CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-78283

    Last Modified: 28 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

    Published: 27 Aug 2026
    7.1
    High

    CVE-2026-78281

    Last Modified: 28 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

    Published: 27 Aug 2026
    7.2
    High

    CVE-2026-78276

    Last Modified: 27 Aug 2026

    Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

    Published: 27 Aug 2026
    6.8
    Medium

    CVE-2026-78275

    Last Modified: 27 Aug 2026

    Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

    Published: 27 Aug 2026
    9.1
    Critical

    CVE-2026-78274

    Last Modified: 27 Aug 2026

    Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

    Published: 27 Aug 2026
    6.5
    Medium

    CVE-2026-78273

    Last Modified: 27 Aug 2026

    Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.

    Published: 27 Aug 2026
    7.2
    High

    CVE-2026-78271

    Last Modified: 27 Aug 2026

    Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

    Published: 27 Aug 2026
    7.1
    High

    CVE-2026-78261

    Last Modified: 27 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

    Published: 27 Aug 2026
    9.3
    Critical

    CVE-2026-78260

    Last Modified: 28 Aug 2026

    Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-78257

    Last Modified: 27 Aug 2026

    Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-32566

    Last Modified: 27 Aug 2026

    Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

    Published: 27 Aug 2026
    8.5
    High

    CVE-2026-32564

    Last Modified: 27 Aug 2026

    Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

    Published: 27 Aug 2026
    8.5
    High

    CVE-2026-32550

    Last Modified: 28 Aug 2026

    Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

    Published: 27 Aug 2026
    9.3
    Critical

    CVE-2026-32479

    Last Modified: 28 Aug 2026

    Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

    Published: 27 Aug 2026
    8.6
    High

    CVE-2026-27330

    Last Modified: 28 Aug 2026

    Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

    Published: 27 Aug 2026
    5.4
    Medium

    CVE-2026-81279

    Last Modified: 27 Aug 2026

    Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.

    Published: 27 Aug 2026
    5.9
    Medium

    CVE-2026-80489

    Last Modified: 31 Aug 2026

    A flaw was found in glibc. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted text to an application that converts text from SHIFT_JISX0213 to UCS-4. The crafted input can lead to a continuous loop of processing, preventing the application from making progress and consuming resources. Exploitation requires specific conditions, including the application retrying conversion after an error with limited output space.

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-81581

    Last Modified: 27 Aug 2026

    Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote Code Execution and Privilege Escalation (since the driver runs with system privileges).

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-81579

    Last Modified: 27 Aug 2026

    In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

    Published: 27 Aug 2026
    7.7
    High

    CVE-2026-81576

    Last Modified: 4 Sept 2026

    If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read license information belonging to another handle.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-81575

    Last Modified: 4 Sept 2026

    If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.

    Published: 27 Aug 2026
    8.2
    High

    CVE-2026-81574

    Last Modified: 27 Aug 2026

    In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this vulnerability.

    Published: 27 Aug 2026
    8.6
    High

    CVE-2026-81573

    Last Modified: 27 Aug 2026

    If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.

    Published: 27 Aug 2026
    7.8
    High

    CVE-2026-81572

    Last Modified: 4 Sept 2026

    In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.

    Published: 27 Aug 2026
    6.1
    Medium

    CVE-2026-59355

    Last Modified: 4 Sept 2026

    In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.

    Published: 27 Aug 2026
    9.6
    Critical

    CVE-2026-59354

    Last Modified: 1 Sept 2026

    In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may result in Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-78333

    Last Modified: 27 Aug 2026

    The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.

    Published: 27 Aug 2026
    4.3
    Medium

    CVE-2026-78139

    Last Modified: 27 Aug 2026

    The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications.

    Published: 27 Aug 2026
    4.3
    Medium

    CVE-2026-78138

    Last Modified: 27 Aug 2026

    The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-78137

    Last Modified: 27 Aug 2026

    The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-78125

    Last Modified: 27 Aug 2026

    The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-77018

    Last Modified: 27 Aug 2026

    The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.

    Published: 27 Aug 2026
    7.7
    High

    CVE-2026-77017

    Last Modified: 27 Aug 2026

    The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.

    Published: 27 Aug 2026
    9.6
    Critical

    CVE-2026-77016

    Last Modified: 27 Aug 2026

    The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.

    Published: 27 Aug 2026
    5.9
    Medium

    CVE-2026-76549

    Last Modified: 27 Aug 2026

    The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-19715

    Last Modified: 27 Aug 2026

    The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.

    Published: 27 Aug 2026
    4.4
    Medium

    CVE-2026-19454

    Last Modified: 27 Aug 2026

    The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.

    Published: 27 Aug 2026
    6.6
    Medium

    CVE-2026-19225

    Last Modified: 27 Aug 2026

    The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

    Published: 27 Aug 2026
    7.2
    High

    CVE-2026-19223

    Last Modified: 27 Aug 2026

    The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

    Published: 27 Aug 2026
    4.3
    Medium

    CVE-2026-16569

    Last Modified: 27 Aug 2026

    The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.

    Published: 27 Aug 2026
    4.3
    Medium

    CVE-2026-16568

    Last Modified: 27 Aug 2026

    The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-16567

    Last Modified: 27 Aug 2026

    The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.

    Published: 27 Aug 2026
    3.5
    Low

    CVE-2026-13416

    Last Modified: 27 Aug 2026

    The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.

    Published: 27 Aug 2026
    7.2
    High

    CVE-2026-13415

    Last Modified: 27 Aug 2026

    The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.

    Published: 27 Aug 2026
    4.8
    Medium

    CVE-2026-13414

    Last Modified: 27 Aug 2026

    The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.

    Published: 27 Aug 2026
    9.4
    Critical

    CVE-2026-77991

    Last Modified: 28 Aug 2026

    Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.

    Published: 27 Aug 2026
    6.9
    Medium

    CVE-2026-77034

    Last Modified: 28 Aug 2026

    Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-77990

    Last Modified: 28 Aug 2026

    Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.

    Published: 27 Aug 2026
    5.1
    Medium

    CVE-2026-77035

    Last Modified: 28 Aug 2026

    Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-77989

    Last Modified: 28 Aug 2026

    Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.

    Published: 27 Aug 2026