CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2026-84654

    Last Modified: 3 Sept 2026

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of the configuration objects those forms are bound to, resulting in changes that apply globally to the Jenkins instance.

    Published: 2 Sept 2026
    3.5
    Low

    CVE-2026-84653

    Last Modified: 5 Sept 2026

    Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

    Published: 2 Sept 2026
    7.3
    High

    CVE-2026-84652

    Last Modified: 11 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

    Published: 2 Sept 2026
    6.3
    Medium

    CVE-2026-84651

    Last Modified: 11 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84650

    Last Modified: 11 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84648

    Last Modified: 11 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84649

    Last Modified: 3 Sept 2026

    In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

    Published: 2 Sept 2026
    4.3
    Medium

    CVE-2026-84646

    Last Modified: 11 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84647

    Last Modified: 3 Sept 2026

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.

    Published: 2 Sept 2026
    8.8
    High

    CVE-2026-84645

    Last Modified: 11 Sept 2026

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.

    Published: 2 Sept 2026
    7.3
    High

    CVE-2026-18058

    Last Modified: 3 Sept 2026

    The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.

    Published: 2 Sept 2026
    7.6
    High

    CVE-2024-7956

    Last Modified: 2 Sept 2026

    A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.

    Published: 2 Sept 2026
    4.3
    Medium

    CVE-2026-82293

    Last Modified: 3 Sept 2026

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach.

    Published: 2 Sept 2026
    6.5
    Medium

    CVE-2026-78588

    Last Modified: 3 Sept 2026

    Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.

    Published: 2 Sept 2026
    3.1
    Low

    CVE-2026-78587

    Last Modified: 3 Sept 2026

    Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents.

    Published: 2 Sept 2026
    6.5
    Medium

    CVE-2026-78586

    Last Modified: 3 Sept 2026

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.

    Published: 2 Sept 2026
    4.3
    Medium

    CVE-2026-78584

    Last Modified: 3 Sept 2026

    Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.

    Published: 2 Sept 2026
    6.3
    Medium

    CVE-2026-78591

    Last Modified: 3 Sept 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.

    Published: 2 Sept 2026
    7.3
    High

    CVE-2026-78590

    Last Modified: 3 Sept 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.

    Published: 2 Sept 2026
    6.5
    Medium

    CVE-2026-78599

    Last Modified: 3 Sept 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-78598

    Last Modified: 3 Sept 2026

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.

    Published: 2 Sept 2026
    4.9
    Medium

    CVE-2026-78594

    Last Modified: 3 Sept 2026

    Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.

    Published: 2 Sept 2026
    7.8
    High

    CVE-2026-78604

    Last Modified: 4 Sept 2026

    Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

    Published: 2 Sept 2026
    9
    Critical

    CVE-2026-82955

    Last Modified: 3 Sept 2026

    In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS certificate verification when KrakenD retrieves the JSON Web Key Set (JWKS) used to validate bearer tokens, potentially allowing an attacker with the ability to intercept this communication to provide a malicious JWKS and compromise token validation. The issue has been addressed by making the parameter configurable through the boolean Helm value krakend.config.disableJwkSecurity and setting its default value to false, ensuring that TLS certificate verification is enabled by default.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-78602

    Last Modified: 8 Sept 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.

    Published: 2 Sept 2026
    5.5
    Medium

    CVE-2026-78601

    Last Modified: 3 Sept 2026

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output.

    Published: 2 Sept 2026
    3.5
    Low

    CVE-2026-78600

    Last Modified: 3 Sept 2026

    Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-78609

    Last Modified: 4 Sept 2026

    Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace.

    Published: 2 Sept 2026
    5.5
    Medium

    CVE-2026-14255

    Last Modified: 2 Sept 2026

    A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-2811

    Last Modified: 2 Sept 2026

    The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.

    Published: 2 Sept 2026
    9.8
    Critical

    CVE-2025-9314

    Last Modified: 2 Sept 2026

    The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2025-8945

    Last Modified: 2 Sept 2026

    The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2025-15490

    Last Modified: 3 Sept 2026

    The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2025-15489

    Last Modified: 7 Sept 2026

    The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content

    Published: 2 Sept 2026
    8.2
    High

    CVE-2025-15485

    Last Modified: 2 Sept 2026

    The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2025-15481

    Last Modified: 2 Sept 2026

    The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.

    Published: 2 Sept 2026
    5.9
    Medium

    CVE-2024-3773

    Last Modified: 2 Sept 2026

    The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 2 Sept 2026
    3.3
    Low

    CVE-2023-3360

    Last Modified: 2 Sept 2026

    The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

    Published: 2 Sept 2026
    7.1
    High

    CVE-2026-79991

    Last Modified: 2 Sept 2026

    Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.

    Published: 2 Sept 2026
    8.7
    High

    CVE-2026-79990

    Last Modified: 2 Sept 2026

    Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.

    Published: 2 Sept 2026
    6.8
    Medium

    CVE-2026-83547

    Last Modified: 2 Sept 2026

    The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-83533

    Last Modified: 2 Sept 2026

    The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

    Published: 2 Sept 2026
    6.8
    Medium

    CVE-2026-82884

    Last Modified: 3 Sept 2026

    The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post.

    Published: 2 Sept 2026
    4.8
    Medium

    CVE-2026-81571

    Last Modified: 3 Sept 2026

    The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have arbitrary shortcodes registered on the site executed server-side.

    Published: 2 Sept 2026
    5.4
    Medium

    CVE-2026-8151

    Last Modified: 2 Sept 2026

    The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is sent to the attacker-controlled account.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-78153

    Last Modified: 2 Sept 2026

    The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-77794

    Last Modified: 3 Sept 2026

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.

    Published: 2 Sept 2026
    5.3
    Medium

    CVE-2026-77793

    Last Modified: 3 Sept 2026

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.

    Published: 2 Sept 2026
    9.9
    Critical

    CVE-2026-77009

    Last Modified: 2 Sept 2026

    The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.

    Published: 2 Sept 2026
    10
    Critical

    CVE-2026-4357

    Last Modified: 2 Sept 2026

    The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

    Published: 2 Sept 2026
    Items Per Page