Search Results (39397 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66658 2 Mvp Themes, Wordpress 2 Reviewer, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-73346 2 Mailchimp, Wordpress 2 Mailchimp For Woocommerce, Wordpress 2026-08-14 7.6 High
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-73353 2 Revolut, Wordpress 2 Revolut Gateway For Woocommerce, Wordpress 2026-08-14 5.3 Medium
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVE-2026-73665 1 Freepbx 1 Ucp 2026-08-14 N/A
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path patched by node/lib/asterisk-manager-patch.js, allowing arbitrary commands to execute as the asterisk service user. This issue is fixed in version 17.0.9.
CVE-2026-73842 1 Openchoreo 1 Openchoreo 2026-08-14 9 Critical
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.
CVE-2026-72831 1 Getgrav 1 Grav 2026-08-14 8.8 High
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and Groups API controllers. An authenticated account with api.access, admin.login, and users.update permissions (but without api.users.write or admin.super) can use the generic /api/v1/flex-objects/user-accounts endpoint to change a super administrator's password, or the /api/v1/flex-objects/user-groups endpoint to grant its group admin.super, resulting in full site takeover. Fixed in Flex Objects 1.4.7.
CVE-2026-72825 1 Getgrav 1 Grav 2026-08-14 7.6 High
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmin() check instead of requireSuper(). Because isSuperAdmin() reads access.api.super directly and never consults api_key_scopes, a least-privilege API key scoped to api.config.write minted on a super account passes the gate, allowing an attacker to append attacker-chosen tokens to the security.twig_sandbox allowlist (persisted to user/config/security.yaml). Widening the allowlist turns any subsequent Twig-in-content render into an SSTI/RCE sink.
CVE-2026-72823 1 Getgrav 1 Grav 2026-08-14 5.4 Medium
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes cap (enforced only in requirePermission()) is skipped. As a result, any scoped API key minted on a super account can bypass its scope restrictions when calling the baseline() and reset() operations (e.g. POST /api/v1/demo/reset), allowing it to capture the demo baseline or force a demo reset. Impact is bounded to demo-engine control and is conditional on demo mode being configured with writable resources.
CVE-2026-19787 1 Sourcecodester 1 Air Cargo Management System 2026-08-14 4.7 Medium
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-58416 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.1 High
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-16810 2 Bitpressadmin, Wordpress 2 Bit Form, Wordpress 2026-08-14 6.5 Medium
The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-28156 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28159 2 Aonetheme, Wordpress 2 Service Finder Booking, Wordpress 2026-08-14 6.5 Medium
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28168 2 Imran Tauqeer, Wordpress 2 Cubewp, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-28186 2 Themefic, Wordpress 2 Travelfic Toolkit, Wordpress 2026-08-14 8.1 High
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
CVE-2026-61978 2 Webhosting4ugr, Wordpress 2 Secure Card Gateway For Epay Paycenter (piraeus Bank), Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
CVE-2026-66431 2 Woompaloompa, Wordpress 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
CVE-2026-66446 2 If-so Dynamic Content, Wordpress 2 If-so Dynamic Content Personalization, Wordpress 2026-08-14 9.3 Critical
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
CVE-2026-66455 2 Rockiger, Wordpress 2 Reactpress, Wordpress 2026-08-14 6 Medium
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CVE-2026-66459 2 Space Codes, Wordpress 2 Ai For Seo, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.