CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2020-37098

    Last Modified: 15 Apr 2026

    Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

    Published: 3 Feb 2026
    8.5
    High

    CVE-2019-25261

    Last Modified: 5 Mar 2026

    AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.

    Published: 3 Feb 2026
    7.5
    High

    CVE-2025-14550

    Last Modified: 4 Feb 2026

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Jiyong Yang for reporting this issue.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-1312

    Last Modified: 18 Apr 2026

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, with dictionary expansion, used in `FilteredRelation`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-1287

    Last Modified: 18 Apr 2026

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansion, as the `**kwargs` passed to `QuerySet` methods `annotate()`, `aggregate()`, `extra()`, `values()`, `values_list()`, and `alias()`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Solomon Kebede for reporting this issue.

    Published: 3 Feb 2026
    7.5
    High

    CVE-2026-1285

    Last Modified: 18 Apr 2026

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html` template filters allow a remote attacker to cause a potential denial-of-service via crafted inputs containing a large number of unmatched HTML end tags. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-1207

    Last Modified: 18 Apr 2026

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Tarek Nakkouch for reporting this issue.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2025-13473

    Last Modified: 4 Feb 2026

    An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers.modwsgi.check_password()` function for authentication via `mod_wsgi` allows remote attackers to enumerate users via a timing attack. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Stackered for reporting this issue.

    Published: 3 Feb 2026
    9.8
    Critical

    CVE-2025-5319

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection. This issue affects DIGITA Efficiency Management System: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Feb 2026
    6.5
    Medium

    CVE-2026-25036

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Passster: from n/a through <= 4.2.25.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-25028

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.1.

    Published: 3 Feb 2026
    7.5
    High

    CVE-2026-25027

    Last Modified: 16 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-25024

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue affects ThirstyAffiliates: from n/a through <= 3.11.9.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-25023

    Last Modified: 16 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP contest-code-checker allows Retrieve Embedded Sensitive Data.This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through <= 2.0.7.

    Published: 3 Feb 2026
    8.5
    High

    CVE-2026-25022

    Last Modified: 16 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-25021

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-25020

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP connect WP Sync for Notion wp-sync-for-notion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sync for Notion: from n/a through <= 1.7.0.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-25019

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.1.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-25016

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Nelio Software Nelio Popups nelio-popups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio Popups: from n/a through <= 1.3.5.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-25015

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-25014

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in themelooks Enter Addons enteraddons allows Cross Site Request Forgery.This issue affects Enter Addons: from n/a through <= 2.3.2.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-25012

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in gfazioli WP Bannerize Pro wp-bannerize-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bannerize Pro: from n/a through <= 1.11.0.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-25011

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-25010

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.09.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24998

    Last Modified: 16 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n/a through <= 7.8.9.2.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24997

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24996

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in wpelemento WPElemento Importer wpelemento-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPElemento Importer: from n/a through <= 0.6.4.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24995

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Latest Post Shortcode: from n/a through <= 14.2.0.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24994

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24992

    Last Modified: 16 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Retrieve Embedded Sensitive Data.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.2.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24991

    Last Modified: 16 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extensions For CF7: from n/a through <= 3.4.0.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-24990

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through <= 2.2.8.

    Published: 3 Feb 2026
    6.5
    Medium

    CVE-2026-24988

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Hogg The Events Calendar Shortcode & Block the-events-calendar-shortcode allows Stored XSS.This issue affects The Events Calendar Shortcode & Block: from n/a through <= 3.1.1.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-24986

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wp.insider Simple Membership WP user Import simple-membership-wp-user-import allows Cross Site Request Forgery.This issue affects Simple Membership WP user Import: from n/a through <= 1.9.1.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24985

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in approveme WP Forms Signature Contract Add-On wp-forms-signature-contract-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Forms Signature Contract Add-On: from n/a through <= 1.8.2.

    Published: 3 Feb 2026
    6.5
    Medium

    CVE-2026-24984

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: from n/a through <= 2.2.9.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24982

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.17.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24967

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24966

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Request Forgery.This issue affects Copyscape Premium: from n/a through <= 1.4.1.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24965

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24962

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Sigmize sigmize allows Cross Site Request Forgery.This issue affects Sigmize: from n/a through <= 0.0.9.

    Published: 3 Feb 2026
    5.4
    Medium

    CVE-2026-24961

    Last Modified: 16 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5.

    Published: 3 Feb 2026
    6.5
    Medium

    CVE-2026-24958

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.2.

    Published: 3 Feb 2026
    6.5
    Medium

    CVE-2026-24957

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through <= 3.2.20.

    Published: 3 Feb 2026
    8.8
    High

    CVE-2026-24954

    Last Modified: 16 Apr 2026

    Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

    Published: 3 Feb 2026
    6.5
    Medium

    CVE-2026-24952

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24951

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24947

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through < 1.5.6.3.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-24945

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.5.34.

    Published: 3 Feb 2026
    4.3
    Medium

    CVE-2026-24942

    Last Modified: 16 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.

    Published: 3 Feb 2026