CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-57364

    Last Modified: 13 Jul 2026

    Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More: from n/a through <= 2.2.0.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57368

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57375

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.

    Published: 13 Jul 2026
    7.2
    High

    CVE-2026-57372

    Last Modified: 13 Jul 2026

    Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.

    Published: 13 Jul 2026
    8.8
    High

    CVE-2026-57371

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57363

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57365

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57376

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57369

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57377

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.

    Published: 13 Jul 2026
    2.1
    Low

    CVE-2026-15547

    Last Modified: 13 Jul 2026

    A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This project is superseded by FreshTomato.

    Published: 13 Jul 2026
    9.6
    Critical

    CVE-2026-14453

    Last Modified: 13 Jul 2026

    This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute arbitrary code on the server. This results in disclosure of environment secrets and could impact platform availability of Centreon Infra Monitoring product.

    Published: 13 Jul 2026
    5.4
    Medium

    CVE-2026-9597

    Last Modified: 13 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681

    Published: 13 Jul 2026
    2.1
    Low

    CVE-2026-15546

    Last Modified: 13 Jul 2026

    A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing a manipulation of the argument jffs2_exec results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-6850

    Last Modified: 13 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-10106

    Last Modified: 13 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a cookie obtained from any accessible channel.. Mattermost Advisory ID: MMSA-2026-00690

    Published: 13 Jul 2026
    5.4
    Medium

    CVE-2026-10085

    Last Modified: 13 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

    Published: 13 Jul 2026
    7.4
    High

    CVE-2026-15545

    Last Modified: 13 Jul 2026

    A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.

    Published: 13 Jul 2026
    4.9
    Medium

    CVE-2026-9708

    Last Modified: 13 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-00683

    Published: 13 Jul 2026
    4.3
    Medium

    CVE-2026-10103

    Last Modified: 14 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.. Mattermost Advisory ID: MMSA-2026-00689

    Published: 13 Jul 2026
    8.3
    High

    CVE-2026-62143

    Last Modified: 14 Jul 2026

    A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. However, IP addresses were compared against the blocked ranges without first normalising IPv4-mapped IPv6 addresses. An authenticated attacker able to invoke the module could supply an IPv4-mapped IPv6 address, such as: http://[::ffff:127.0.0.1]/ http://[::ffff:169.254.169.254]/ Alternatively, the attacker could use a hostname that resolves to an IPv4-mapped IPv6 address. These addresses were treated as IPv6 addresses and therefore did not match the corresponding blocked IPv4 ranges. Successful exploitation could cause the misp-modules server to connect to services available through its loopback interface, internal network, or link-local network. This could expose internal web services, administrative interfaces, or cloud instance metadata, with retrieved content potentially returned to the attacker as converted Markdown. The vulnerability has been addressed by normalising IPv4-mapped IPv6 addresses to their underlying IPv4 representation before applying the blocked-range checks. URLs without a valid hostname are now also rejected.

    Published: 13 Jul 2026
    5.9
    Medium

    CVE-2026-9571

    Last Modified: 14 Jul 2026

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680

    Published: 13 Jul 2026
    7.4
    High

    CVE-2026-15544

    Last Modified: 13 Jul 2026

    A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.

    Published: 13 Jul 2026
    8.8
    High

    CVE-2026-57830

    Last Modified: 23 Jul 2026

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

    Published: 13 Jul 2026
    8.7
    High

    CVE-2026-57829

    Last Modified: 23 Jul 2026

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

    Published: 13 Jul 2026
    7.4
    High

    CVE-2026-15543

    Last Modified: 13 Jul 2026

    A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-14165

    Last Modified: 13 Jul 2026

    An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.

    Published: 13 Jul 2026
    6.9
    Medium

    CVE-2026-15542

    Last Modified: 15 Jul 2026

    A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull request to fix this issue awaits acceptance.

    Published: 13 Jul 2026
    6.9
    Medium

    CVE-2026-15541

    Last Modified: 13 Jul 2026

    A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-4769

    Last Modified: 13 Jul 2026

    Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.

    Published: 13 Jul 2026
    2.1
    Low

    CVE-2026-15540

    Last Modified: 13 Jul 2026

    A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    Published: 13 Jul 2026
    2
    Low

    CVE-2026-15539

    Last Modified: 13 Jul 2026

    A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-15538

    Last Modified: 27 Aug 2026

    A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the file components/lib/utils/ObjectUtils.js of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The attack is possible to be carried out remotely. Upgrading to version 10.9.9 and 11.0.0 is capable of addressing this issue. Patch name: 61f182e11d9ef52032ff56f420da763a6938236f. It is recommended to upgrade the affected component.

    Published: 13 Jul 2026
    8.6
    High

    CVE-2026-12582

    Last Modified: 4 Aug 2026

    The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.

    Published: 13 Jul 2026
    4.3
    Medium

    CVE-2026-12397

    Last Modified: 3 Aug 2026

    The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users with a subscriber-level (self-registerable) account to read other employers' private account email addresses by enumerating job identifiers.

    Published: 13 Jul 2026
    5.4
    Medium

    CVE-2026-12396

    Last Modified: 3 Aug 2026

    The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a subscriber-level (self-registerable) account to approve, feature, or reject arbitrary jobs, including those owned by other users.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-12275

    Last Modified: 3 Aug 2026

    The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it enforces in its core course handler, allowing authenticated users with subscriber-level access to enroll in paid or private courses without authorization, read private course content, and mark arbitrary courses as completed, on sites where the Droip or Kirki integration is active.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-12274

    Last Modified: 4 Aug 2026

    The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one of its content-builder save handlers, authorizing the request only against an unrelated identifier, allowing authenticated users with instructor-level access to overwrite and take over any post or page on the site, including those owned by administrators.

    Published: 13 Jul 2026
    4.3
    Medium

    CVE-2026-12273

    Last Modified: 5 Aug 2026

    The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.

    Published: 13 Jul 2026
    5.4
    Medium

    CVE-2026-12271

    Last Modified: 29 Jul 2026

    The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level access and above to modify and force-complete other students' quiz attempts, overwriting their recorded marks and pass/fail result.

    Published: 13 Jul 2026
    5
    Medium

    CVE-2026-12081

    Last Modified: 3 Aug 2026

    The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry. This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.

    Published: 13 Jul 2026
    9.1
    Critical

    CVE-2026-11964

    Last Modified: 5 Aug 2026

    The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a paid membership subscription without completing a real payment.

    Published: 13 Jul 2026
    8.1
    High

    CVE-2026-11963

    Last Modified: 5 Aug 2026

    The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier.

    Published: 13 Jul 2026
    6.1
    Medium

    CVE-2026-10551

    Last Modified: 29 Jul 2026

    The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

    Published: 13 Jul 2026
    5.5
    Medium

    CVE-2026-15537

    Last Modified: 13 Jul 2026

    A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

    Published: 13 Jul 2026
    2.1
    Low

    CVE-2026-15536

    Last Modified: 15 Jul 2026

    A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

    Published: 13 Jul 2026
    2.1
    Low

    CVE-2026-15535

    Last Modified: 13 Jul 2026

    A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to deserialization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 13 Jul 2026
    2
    Low

    CVE-2026-15533

    Last Modified: 13 Jul 2026

    A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    Published: 13 Jul 2026
    1.9
    Low

    CVE-2026-15532

    Last Modified: 13 Jul 2026

    A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used.

    Published: 13 Jul 2026
    1.9
    Low

    CVE-2026-15531

    Last Modified: 13 Jul 2026

    A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to deserialization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The pull request to fix this issue awaits acceptance.

    Published: 13 Jul 2026