Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Classified Listing: from n/a through 6.1.1.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-84835

    Last Modified: 2 Sept 2026

    Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-66652

    Last Modified: 2 Sept 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-84780

    Last Modified: 4 Sept 2026

    Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-84775

    Last Modified: 2 Sept 2026

    Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.

    Published: 2 Sept 2026
    5.5
    Medium

    CVE-2026-84772

    Last Modified: 3 Sept 2026

    Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-84771

    Last Modified: 2 Sept 2026

    Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84770

    Last Modified: 2 Sept 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84764

    Last Modified: 4 Sept 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-84760

    Last Modified: 2 Sept 2026

    Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.

    Published: 2 Sept 2026
    7.1
    High

    CVE-2026-84759

    Last Modified: 3 Sept 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.

    Published: 2 Sept 2026
    6.5
    Medium

    CVE-2026-83562

    Last Modified: 2 Sept 2026

    Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.

    Published: 2 Sept 2026
    6.5
    Medium

    CVE-2026-82223

    Last Modified: 2 Sept 2026

    Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.

    Published: 2 Sept 2026
    Items Per Page