CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-108549 cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing 10.10.2026 9.2
CVE-2026-108551 openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates 10.10.2026 9.3
CVE-2026-104803 WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback 10.10.2026 9.8
CVE-2026-62045 WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-62046 WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93927 WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93929 WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93930 WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93931 WordPress Smash theme <= 1.12.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93932 WordPress Smart Casa theme <= 1.0.12 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93933 WordPress Rosalinda theme <= 1.2.4 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93934 WordPress Partiso theme <= 1.1.13 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93935 WordPress Let's Play theme <= 1.1.15 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93936 WordPress IPharm theme <= 1.2.4 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93937 WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93938 WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93940 WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93941 WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93942 WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93943 WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93944 WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93945 WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-104801 PPOM <= 34.0.10 - Unauthenticated Arbitrary File Deletion via 'ppom[fields][<data_name>][n][org]' Parameter 10.10.2026 9.1
CVE-2026-103889 3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'xpv_image' Parameter 10.10.2026 9.8
CVE-2026-97670 Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Field 10.10.2026 9.1
CVE-2026-104732 Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler 10.10.2026 9.8
CVE-2026-107645 Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter 10.10.2026 9.1
CVE-2026-94589 Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.4.5 - Unauthenticated Arbitrary File Upload via Signature Field File Upload 10.10.2026 9.8
CVE-2026-108474 09.10.2026 9.8
CVE-2026-108267 Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session 09.10.2026 9.1
CVE-2026-108268 enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session 09.10.2026 9.1
CVE-2026-108269 ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session 09.10.2026 9.1
CVE-2026-108266 Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session 09.10.2026 9.1
CVE-2026-108264 Wizarr: Authenticated Server-Side Template Injection (SSTI) in wizard step rendering leads to Remote Code Execution (RCE) 09.10.2026 9.1
CVE-2026-108265 enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session 09.10.2026 9.1
CVE-2026-108261 TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment 09.10.2026 9.3
CVE-2026-108263 Astron Agent: Unsandboxed code-node leads to cross-tenant RCE 09.10.2026 9.9
CVE-2026-107845 Contao: Cross-site scripting in the comments bundle 09.10.2026 9.3
CVE-2026-107824 x64dbg-MCP Server exposes debugger operations to unauthenticated network clients 09.10.2026 9.3
CVE-2026-108157 Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking 09.10.2026 9.2
CVE-2026-107806 Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite 09.10.2026 9.4
CVE-2026-15340 Savannah lwIP SMTP client Classic Buffer Overflow 09.10.2026 9.3
CVE-2026-108107 PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php 09.10.2026 9.3
CVE-2026-108109 PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code 09.10.2026 9.3
CVE-2026-28745 Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format 09.10.2026 9.3
CVE-2026-33367 Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function 09.10.2026 9.3
CVE-2026-39460 Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials 09.10.2026 9.3
CVE-2026-105278 Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials 09.10.2026 9.3
CVE-2026-32645 Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials 09.10.2026 9.2
CVE-2026-100730 Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data 09.10.2026 9.3
CVE-2026-86405 Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop 09.10.2026 9.8
CVE-2026-85531 Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x 09.10.2026 9.8
CVE-2026-93947 WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-94503 WordPress Zombify plugin <= 1.7.7 - Arbitrary File Upload vulnerability 09.10.2026 10
CVE-2026-96327 WordPress WPLMS plugin < 1.9.9.8.2 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96328 WordPress JNews - Pay Writer plugin <= 12.0.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96330 WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96331 WordPress Ajax Search Pro plugin <= 4.29.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96809 WordPress EduAdmin Booking plugin < 6.0.0 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-107935 Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose 09.10.2026 9.3
CVE-2026-107908 Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message 09.10.2026 9.3
CVE-2026-107910 Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling 09.10.2026 9.2
CVE-2026-5759 Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB 09.10.2026 9.3
CVE-2026-7827 Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB 09.10.2026 9.2
CVE-2026-69435 Azure SRE Agent Elevation of Privilege Vulnerability 10.10.2026 9.6
CVE-2026-77900 Azure App Service Remote Code Execution Vulnerability 10.10.2026 9.8
CVE-2026-88131 Microsoft Dataverse Remote Code Execution Vulnerability 10.10.2026 9.8
CVE-2026-94510 Microsoft Bookings Elevation of Privilege Vulnerability 10.10.2026 9.9
CVE-2026-96207 Microsoft Partner Center Elevation of Privilege Vulnerability 10.10.2026 10
CVE-2026-107726 Hazelcast: Arbitrary member memory access by low-privileged client 09.10.2026 9.3
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion 08.10.2026 9.8
CVE-2026-75875 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 10.10.2026 9.8
CVE-2026-80381 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 10.10.2026 9.8
CVE-2026-84249 IBM Guardium Data Protection is affected by vulnerability 10.10.2026 9.8
CVE-2026-107406 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 10.10.2026 9.5
CVE-2026-16823 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.1
CVE-2026-16916 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.1
CVE-2026-19491 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.1
CVE-2026-78401 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.8
CVE-2026-78406 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.8
CVE-2026-79842 10.10.2026 9.1
CVE-2026-107779 Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE 08.10.2026 9.3
CVE-2026-107780 Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter 08.10.2026 9.3
CVE-2026-107781 Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById 09.10.2026 9.1
CVE-2026-106126 Command Injection 08.10.2026 9.4
CVE-2026-104075 TVU Networks Receiver/Transceiver Authentication Bypass via /tvu/Login 08.10.2026 9.3
CVE-2026-104076 TVU Networks Receiver/Transceiver Missing Authentication via REST API 09.10.2026 9.3
CVE-2026-84244 IBM Guardium Data Protection Cross-Site Scripting 08.10.2026 9.3
CVE-2026-84272 IBM Guardium Data Protection Missing Authentication 10.10.2026 9.8
CVE-2026-107699 ppt2png through 0.0.6 OS Command Injection via input and output paths 08.10.2026 9.3
CVE-2026-107700 dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument 09.10.2026 9.3
CVE-2026-107703 @enmaso/node-convert through 1.0.0 OS Command Injection via filepath and convertTo 08.10.2026 9.3
CVE-2026-107704 image_optimizer 1.3.0 through 1.9.0 OS Command Injection via identify_format 09.10.2026 9.3
CVE-2026-9209 mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx 08.10.2026 9.3
CVE-2026-14269 IBM DataPower Gateway Buffer Overflow 09.10.2026 9.8
CVE-2026-107640 Integrics Enswitch 3.13 through 4.4 Authentication Bypass via Password Reset API 08.10.2026 9.3
CVE-2026-14502 IBM DataPower Gateway Improper Authentication 09.10.2026 9.8
CVE-2026-14992 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-14990 IBM DataPower Gateway affected by cross-site scripting 08.10.2026 9.3
CVE-2026-14991 IBM DataPower Gateway Out-of-bounds Write 10.10.2026 9.8
CVE-2026-103663 Path Traversal leading to Remote Code Execution in Ollama 08.10.2026 9.4
CVE-2026-15762 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-16340 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-19218 Password Reset Code Brute Force Leading to Account Takeover in AKIN Software's MyRezzta 08.10.2026 9.1
CVE-2026-92555 Database Credentials Disclosure in AKIN Software's AKINSOFT WOLVOX Control Panel 08.10.2026 9.8
CVE-2026-107510 Authenticated argument injection in NIOS command line leading to privilege escalation 09.10.2026 9.1
CVE-2026-105110 Iskratel Innbox Unauthenticated Remote Code Execution via login.xgi CLI Parameter 08.10.2026 9.3
CVE-2026-12260 SQL injection in the NetBoard CRM demo platform 08.10.2026 10
CVE-2026-85097 Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter 08.10.2026 9.8
CVE-2026-107459 Openfind|SecuShare Pro - OS Command Injection 08.10.2026 9.3
CVE-2026-17609 Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter 10.10.2026 9.1
CVE-2026-107282 AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host 10.10.2026 9.4
CVE-2026-76268 Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise 09.10.2026 9.8
CVE-2026-95605 WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability 07.10.2026 9.3
CVE-2026-95606 WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability 07.10.2026 9.8
CVE-2026-20328 Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability 08.10.2026 9.1
CVE-2026-62176 PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation 07.10.2026 9.1
CVE-2026-62252 Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login 07.10.2026 9.8
CVE-2026-62253 Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default) 10.10.2026 9.8
CVE-2026-76454 Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability 07.10.2026 9.1
CVE-2026-76455 Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities 08.10.2026 9.8
CVE-2026-76459 Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Write Vulnerabilities 09.10.2026 9.8
CVE-2026-76464 Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities 07.10.2026 9.6
CVE-2026-76465 Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76471 Cisco NX-OS Software NX-API Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76480 Cisco License On-Prem Security Hardening Release 08.10.2026 9.8
CVE-2026-76482 Cisco License On-Prem Security Hardening Release 08.10.2026 10
CVE-2026-76483 Cisco License On-Prem Security Hardening Release 08.10.2026 9.1
CVE-2026-76485 Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76486 Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76498 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Access Control Vulnerabilities 07.10.2026 9.8
CVE-2026-76499 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization Vulnerabilities 07.10.2026 9.8
CVE-2026-76500 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime Vulnerabilities 08.10.2026 9.8
CVE-2026-76501 Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-92414 Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens 07.10.2026 9.3
CVE-2026-107204 LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint 07.10.2026 9.3
CVE-2026-107194 10.10.2026 9.2
CVE-2026-107183 llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser 07.10.2026 9.2
CVE-2026-96408 07.10.2026 9.3
CVE-2026-105192 LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization 07.10.2026 9.8
CVE-2026-103416 07.10.2026 9.3
CVE-2025-64393 08.10.2026 9.4
CVE-2026-102782 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 08.10.2026 9.3
CVE-2026-107102 Account Takeover Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107103 SQL Injection Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107104 Unsafe Deserialization Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-59346 VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability 07.10.2026 9.3
CVE-2026-19572 FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability 07.10.2026 9.3
CVE-2026-14911 07.10.2026 9.3
CVE-2026-16516 wolfSSH ECDSA host key curve not validated against negotiated algorithm 07.10.2026 9
CVE-2026-19386 08.10.2026 9.3
CVE-2026-105324 An HTTP header injection vulnerability was found in the ADM 07.10.2026 9.2
CVE-2026-104334 Langflow OSS is affected by multiple vulnerabilities 08.10.2026 9.8
CVE-2026-93674 Langflow OSS is affected by multiple vulnerabilities 08.10.2026 9.8
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder 07.10.2026 9.6
CVE-2026-101157 Security Advisory 0192 06.10.2026 9.3
CVE-2026-102159 Security Advisory 0190 06.10.2026 9.3
CVE-2026-102162 Security Advisory 0193 06.10.2026 9.4
CVE-2026-102167 Security Advisory 0197 06.10.2026 9
CVE-2026-106445 Handlebars: JavaScript Injection via Own Property Check Bypass 09.10.2026 9.2
CVE-2026-106446 Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams) 07.10.2026 9.8
CVE-2026-101158 Security Advisory 0185 06.10.2026 9.3
CVE-2026-76750 Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76751 Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution 08.10.2026 9.8
CVE-2026-76752 Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access 08.10.2026 9.8
CVE-2026-76753 Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76754 Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-79794 Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface 08.10.2026 9.1
CVE-2026-79796 Authentication Bypass Vulnerabilities in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-79798 Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface 08.10.2026 9.9
CVE-2026-79801 Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent 08.10.2026 9.8
CVE-2026-79805 Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76742 Authentication Bypass in the Web Management Interface of AOS-S 08.10.2026 9.8
CVE-2026-76743 Authentication Bypass Vulnerability in the Management Interface of AOS-S 08.10.2026 9.8
CVE-2026-76744 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S 08.10.2026 9.8
CVE-2026-76745 Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S 08.10.2026 9.6
CVE-2026-76746 Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S 07.10.2026 9.3
CVE-2026-76747 Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S 07.10.2026 9.1
CVE-2026-86360 06.10.2026 9.6
CVE-2026-106102 Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() 06.10.2026 10
CVE-2026-105863 Payload authentication token field handling issue 09.10.2026 9.2
CVE-2026-105857 Payload: RCE in Payload Form Builder 06.10.2026 10
CVE-2026-105859 Payload: Unauthorized update to collection documents 06.10.2026 9.8
CVE-2026-104070 SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE 09.10.2026 9.3
CVE-2026-105851 Payload: Field access control bypass on auth collections 06.10.2026 9.3
CVE-2026-105844 Payload: Prototype pollution in Payload Import Export plugin 09.10.2026 9.3
CVE-2026-105845 Payload: SQL Injection in SQLite and Postgres 06.10.2026 9.8
CVE-2026-67273 08.10.2026 9.6
CVE-2026-54472 06.10.2026 9.8
CVE-2026-61421 06.10.2026 9.8
CVE-2026-67269 08.10.2026 9.9
CVE-2026-63688 06.10.2026 10
CVE-2026-63692 09.10.2026 10
CVE-2026-105793 Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` 06.10.2026 9.1
CVE-2026-105794 MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL 06.10.2026 9.1
CVE-2026-106037 Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service 06.10.2026 9.3
CVE-2026-91140 OS command injection in Progress Software Autonomous REST Connector GenAI Agents 07.10.2026 9.6
CVE-2026-105835 PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint 09.10.2026 9.1
CVE-2026-82531 Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache 06.10.2026 9.2
CVE-2026-32557 WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-32568 WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability 06.10.2026 9.9
CVE-2026-32579 WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39746 WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39753 WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39755 WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39757 WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39759 WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39761 WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39764 WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39770 WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39773 WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability 06.10.2026 10
CVE-2026-39785 WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39795 WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39797 WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability 06.10.2026 9.8
CVE-2026-41555 WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42415 WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42417 WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-98323 RDMA/siw: Bound fragmented header copies by the remaining length 07.10.2026 9.8
CVE-2026-98365 RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access 07.10.2026 9.8
CVE-2026-85153 Information Disclosure Vulnerability in Schmooze dating mobile Application 06.10.2026 9.3
CVE-2026-105778 Tenda AC5 Wifi setWifi stack-based overflow 06.10.2026 9.4
CVE-2026-94293 Missing authentication for critical function in the aas-edge-client REST API 06.10.2026 9.3
CVE-2026-105484 TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection 06.10.2026 10
CVE-2026-105763 Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL 08.10.2026 9.6
CVE-2026-21589 07.10.2026 9.3
CVE-2026-91107 openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) 06.10.2026 9.3
CVE-2026-105697 Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration 09.10.2026 9.9
CVE-2026-105740 Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server 06.10.2026 9.9
CVE-2026-77226 Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint 07.10.2026 9.2
CVE-2026-105691 Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color 06.10.2026 9.9
CVE-2026-103352 WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability 05.10.2026 9.3
CVE-2026-105636 Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 07.10.2026 9.9
CVE-2026-105637 Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) 05.10.2026 9.6
CVE-2026-105638 Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force 05.10.2026 9.1
CVE-2026-105639 Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane 06.10.2026 9.8
CVE-2026-105640 Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) 05.10.2026 9.1
CVE-2026-105641 Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass 07.10.2026 9.8
CVE-2026-97283 WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability 05.10.2026 9.8
CVE-2026-102428 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 05.10.2026 9.3
CVE-2026-79820 05.10.2026 9
CVE-2026-105285 Totolink A3002MU QoS Rule formIpQoS stack-based overflow 05.10.2026 10
CVE-2026-105284 Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization 05.10.2026 10
CVE-2026-100102 RCE via exposed JDWP debug agent in P4Search 05.10.2026 9.5
CVE-2026-100103 Authentication bypass via default auth token in P4Search 05.10.2026 10
CVE-2026-103510 Authentication bypass via blank auth token in P4Search 05.10.2026 9.5
CVE-2026-105223 maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105293 Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers 05.10.2026 9.2
CVE-2026-105294 Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig 05.10.2026 9.1
CVE-2026-105221 Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105222 alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer 05.10.2026 9.1
CVE-2026-105216 go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper 05.10.2026 9.1
CVE-2026-105218 gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client 05.10.2026 9.1
CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title 05.10.2026 9.3
CVE-2026-105089 WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates 06.10.2026 9.3
CVE-2026-105207 ZITADEL before 4.17.3 Account Takeover via External IdP Linking 06.10.2026 9.3
CVE-2026-105209 ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment 05.10.2026 9.3
CVE-2026-105211 ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode 05.10.2026 9.2
CVE-2026-105215 ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback 05.10.2026 9.3
CVE-2026-103355 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-105134 Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection 05.10.2026 10
CVE-2026-105135 InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection 06.10.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-108579 OpenPanel through 2.3.0 CSV Formula Injection via Cohort Member Export 10.10.2026
CVE-2026-108580 AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login 10.10.2026
CVE-2026-108581 Octop through 1.0.2b6 Missing Authorization Exposes Provider API Keys via /api/providers 10.10.2026
CVE-2026-108582 GenOffice through 0.11.505 Insecure Permissions in HTTP MCP Server File Store 10.10.2026
CVE-2026-108583 zotero-mcp 0.10.0 through 0.14.1 SSRF via zotero_add_by_url Tool 10.10.2026
CVE-2026-108553 OpenRefine through 3.10.1 CSRF to RCE via get-rows Command 10.10.2026
CVE-2026-108554 PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input 10.10.2026
CVE-2026-108555 PairDrop through 1.11.2 IP Spoofing via cf-connecting-ip Header 10.10.2026
CVE-2026-108547 AstronRPA through 1.1.6 Cross-Tenant Shared Variable Disclosure via get-batch-shared-var 10.10.2026
CVE-2026-108548 AstronRPA through 1.1.6 Authentication Bypass via Arbitrary Bearer Token 10.10.2026
CVE-2026-108549 cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing 10.10.2026
CVE-2026-108550 SkillHub before 0.2.22 Account Takeover via Account Merge Flow 10.10.2026
CVE-2026-108551 openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates 10.10.2026
CVE-2026-108114 Strapi 5.47.0 through 5.57.0 Improper Authorization via Admin API Token Field Permissions 10.10.2026
CVE-2026-108115 Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses 10.10.2026
CVE-2026-108545 SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing 10.10.2026
CVE-2026-108546 Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration 10.10.2026
CVE-2026-102388 WordPress Forminator plugin <= 1.57.3 - Cross Site Scripting (XSS) vulnerability 10.10.2026 7.1
CVE-2026-105885 WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability 10.10.2026 8.8
CVE-2026-66435 WordPress WP Rollback plugin <= 3.1.2 - Sensitive Data Exposure vulnerability 10.10.2026 5.9
CVE-2026-94676 WordPress Tainacan plugin <= 1.3.0 - PHP Object Injection vulnerability 10.10.2026 7.2
CVE-2026-97263 WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability 10.10.2026 7.1
CVE-2026-97264 WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability 10.10.2026 7.1
CVE-2026-108161 FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download 10.10.2026
CVE-2026-108162 Pingvin Share X before 1.22.0 Rate Limit Bypass via Spoofed X-Forwarded-For 10.10.2026
CVE-2026-108163 Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL 10.10.2026
CVE-2026-108164 Open Source Social Network (OSSN) through 10.1 IDOR via Message Attachment Route 10.10.2026
CVE-2026-108165 Immich through 3.3.1 Missing Authorization in Partner Sync Exposes Locked Folder Metadata 10.10.2026
CVE-2013-10076 ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list 10.10.2026
CVE-2026-107373 ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument 10.10.2026
CVE-2026-107794 ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list 10.10.2026
CVE-2026-103501 Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow allows memory corruption via a crafted sketch 10.10.2026
CVE-2026-103513 Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch deserialization allows memory corruption via a crafted sketch 10.10.2026
CVE-2026-103635 Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deserialization allows denial of service via a crafted sketch 10.10.2026
CVE-2026-103636 Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization allows denial of service via a truncated sketch 10.10.2026
CVE-2026-106138 Cross-Site Scripting via Chart Tooltip in KendoReact 10.10.2026 5.4
CVE-2026-106139 Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue 10.10.2026 5.4
CVE-2026-108506 Unauthorized access vulnerability in ZTE Z80 Ultra product 10.10.2026 5.5
CVE-2026-108505 Information disclosure vulnerability in ZTE Z80 Ultra product 10.10.2026 3.3
CVE-2026-104722 Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'ix[file]' Parameter 10.10.2026 4.9
CVE-2026-107657 HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribute Value via Registration Form 10.10.2026 7.2
CVE-2026-4791 PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Attribute 10.10.2026 6.4
CVE-2026-91136 Divi Plus <= 2.4.0 - Unauthenticated Arbitrary File Read via 'svg_image' Parameter 10.10.2026 7.5
CVE-2026-93951 WordPress Zeinet theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability 10.10.2026 7.1
CVE-2026-100147 FunnelKit <= 3.16.0.5 - Unauthenticated Stored Cross-Site Scripting via Order Fields (shipping/billing) 10.10.2026 7.2
CVE-2026-100178 WPAdverts <= 2.3.4 - Unauthenticated Stored Cross-Site Scripting via 'adverts_location' Parameter 10.10.2026 7.2
CVE-2026-101920 Molongui Authorship <= 5.2.12 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Comment href Attribute 10.10.2026 7.2
CVE-2026-101921 WPForms <= 2.0.2.1 - Reflected Cross-Site Scripting via 'query_var' Smart Tag in iframe srcdoc Attribute 10.10.2026 4.7
CVE-2026-102291 Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'display_name' 10.10.2026 5.4
CVE-2026-102774 SureDash <= 1.12.1 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via Image 'alt' Attribute in Community Post Content 10.10.2026 6.4
CVE-2026-103478 Premium Packages <= 7.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkout[billing][phone]' Parameter 10.10.2026 6.4
CVE-2026-104728 AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via wp_ajax_automatorwp_fluentform_get_forms AJAX Action 10.10.2026 4.3
CVE-2026-104759 WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via OIDC Nonce Replay via id_token Nonce Verification 10.10.2026 8.1
CVE-2026-104803 WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback 10.10.2026 9.8
CVE-2026-93746 WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 5.0.2 - Insecure Direct Object Reference to Unauthenticated Unauthorized Order Document Access via 'email' Parameter 10.10.2026 7.5
CVE-2026-96278 WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Session History 10.10.2026 7.2
CVE-2026-96563 Motors <= 1.4.123 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'stm_f_s' Parameter 10.10.2026 6.4
CVE-2026-96653 WP Directory Kit <= 1.5.9 - Authenticated (Subscriber+) SQL Injection via 'display_name' Profile Field (Second-Order) 10.10.2026 6.5
CVE-2026-96662 Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_id]' Parameter 10.10.2026 7.5
CVE-2026-96765 WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via 'id_token' Parameter (iss / unique_name JWT claims) 10.10.2026 7.2
CVE-2026-97340 Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'author_facebook' User Profile Field 10.10.2026 6.4
CVE-2026-97396 Email Marketing for WordPress and WooCommerce <= 1.0.10 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter to /updateOptions REST Endpoint 10.10.2026 6.4
CVE-2026-108504 Unauthorized information retrieval vulnerability in ZTE Z80 Ultra product 10.10.2026 5.5
CVE-2026-106606 WordPress YITH WooCommerce Affiliates plugin <= 3.31.0 - PHP Object Injection vulnerability 10.10.2026 7.2
CVE-2026-62045 WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-62046 WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93927 WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93929 WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93930 WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93931 WordPress Smash theme <= 1.12.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93932 WordPress Smart Casa theme <= 1.0.12 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93933 WordPress Rosalinda theme <= 1.2.4 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93934 WordPress Partiso theme <= 1.1.13 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93935 WordPress Let's Play theme <= 1.1.15 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93936 WordPress IPharm theme <= 1.2.4 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93937 WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93938 WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93940 WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93941 WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93942 WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93943 WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93944 WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93945 WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability 10.10.2026 9.8
CVE-2026-93949 WordPress Grocery Shopping Store theme <= 1.3.3 - Broken Authentication vulnerability 10.10.2026 7.1
CVE-2026-93950 WordPress Motors theme <= 1.4.108 - Broken Access Control vulnerability 10.10.2026 7.5
CVE-2026-100161 Photo Reviews for WooCommerce <= 1.2.30 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'wcpr_image_upload_id' Parameter 10.10.2026 7.2
CVE-2026-100196 LazyLoad Plugin <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content 10.10.2026 7.2
CVE-2026-102402 Team <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ttp_filter_taxonomy' Post Meta via [tlpteam] Shortcode 10.10.2026 6.4
CVE-2026-103427 Simple Membership <= 4.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Country Field 10.10.2026 6.4
CVE-2026-103897 Responsive Lightbox & Gallery <= 2.7.9 - Authenticated (Editor+) Stored Cross-Site Scripting via Comment Content 'title' Attribute 10.10.2026 4.4
CVE-2026-104006 SpeedyCache <= 1.4.2 - Unauthenticated Sensitive Information Exposure via Insecure Cache Configuration via Cache Write Gate Missing comment_author_* Cookie Check 10.10.2026 3.7
CVE-2026-104801 PPOM <= 34.0.10 - Unauthenticated Arbitrary File Deletion via 'ppom[fields][<data_name>][n][org]' Parameter 10.10.2026 9.1
CVE-2026-107712 WP Booking System <= 2.1.0.1 - Authenticated (Subscriber+) SQL Injection via 'current_month' Parameter 10.10.2026 6.5
CVE-2026-107742 10Web Booster <= 2.34.8 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name 10.10.2026 7.2
CVE-2026-108502 Information disclosure vulnerability in ZTE Z80 Ultra product 10.10.2026 3.3
CVE-2026-108503 Unauthorized information acquisition vulnerability in ZTE Z80 Ultra product 10.10.2026 3.3
CVE-2026-12626 Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Object Injection via 'value' Parameter 10.10.2026 7.2
CVE-2026-15178 Fluent Forms <= 6.2.5 - Missing Authorization to Authenticated (Custom+) Sensitive Data Exposure and Modification 10.10.2026 5.4
CVE-2026-3717 CV Builder – Professional Resume Builder SaaS <= 1.3.1 - Missing Authorization to Unauthenticated PNG File Upload 10.10.2026 5.3
CVE-2026-5725 Favicon Rotator <= 1.2.11 - Reflected Cross-Site Scripting via 'fvrt_' prefix 10.10.2026 6.1
CVE-2026-6243 Frontend Admin by DynamiApps <= 3.28.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content 10.10.2026 6.4
CVE-2026-89100 Payment Plugins for Stripe WooCommerce <= 4.0.17 - Reflected DOM-Based Cross-Site Scripting via '#response' URL Fragment 10.10.2026 6.1
CVE-2026-94538 WP File Download <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion/Modification via 'task' Parameter to Multiple Functions 10.10.2026 8.1
CVE-2026-95684 VikBooking Hotel Booking Engine & PMS <= 1.8.15 - Unauthenticated Stored Cross-Site Scripting via 'attachments[name]' Parameter 10.10.2026 7.2
CVE-2026-96558 Quiz and Survey Master (QSM) <= 11.2.6 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'qsm_hidden_questions' Parameter 10.10.2026 7.2
CVE-2026-96572 WP Meteor Website Speed Optimization Addon <= 3.4.18 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name 10.10.2026 7.2
CVE-2026-96574 User Frontend <= 4.3.12 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpuf_payment_method' Parameter 10.10.2026 6.4
CVE-2026-96840 Post Grid Gutenberg Blocks <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting via display_name User Field 10.10.2026 7.2
CVE-2026-97348 SiteOrigin Widgets Bundle <= 1.74.3 - Authenticated (Contributor+) Arbitrary File Read via LESS Injection via [siteorigin_widget] Shortcode 'value' JSON Instance (design.colors LESS Variable) 10.10.2026 6.5
CVE-2026-104752 Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import 10.10.2026
CVE-2026-104753 Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter 10.10.2026
CVE-2026-104754 Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL 10.10.2026
CVE-2026-105976 Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX Actions 10.10.2026
CVE-2026-105977 Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion via pfg_delete_video_thumbnail 10.10.2026
CVE-2026-105989 Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status Forgery 10.10.2026
CVE-2026-105990 Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via CSV Export 10.10.2026
CVE-2026-105995 Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure 10.10.2026
CVE-2026-107120 Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN 10.10.2026
CVE-2026-107321 W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import 10.10.2026
CVE-2026-107323 Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS 10.10.2026
CVE-2026-85571 Tutor LMS 4.0.5 - 4.1.0 - Instructor+ Arbitrary Post Reparenting via IDOR 10.10.2026
CVE-2026-87780 LTL Freight Quotes – Old Dominion Edition < 4.2.19 - Unauthenticated Stored XSS via Shipping Rules 10.10.2026
CVE-2026-87781 LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipping Rule 'edit_id' Parameter 10.10.2026
CVE-2026-94256 SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP 10.10.2026
CVE-2026-94257 SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Reset 10.10.2026
CVE-2026-103482 Simple Newsletter Plugin <= 4.3.10 - Unauthenticated Stored Cross-Site Scripting via Subscriber Custom Field via Manage Preferences Form + Campaign Preview noptin_key Pivot 10.10.2026 5.4
CVE-2026-103520 HivePress <= 1.7.31 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Listing Attribute Value in Administrator-configured HTML Format 10.10.2026 6.4
CVE-2026-103912 JetFormBuilder <= 3.6.6 - Reflected DOM-Based Cross-Site Scripting via 'query_var' Dynamic Preset via data-jfb-macro / JFB_FIELD:: Macro Renderer 10.10.2026 4.7
CVE-2026-104023 Smart Popup by Supsystic <= 1.13.2 - Authenticated (Administrator+) SQL Injection via 'sidx' Parameter 10.10.2026 4.9
CVE-2026-104723 LifterLMS <= 10.2.1 - Authenticated (Custom+) PHP Object Injection via 'custom' Lesson Data 10.10.2026 8.8
CVE-2026-104725 Groundhogg <= 4.9 - Authenticated (Custom+) Privilege Escalation to 'user' Parameter 10.10.2026 8.8
CVE-2026-104741 AI Puffer <= 2.4.89 - Missing Authorization to Authenticated (Subscriber+) Global Plugin Settings Modification via ajax_save_cpt_indexing_options AJAX Endpoint 10.10.2026 3.1
CVE-2026-104742 AI Puffer <= 2.4.89 - Missing Authorization to Authenticated (Subscriber+) Semantic Search Settings Modification via ajax_save_semantic_search_settings AJAX action 10.10.2026 3.1
CVE-2026-104762 Kadence Blocks <= 3.7.12 - Authenticated (Author+) Stored Cross-Site Scripting via Block Font Family Attribute 10.10.2026 6.4
CVE-2026-104763 Post Export Import with Media <= 1.17.1 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_path' Parameter in media_metadata.json 10.10.2026 4.9
CVE-2026-104766 Appointment Booking Plugin <= 5.7.3 - Authenticated (Custom+) Privilege Escalation to 'settings[default_wp_role_for_customer]' Parameter 10.10.2026 8.8
CVE-2026-104899 GeoDirectory <= 2.8.187 - Unauthenticated Local File Inclusion via 'design_type' Parameter 10.10.2026 8.1
CVE-2026-12054 Download Manager <= 3.3.57 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via 'REFERRER' Parameter 10.10.2026 6.1
CVE-2026-14335 Easy Digital Downloads <= 3.6.9 - Unauthenticated Stored Cross-Site Scripting via PayPal IPN Parameters 10.10.2026 7.2
CVE-2026-14379 GamiPress <= 7.9.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'video_id' Parameter 10.10.2026 6.4
CVE-2026-14877 Data Tables Generator by Supsystic <= 1.12.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table 'id' HTML Attribute 10.10.2026 6.4
CVE-2026-14882 Brizy <= 2.8.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'brizy-compiled-sections' Post Meta 10.10.2026 6.4
CVE-2026-16776 MP3 Audio Player <= 5.14.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 10.10.2026 6.4
CVE-2026-17025 Graphene <= 2.9.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Fields 10.10.2026 6.4
CVE-2026-18496 Booking Calendar <= 11.4.3 - Unauthenticated Sensitive Information Exposure in 'WPBC_FLEXTIMELINE_NAV' AJAX Action 10.10.2026 5.3
CVE-2026-18558 Embed Any Document <= 2.7.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'embeddoc' Shortcode 10.10.2026 6.4
CVE-2026-77183 FooSales <= 1.43.0 - Authenticated (Custom+) Privilege Escalation via create_update_customer REST Endpoint 10.10.2026 8.8
CVE-2026-78068 Table Field Add-on for ACF and SCF <= 1.3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table Cell Content 10.10.2026 6.4
CVE-2026-83526 FV Player 8 <= 8.1.7 - Authenticated (Subscriber+) Arbitrary File Upload via videos[].fv_wp_flowplayer_field_src Parameter 10.10.2026 8.8
CVE-2026-91050 Appointment Booking Plugin <= 5.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Unauthorized Booking Creation and Sensitive Information Disclosure via 'params[presets][order_item_id]' Parameter 10.10.2026 4.3
CVE-2026-91862 Getwid <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-image-points' 10.10.2026 6.4
CVE-2026-92975 Groundhogg <= 4.8.3 - Unauthenticated Privilege Escalation to Support User Identity Confusion 10.10.2026 8.1
CVE-2026-93775 Podlove Podcast Publisher <= 4.5.6 - Unauthenticated Stored Cross-Site Scripting via Auphonic Webhook 10.10.2026 7.2
CVE-2026-94375 Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive File Exposure via Missing Directory Guard Re-verification in get_file_path() 10.10.2026 5.3
CVE-2026-94421 Church Admin <= 5.1.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'email' Parameter 10.10.2026 6.4
CVE-2026-96667 Real Estate Manager <= 7.3 - Unauthenticated Stored Cross-Site Scripting via 'first_name' Parameter 10.10.2026 7.2
CVE-2026-96682 Presto Player <= 4.5.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content via <presto-player> Tag 10.10.2026 7.2
CVE-2026-97643 GiveWP <= 4.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via givewp_campaign_grid Shortcode Attributes 10.10.2026 6.4
CVE-2026-101324 Fluent Forms <= 6.2.14 - Reflected Cross-Site Scripting via '{get.*}' Editor SmartCode Parameter 10.10.2026 4.7
CVE-2026-102401 Download Manager <= 3.3.71 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'regurl' Shortcode Attribute 10.10.2026 6.4
CVE-2026-103424 Anti-Spam by CleanTalk <= 6.88 - Unauthenticated Stored Cross-Site Scripting via Comment Content via ContactsEncoder Greedy Regex 10.10.2026 5.4
CVE-2026-103889 3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'xpv_image' Parameter 10.10.2026 9.8
CVE-2026-103964 Download Manager <= 3.3.71 - Authenticated (Subscriber+) Sensitive Information Exposure via Email Template Token Injection in 'first_name' Profile Field Token Injection into Suspension Email 10.10.2026 4.3
CVE-2026-103998 Form Maker by 10Web <= 1.15.48 - Reflected Cross-Site Scripting via 'inputs' Parameter Array Key 10.10.2026 6.1
CVE-2026-104021 Fastcache by Host.it <= 1.7.4 - Authenticated (Administrator+) Code Injection via .htaccess Directive Injection via 'cache_cookie_exclude' Setting 10.10.2026 7.2
CVE-2026-104724 FireBox <= 3.1.13 - Authenticated (Author+) SQL Injection via FireBox Form Display Condition 10.10.2026 5.3
CVE-2026-104735 RSS Aggregator by Feedzy <= 5.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> 10.10.2026 6.4
CVE-2026-104993 GeoDirectory <= 2.8.188 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Contact Email Custom Field 10.10.2026 6.4
CVE-2026-5727 Hello Plus <= 1.7.7 - Authenticated (Contributor+) Missing Authorization to Template Activation via hello_plus_set_as_entire_site 10.10.2026 5.4
CVE-2026-6723 Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Token 10.10.2026 5.3
CVE-2026-87869 Filter Everything — WordPress & WooCommerce Filters <= 1.9.6 - Reflected Cross-Site Scripting via Elementor Posts Widget Pagination URL 10.10.2026 6.1
CVE-2026-89301 rtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Missing Authorization to Unauthenticated Limited File Read/Disclosure and Limited File Deletion via Sideload via 'files[tmp_name]' Parameter 10.10.2026 7.5
CVE-2026-96648 Data Tables Generator by Supsystic <= 1.15.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action 10.10.2026 6.4
CVE-2026-97630 FV Flowplayer Video Player <= 7.5.54.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute 10.10.2026 6.4
CVE-2026-97670 Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Field 10.10.2026 9.1
CVE-2026-9696 Download Manager <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_packages Shortcode 10.10.2026 6.4
CVE-2026-108501 Unauthorized access vulnerability in ZTE Z80 Ultra product 10.10.2026 5.7
CVE-2026-103365 Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information Exposure in 'phone' Parameter to bookly_render_details 10.10.2026 5.3
CVE-2026-104732 Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler 10.10.2026 9.8
CVE-2026-104797 Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action 10.10.2026 8.1
CVE-2026-104898 Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via 'id' and 'wp_user_id' Parameters via Query String / JSON Body 10.10.2026 6.8
CVE-2026-107645 Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter 10.10.2026 9.1
CVE-2026-94589 Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.4.5 - Unauthenticated Arbitrary File Upload via Signature Field File Upload 10.10.2026 9.8
CVE-2026-96743 Table Field Add-on for ACF and SCF <= 1.4.1-RC2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Table Field Value 10.10.2026 6.4
CVE-2026-101947 ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export 10.10.2026
CVE-2026-104022 Academy LMS <= 4.0.3 - Authenticated (Custom+) Privilege Escalation to add_child REST endpoint 10.10.2026 5.4
CVE-2026-104915 Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id 10.10.2026 6.5
CVE-2026-93883 Advanced Classifieds & Directory Pro <= 3.4.4 - Authenticated (Custom+) Stored Cross-Site Scripting via 'phone' Parameter 10.10.2026 6.4
CVE-2026-108474 09.10.2026 9.8
CVE-2026-103755 09.10.2026
CVE-2026-16681 09.10.2026
CVE-2026-18524 09.10.2026
CVE-2026-22061 CVE-2026-22061 Debug Log Information Disclosure Vulnerability in Trident 09.10.2026