CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2026-64972

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises these parameters, but that does not prevent XSS in the parent frameset rendered by preview.php itself. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    4.8
    Medium

    CVE-2026-64971

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    5.1
    Medium

    CVE-2026-64970

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When any authenticated user visits the attacker's public profile, the profile template echoes the phone value without output encoding and the browser executes the payload leading to the theft of user's session cookie. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-64969

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST request to the profile album endpoint and permanently delete that user's profile picture, including those of instructors and administrators. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    5.1
    Medium

    CVE-2026-64968

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP environment permits URL wrappers. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    6.9
    Medium

    CVE-2026-64967

    Last Modified: 20 Aug 2026

    A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This can lead to unauthorized access to sensitive files and other resources accessible to the web server process. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    8.7
    High

    CVE-2026-64966

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP archive, causing files to be written outside the intended extraction directory. This allows an attacker to place a server-executable .phtml file in the web root and achieve remote code execution with web server privileges on the underlying server. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-64965

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enrolled in a course can bypass authorization checks by sending requests directly to the backend import endpoints, allowing the unauthorized import of tests and questions within a course. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    8.6
    High

    CVE-2026-76635

    Last Modified: 25 Aug 2026

    baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a backup restore code injection flaw, where PHP code outside class definitions in schema files executes unconditionally upon loading, to plant malicious table names and trigger error-based SQL injection that retrieves database version, schema contents, and arbitrary data from the PostgreSQL backend.

    Published: 20 Aug 2026
    6.3
    Medium

    CVE-2026-64964

    Last Modified: 20 Aug 2026

    ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or can predict these values can guess valid account activation tokens. This allows an attacker to activate an unconfirmed account without access to the victim's email inbox. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    2.3
    Low

    CVE-2026-64963

    Last Modified: 20 Aug 2026

    A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This can lead to unauthorized access to files and disclosure of information about the filesystem structure. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    5.1
    Medium

    CVE-2026-64962

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated victim, submits a forged request to the system. Due to the lack of proper CSRF token implementation, the forged request is processed successfully, allowing an attacker to modify profile fields of an existing user. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    6.3
    Medium

    CVE-2026-64961

    Last Modified: 20 Aug 2026

    ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain uninitialized in certain code paths. An unauthenticated attacker who can determine a user's identifier and registration timestamp can generate a valid token and authenticate as an existing user, including administrator, without knowing the password. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    8.7
    High

    CVE-2026-64960

    Last Modified: 20 Aug 2026

    ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-executable malicious script. The uploaded file can then be requested over HTTP, resulting in remote code execution as the web server process user. In most cases, course_id=0 can be used, as it commonly represents the global context. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-76634

    Last Modified: 20 Aug 2026

    WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags.

    Published: 20 Aug 2026
    8.6
    High

    CVE-2026-76633

    Last Modified: 20 Aug 2026

    WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routing through verificarSenhaConfig() instead of verificarSenha() to bypass current password verification and convert temporary session access into permanent account takeover.

    Published: 20 Aug 2026
    8.4
    High

    CVE-2026-76833

    Last Modified: 21 Aug 2026

    @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML input with this library exposes full Node.js runtime authority, including environment variable access, filesystem read/write, network access, and subprocess execution, with no safe-mode alternative or opt-out mechanism available.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-15706

    Last Modified: 21 Aug 2026

    Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-76990

    Last Modified: 21 Aug 2026

    A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-76989

    Last Modified: 25 Aug 2026

    A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive Path. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is e8e9dba09bf56962807d3504b783ccdb6287f3e4. To fix this issue, it is recommended to deploy a patch.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-76988

    Last Modified: 20 Aug 2026

    A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_open of the file cipconnectionmanager.cc of the component ForwardOpen Handler. Executing a manipulation of the argument product_code_ can lead to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ea870a274bf68dfaa3f511f20e2fff6778fb7b74. A patch should be applied to remediate this issue.

    Published: 20 Aug 2026
    8.4
    High

    CVE-2026-77118

    Last Modified: 26 Aug 2026

    A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only when a sync marker introduces a new plane/row; between sync markers the run length is bounded solely by the input. A crafted PCD file that positions the pointer near the end of a plane and then supplies a long run of deltas with no intervening sync therefore walks the pointer past the end of the allocation and writes through it. Processing an untrusted PCD file — for example with gm convert or gm identify, or through any application linked against libGraphicsMagick — can corrupt heap memory beyond the buffers.

    Published: 20 Aug 2026
    9.6
    Critical

    CVE-2026-28164

    Last Modified: 20 Aug 2026

    Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-18482

    Last Modified: 27 Aug 2026

    Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-28163

    Last Modified: 21 Aug 2026

    Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8.

    Published: 20 Aug 2026
    7.6
    High

    CVE-2026-74011

    Last Modified: 20 Aug 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.

    Published: 20 Aug 2026
    4.8
    Medium

    CVE-2026-21784

    Last Modified: 27 Aug 2026

    HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation.

    Published: 20 Aug 2026
    6.6
    Medium

    CVE-2025-62299

    Last Modified: 27 Aug 2026

    HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-76987

    Last Modified: 20 Aug 2026

    A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Attribute Logic. Performing a manipulation results in memory corruption. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is named e745d9d4a8ca3a13689066983a1269fe1e567674. It is suggested to install a patch to address this issue.

    Published: 20 Aug 2026
    5.9
    Medium

    CVE-2025-62300

    Last Modified: 27 Aug 2026

    HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior.

    Published: 20 Aug 2026
    2.3
    Low

    CVE-2026-7485

    Last Modified: 26 Aug 2026

    Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.

    Published: 20 Aug 2026
    5
    Medium

    CVE-2025-62306

    Last Modified: 21 Aug 2026

    HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response.

    Published: 20 Aug 2026
    5.4
    Medium

    CVE-2025-62307

    Last Modified: 21 Aug 2026

    HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-74020

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-74019

    Last Modified: 24 Aug 2026

    Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-74018

    Last Modified: 21 Aug 2026

    Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-74016

    Last Modified: 21 Aug 2026

    Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-74014

    Last Modified: 21 Aug 2026

    Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-74013

    Last Modified: 21 Aug 2026

    Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-74001

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-73998

    Last Modified: 21 Aug 2026

    Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-73993

    Last Modified: 20 Aug 2026

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-73992

    Last Modified: 20 Aug 2026

    Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-73402

    Last Modified: 20 Aug 2026

    Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-68566

    Last Modified: 20 Aug 2026

    Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-68564

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-66682

    Last Modified: 20 Aug 2026

    Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-66680

    Last Modified: 20 Aug 2026

    Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

    Published: 20 Aug 2026
    7.6
    High

    CVE-2026-66677

    Last Modified: 21 Aug 2026

    Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66673

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.

    Published: 20 Aug 2026