CVE-2026-32327
Last Modified: 6 Aug 2026A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34191
Last Modified: 7 Aug 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501
Last Modified: 7 Aug 2026Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-34502
Last Modified: 7 Aug 2026Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
CVE-2026-19045
Last Modified: 6 Aug 2026A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-66711
Last Modified: 6 Aug 2026Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
CVE-2026-66710
Last Modified: 6 Aug 2026Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-66709
Last Modified: 6 Aug 2026Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-66708
Last Modified: 6 Aug 2026Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVE-2026-66707
Last Modified: 8 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-66706
Last Modified: 6 Aug 2026Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
CVE-2026-66705
Last Modified: 8 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2026-66703
Last Modified: 6 Aug 2026Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-66702
Last Modified: 6 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-66701
Last Modified: 8 Aug 2026Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
CVE-2026-66699
Last Modified: 6 Aug 2026Custom role Broken Access Control in Dokan <= 5.0.10 versions.
CVE-2026-66696
Last Modified: 7 Aug 2026Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
CVE-2026-66695
Last Modified: 6 Aug 2026Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66694
Last Modified: 8 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-66692
Last Modified: 8 Aug 2026Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-66690
Last Modified: 6 Aug 2026Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
CVE-2026-66688
Last Modified: 6 Aug 2026Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-66686
Last Modified: 7 Aug 2026Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
CVE-2026-66685
Last Modified: 7 Aug 2026Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
CVE-2026-66684
Last Modified: 8 Aug 2026Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-66683
Last Modified: 7 Aug 2026Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
CVE-2026-66681
Last Modified: 7 Aug 2026Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
CVE-2026-66678
Last Modified: 6 Aug 2026Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVE-2026-66665
Last Modified: 7 Aug 2026Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-66664
Last Modified: 8 Aug 2026Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
CVE-2026-66663
Last Modified: 6 Aug 2026Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-66662
Last Modified: 8 Aug 2026Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66470
Last Modified: 8 Aug 2026Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66457
Last Modified: 6 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
CVE-2026-66452
Last Modified: 8 Aug 2026Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
CVE-2026-66451
Last Modified: 6 Aug 2026Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
CVE-2026-66447
Last Modified: 6 Aug 2026Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
CVE-2026-66440
Last Modified: 6 Aug 2026Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
CVE-2026-66439
Last Modified: 6 Aug 2026Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-66425
Last Modified: 8 Aug 2026Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
CVE-2026-65581
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-65579
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-65578
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-65577
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65576
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65575
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-65574
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
CVE-2026-65573
Last Modified: 6 Aug 2026Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65572
Last Modified: 7 Aug 2026Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-65571
Last Modified: 7 Aug 2026Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
