Products: 3
Vulnerabilities: 11
Known Exploited: 0
3
Critical Level Threats
2
High Level Threats
6
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-18855
Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter
Last Modified: Aug 17, 2026
Published: Aug 15, 2026
CVE-2026-2429
Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field
Last Modified: Apr 22, 2026
Published: Mar 07, 2026
CVE-2026-1649
Community Events <= 1.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter
Last Modified: Apr 15, 2026
Published: Feb 18, 2026
CVE-2026-1401
Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via CSV Import
Last Modified: Apr 15, 2026
Published: Feb 06, 2026
CVE-2025-14029
Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter
Last Modified: Apr 22, 2026
Published: Jan 17, 2026
Items Per Page
