| CVE-2026-108913 |
|
11.10.2026 |
7.1 |
| CVE-2026-107761 |
Channel tokens and organization API key exposed in API responses |
11.10.2026 |
|
| CVE-2026-108902 |
pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link |
11.10.2026 |
|
| CVE-2026-108903 |
pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID |
11.10.2026 |
|
| CVE-2026-108904 |
pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController |
11.10.2026 |
|
| CVE-2026-108905 |
pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header |
11.10.2026 |
|
| CVE-2026-108684 |
erzhongxmu Jeewms Autocomplete Data JeecgFormDemoController.java getTreeData sql injection |
11.10.2026 |
|
| CVE-2026-108683 |
zhayujie CowAgent Media Download memory allocation |
11.10.2026 |
|
| CVE-2026-108866 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserAuths |
11.10.2026 |
|
| CVE-2026-108867 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserRoleSetById |
11.10.2026 |
|
| CVE-2026-108868 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusTemplateAnnouncement |
11.10.2026 |
|
| CVE-2026-108869 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendSysAnnouncement |
11.10.2026 |
|
| CVE-2026-108870 |
JeecgBoot through 3.9.5 Missing Authorization via POST /sys/role/datarule |
11.10.2026 |
|
| CVE-2026-108871 |
JeecgBoot through 3.9.5 Missing Authorization via POST /sys/sysDepartRole/datarule |
11.10.2026 |
|
| CVE-2026-108872 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/batchEditUsers |
11.10.2026 |
|
| CVE-2026-108873 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/doUpdateDepartInfo |
11.10.2026 |
|
| CVE-2026-108874 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/changeDepartChargePerson |
11.10.2026 |
|
| CVE-2026-108875 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/addSysUserGroup |
11.10.2026 |
|
| CVE-2026-108876 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/putCancelQuit |
11.10.2026 |
|
| CVE-2026-108877 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/delete |
11.10.2026 |
|
| CVE-2026-108878 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/app/queryById |
11.10.2026 |
|
| CVE-2026-108879 |
JeecgBoot through 3.9.5 IDOR via /airag/api/getChatVariable Username Parameter |
11.10.2026 |
|
| CVE-2026-108880 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/editDictByLowAppId |
11.10.2026 |
|
| CVE-2026-108881 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/getTenantPackInfo |
11.10.2026 |
|
| CVE-2026-108882 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser |
11.10.2026 |
|
| CVE-2026-108883 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/thirdApp/editThirdAppConfig |
11.10.2026 |
|
| CVE-2026-108884 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Delete Endpoint |
11.10.2026 |
|
| CVE-2026-108885 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/message/sysMessage/delete |
11.10.2026 |
|
| CVE-2026-108886 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/queryChildrenByUsername |
11.10.2026 |
|
| CVE-2026-108887 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/comment/exportXls |
11.10.2026 |
|
| CVE-2026-108888 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/exportXls |
11.10.2026 |
|
| CVE-2026-108891 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/getUserDetailByUserId |
11.10.2026 |
|
| CVE-2026-108682 |
zhayujie CowAgent Web Console upload read denial of service |
11.10.2026 |
|
| CVE-2026-108697 |
CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction |
11.10.2026 |
|
| CVE-2026-108698 |
hyper-mcp through 0.8.3 OCI Plugin Signature Verification TOCTOU Race Condition |
11.10.2026 |
|
| CVE-2026-108699 |
hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins |
11.10.2026 |
|
| CVE-2026-108839 |
thClaws through 0.141.0 Symlink Following File Write via POST /v1/inputs |
11.10.2026 |
|
| CVE-2026-108850 |
Company Research Agent through 2.2.0 SSRF via /generate-pdf ReportLab Markup |
11.10.2026 |
|
| CVE-2026-108851 |
phpMyFAQ through 4.1.10 Missing Authorization via MCP Server faq_search Tool |
11.10.2026 |
|
| CVE-2026-108852 |
Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass |
11.10.2026 |
|
| CVE-2026-108853 |
UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app |
11.10.2026 |
|
| CVE-2026-108854 |
Wanwu before 0.6.3 IDOR AppKey Deletion via DELETE /v1/appspace/app/key |
11.10.2026 |
|
| CVE-2026-108855 |
UnicomAI Wanwu through 0.6.5 Missing Authorization via DELETE /v1/appspace/app/publish |
11.10.2026 |
|
| CVE-2026-108856 |
UnicomAI Wanwu through 0.6.5 Authorization Bypass via /v1/appspace/app/key AppKey Minting |
11.10.2026 |
|
| CVE-2026-108857 |
Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging |
11.10.2026 |
|
| CVE-2026-108858 |
Predibase LoRAX through 0.12.1 API Token Exposure via Router Logs |
11.10.2026 |
|
| CVE-2026-108859 |
mcp-go through 1.2.1 Denial of Service via Unbounded POST Body Buffering |
11.10.2026 |
|
| CVE-2026-108860 |
BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key |
11.10.2026 |
|
| CVE-2026-108861 |
Odoo MCP 1.0.0 through 1.3.2 Information Disclosure via execute_method Tool |
11.10.2026 |
|
| CVE-2026-108862 |
APIPark through 1.9.7-beta IDOR via application authorization endpoints |
11.10.2026 |
|
| CVE-2026-108863 |
Katanemo Plano through 0.4.37 Missing Authentication on Envoy Admin Interface |
11.10.2026 |
|
| CVE-2026-108864 |
iFlytek Astron Agent through 1.1.2 Authorization Bypass via /workflow/v1/resume Endpoint |
11.10.2026 |
|
| CVE-2026-108865 |
AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize |
11.10.2026 |
|
| CVE-2026-108681 |
zhayujie CowAgent Web Console web_channel.py denial of service |
11.10.2026 |
|
| CVE-2026-108584 |
FunnyWolf Viper config hard-coded credentials |
11.10.2026 |
|
| CVE-2026-108578 |
Neterbit NW-431F Embedded Web Server sms.json information disclosure |
11.10.2026 |
|
| CVE-2026-108576 |
TOZED X300 IPPingDiagnostics process_ping os command injection |
11.10.2026 |
|
| CVE-2026-108577 |
Konstanty Bialkowski libmodplug ABC Music Format load_abc.cpp abc_add_gchord resource consumption |
11.10.2026 |
|
| CVE-2026-108710 |
NornicDB through 1.4.1 Missing Authorization via Vector Search Endpoints |
11.10.2026 |
|
| CVE-2026-108711 |
Plastic Labs Honcho through 3.3.0 Incorrect Authorization via POST /v3/workspaces |
11.10.2026 |
|
| CVE-2026-108712 |
SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via DetailUserRole Entry Point |
11.10.2026 |
|
| CVE-2026-108713 |
SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via setCampaignMarketingAndTemplate |
11.10.2026 |
|
| CVE-2026-108714 |
MCP Kotlin SDK through 0.15.0 Memory Exhaustion via Application.mcpWebSocket |
11.10.2026 |
|
| CVE-2026-108715 |
LibreNMS through 26.9.1.1 Authorization Bypass via Smokeping Graph auth.inc.php |
11.10.2026 |
|
| CVE-2026-108716 |
mcp-remote 0.8.0 through 0.14.3 Cleartext Credential Transmission via --device-code OAuth Grant |
11.10.2026 |
|
| CVE-2026-108717 |
Combodo iTop 3.1.0 through 3.3.0 Missing Authorization via LinkSetController |
11.10.2026 |
|
| CVE-2026-108718 |
Rill 0.77.0 through 0.90.5 OAuth Missing Authorization via Dynamic Client Registration |
11.10.2026 |
|
| CVE-2026-108719 |
LLMGateway through 1.20.0 Blind SSRF via Video-Generation callback_url |
11.10.2026 |
|
| CVE-2026-108720 |
phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages |
11.10.2026 |
|
| CVE-2026-108721 |
Open Computer Use through 1.0.0 Denylist Bypass via Case-Variant Bundle ID |
11.10.2026 |
|
| CVE-2026-108722 |
open-computer-use through commit 610bac8 Stored XSS via log.html Session Log |
11.10.2026 |
|
| CVE-2026-108723 |
answer-me-with-html through 0.5.0 Symlink Following in Code Block src Embedding |
11.10.2026 |
|
| CVE-2026-108724 |
Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint |
11.10.2026 |
|
| CVE-2026-108725 |
Cheshire Cat AI core through 2.0.23 Stored XSS via uploads plugin |
11.10.2026 |
|
| CVE-2026-108726 |
GLPI through 12.0.0 Missing Authorization via ajax/map.php |
11.10.2026 |
|
| CVE-2026-108727 |
EdgeEver through 1.108.0 Missing Authorization via Memo-Template API Routes |
11.10.2026 |
|
| CVE-2026-108728 |
Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook |
11.10.2026 |
|
| CVE-2026-108729 |
Corteza through 2024.9.10 Unauthenticated Attachment Access via Compose Attachment Endpoints |
11.10.2026 |
|
| CVE-2026-108730 |
Raven 2.0.0 through 3.0.0 Missing Authorization via Legacy Message and File APIs |
11.10.2026 |
|
| CVE-2026-108731 |
Raven 2.0.0 through 3.0.0 Missing Authorization via join_workspace Invite-Only Bypass |
11.10.2026 |
|
| CVE-2026-108732 |
Frappe HR (hrms) before 16.11.0 Missing Authorization via get_account_and_amount |
11.10.2026 |
|
| CVE-2026-108733 |
Frappe HR (hrms) before 16.11.0 Missing Authorization via expire_allocation |
11.10.2026 |
|
| CVE-2026-108734 |
Frappe CRM 1.49.0 through 1.87.0 Missing Authorization via get_linked_docs_of_document |
11.10.2026 |
|
| CVE-2026-108735 |
Miniflux 2.3.0 through 2.3.3 SSRF via Per-Feed Proxy URL |
11.10.2026 |
|
| CVE-2026-108736 |
Speedtest Tracker through 1.15.0 IP Allowlist Bypass via X-Forwarded-For Spoofing |
11.10.2026 |
|
| CVE-2026-108737 |
Traccar through 6.16.0 Weak Password Recovery via TokenManager Token Purpose Confusion |
11.10.2026 |
|
| CVE-2026-108738 |
Traccar 5.7 through 6.16.0 Login CSRF via OpenID Connect Callback |
11.10.2026 |
|
| CVE-2026-108739 |
OpenAgents Workspace through launcher-v1.0.17 Unauthenticated Credential Exposure via /v1/workspaces |
11.10.2026 |
|
| CVE-2026-108740 |
GoatCounter through 2.7.0 Privilege Escalation via /user/pref Mass Assignment |
11.10.2026 |
|
| CVE-2026-108741 |
Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker |
11.10.2026 |
|
| CVE-2026-108742 |
CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation |
11.10.2026 |
|
| CVE-2026-108744 |
pbi-cli 3.10.1 through 3.12.0 OS Command Injection via Desktop Sync |
11.10.2026 |
|
| CVE-2026-108745 |
CloudBeaver through 25.3.5 Missing Authorization via /api/sql-result-value Servlet |
11.10.2026 |
|
| CVE-2026-108746 |
Vearch 3.5.2 through 3.5.9 Incorrect Authorization via Role.HasPermissionForResources |
11.10.2026 |
|
| CVE-2026-108747 |
Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion |
11.10.2026 |
|
| CVE-2026-108748 |
Quarkus LangChain4j 1.9.0 through 1.14.1 Memory Exhaustion via /_chat/routes WebSocket |
11.10.2026 |
|
| CVE-2026-108749 |
docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints |
11.10.2026 |
|
| CVE-2026-108750 |
OpenDocMan 2.4.0 through 2.10.0 Decompression Bomb DoS via Upload Text Extraction |
11.10.2026 |
|
| CVE-2026-108751 |
MoAI-ADK through 3.1.2 Symlink Following via moai init Template Deployer |
11.10.2026 |
|
| CVE-2026-108752 |
JupyterHub through 6.0.1 OAuth Client ID Collision via Unescaped Hyphen |
11.10.2026 |
|
| CVE-2026-108753 |
Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose |
11.10.2026 |
|
| CVE-2026-108754 |
GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger |
11.10.2026 |
|
| CVE-2026-108755 |
Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint |
11.10.2026 |
|
| CVE-2026-108756 |
Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes |
11.10.2026 |
|
| CVE-2026-108757 |
Nexting pinclaw through 0.3.0 Missing Authentication via POST /pinclaw/send |
11.10.2026 |
|
| CVE-2026-108758 |
Easy!Appointments through 1.6.0 Authorization Bypass via booking/register Endpoint |
11.10.2026 |
|
| CVE-2026-108759 |
mistral.rs 0.9.0 through 0.9.4 Sandbox Escape via Symlink Following in mistralrs-code-exec |
11.10.2026 |
|
| CVE-2026-108760 |
LlamaFarm through 0.0.34 Unauthenticated API Exposed on All Interfaces |
11.10.2026 |
|
| CVE-2026-108575 |
BerriAI LiteLLM Secret Resolution main.py get_secret improper authorization |
11.10.2026 |
|
| CVE-2026-108574 |
BerriAI LiteLLM Spend Tracking spend_management_endpoints.py ui_view_session_spend_logs authorization |
11.10.2026 |
|
| CVE-2026-108573 |
Open Asset Import Library Assimp PLY File getNextBlock out-of-bounds |
11.10.2026 |
|
| CVE-2026-108572 |
Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery |
11.10.2026 |
|
| CVE-2026-108571 |
Xinhu Rainrock RockOA Openkqj Action openkqjAction.php returnchuli sql injection |
11.10.2026 |
|
| CVE-2026-108570 |
Furion .NET Framework View ViewEngine.cs RunCompile special elements in template engine |
11.10.2026 |
|
| CVE-2026-108569 |
Furion .NET Framework StringRenderExtensions.cs String.Replace sql injection |
11.10.2026 |
|
| CVE-2026-108568 |
InstantSoft icms2 Billing paypal.php validatePaypalOrder data authenticity |
11.10.2026 |
|
| CVE-2026-108567 |
InstantSoft icms2 Image image.php files_delete_file path traversal |
11.10.2026 |
|
| CVE-2026-108566 |
InstantSoft icms2 Private Message index.tpl.php index cross site scripting |
11.10.2026 |
|
| CVE-2026-108544 |
Lippu Docx Reader Office Viewer App path traversal |
11.10.2026 |
|
| CVE-2026-108543 |
ag2ai ag2 UserProxyAgent os.path.join path traversal |
11.10.2026 |
|
| CVE-2026-108542 |
021is elvix-sdk MCP Request index.ts server-side request forgery |
11.10.2026 |
|
| CVE-2026-108541 |
highwarden Super Store Finder index.php sql injection |
11.10.2026 |
|
| CVE-2026-103305 |
Prenotazioni <= 1.7.5 - Unauthenticated Stored XSS via Settings Update |
11.10.2026 |
|
| CVE-2026-103694 |
Mobile builder <= 1.4.2 - Subscriber+ Privilege Escalation to Admin |
11.10.2026 |
|
| CVE-2026-103695 |
Mobile Builder <= 1.4.2 - Unauthenticated SQLi via 'vendor_id' Parameter |
11.10.2026 |
|
| CVE-2026-104028 |
Anton Extensions <= 1.2.2 - Unauthenticated Arbitrary File Upload to RCE |
11.10.2026 |
|
| CVE-2026-104680 |
Envira Gallery < 1.16.2 - Multisite Subsite Admin+ Arbitrary Plugin Installation via Onboarding Wizard |
11.10.2026 |
|
| CVE-2026-104681 |
Envira Gallery < 1.16.2 - Author+ Non-Public Post Title and Excerpt Disclosure via Gallery REST Field |
11.10.2026 |
|
| CVE-2026-104682 |
Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route |
11.10.2026 |
|
| CVE-2026-104684 |
Envira Gallery < 1.16.2 - Author+ IDOR via Shortcode |
11.10.2026 |
|
| CVE-2026-106029 |
WeddingCity Lite <= 1.0.4 - Unauthenticated Arbitrary Post and Attachment Deletion |
11.10.2026 |
|
| CVE-2026-107507 |
Squadeno < 1.12.0 - Trainer+ Section and Age Group Reassignment via Quick Edit |
11.10.2026 |
|
| CVE-2026-107694 |
Dokan < 5.2.0 - Vendor+ Cross-Vendor Commission Settings Disclosure via Commission REST Endpoint |
11.10.2026 |
|
| CVE-2026-108540 |
OpenSpug File Transfer transfer os command injection |
11.10.2026 |
|
| CVE-2026-12980 |
Post Snippets <= 4.2.4 - Contributor+ Stored XSS via Snippet Variable |
11.10.2026 |
|
| CVE-2026-14854 |
WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service |
11.10.2026 |
|
| CVE-2026-81153 |
Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Overlay Effect Meta |
11.10.2026 |
|
| CVE-2026-81154 |
Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Alt Text |
11.10.2026 |
|
| CVE-2026-81155 |
Robo Gallery < 5.2.6 - Author+ Stored XSS via Gallery Search Label |
11.10.2026 |
|
| CVE-2026-81156 |
Robo Gallery < 5.2.6 - Contributor+ Stored XSS via Gallery Settings |
11.10.2026 |
|
| CVE-2026-81420 |
Tcard WP <= 1.8.0 - Unauthenticated SQLi via group_id Parameter |
11.10.2026 |
|
| CVE-2026-81649 |
Fundiin <= 3.4.0 - Unauthenticated Payment Gateway Settings Update and Credential Disclosure |
11.10.2026 |
|
| CVE-2026-84251 |
click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Arbitrary Options Update |
11.10.2026 |
|
| CVE-2026-84252 |
click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Arbitrary Options Update |
11.10.2026 |
|
| CVE-2026-84253 |
click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Arbitrary Options Update |
11.10.2026 |
|
| CVE-2026-84254 |
click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Arbitrary Options Update |
11.10.2026 |
|
| CVE-2026-84258 |
click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Stored XSS via post_notifications |
11.10.2026 |
|
| CVE-2026-84259 |
click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Stored XSS via post_notifications |
11.10.2026 |
|
| CVE-2026-84260 |
click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Stored XSS via post_notifications |
11.10.2026 |
|
| CVE-2026-84261 |
click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Stored XSS via post_notifications |
11.10.2026 |
|
| CVE-2026-84734 |
Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pass' Parameter |
11.10.2026 |
|
| CVE-2026-84737 |
Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter |
11.10.2026 |
|
| CVE-2026-85118 |
AI Content Generator Marketing <= 1.0.0 - Unauthenticated Privilege Escalation via Arbitrary Option Update and Deletion |
11.10.2026 |
|
| CVE-2026-85121 |
Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailtemplatedesign |
11.10.2026 |
|
| CVE-2026-85126 |
Crowdfundly <= 2.2.2 - Crowdfundly Manager+ Privilege Escalation |
11.10.2026 |
|
| CVE-2026-86706 |
Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update |
11.10.2026 |
|
| CVE-2026-86717 |
Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup |
11.10.2026 |
|
| CVE-2026-86798 |
HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint |
11.10.2026 |
|
| CVE-2026-87760 |
Web Vitals Tracking <= 5.4.2 - Unauthenticated Stored XSS via Tracking Beacon Metric Name |
11.10.2026 |
|
| CVE-2026-87761 |
Adwised Web Push Notification <= 2.5.7 - Subscriber+ Stored XSS via Pop-up Settings |
11.10.2026 |
|
| CVE-2026-87762 |
Adwised Web Push Notification <= 2.5.7 - Unauthenticated Stored XSS via Secret Key Type Juggling |
11.10.2026 |
|
| CVE-2026-87764 |
BuddyPress Instant Chat <= 1.6 - Unauthenticated Stored XSS via Chat Message |
11.10.2026 |
|
| CVE-2026-88785 |
Simple Membership < 4.8.3 - Newly Registered Member Password Disclosure via URL Query String |
11.10.2026 |
|
| CVE-2026-88826 |
SmugMug Embed <= 3.13 - Unauthenticated Stored XSS via saveSelectedAlbums |
11.10.2026 |
|
| CVE-2026-88827 |
Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords |
11.10.2026 |
|
| CVE-2026-88903 |
Topcontent <= 1.2.1 - Unauthenticated Stored XSS via Content Webhook |
11.10.2026 |
|
| CVE-2026-88905 |
KeyWord Collector <= 1.4 - Unauthenticated Stored XSS and Settings Update via WPKeyWordSettings |
11.10.2026 |
|
| CVE-2026-88930 |
Social Web Suite <= 4.1.12 - Unauthenticated Blind SQLi via Unset Shared Secret |
11.10.2026 |
|
| CVE-2026-89195 |
Site Setup Wizard <= 1.5.8 - Unauthenticated SQLi via ssw_check_admin_email_exists |
11.10.2026 |
|
| CVE-2026-89213 |
Llavero.io <= 0.1.4 - Unauthenticated Blind SQLi via 'cill_login' Parameter |
11.10.2026 |
|
| CVE-2026-89214 |
WpCues Basic Quiz <= 1.6.5 - Unauthenticated SQLi via Quiz Result Submission |
11.10.2026 |
|
| CVE-2026-89232 |
RecordBrowser <= 1.1.7 - Unauthenticated SQLi via 'recordid' Parameter |
11.10.2026 |
|
| CVE-2026-89234 |
WP-Partner <= 1.2.1 - Unauthenticated SQLi via 'id' Parameter |
11.10.2026 |
|
| CVE-2026-89283 |
WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite |
11.10.2026 |
|
| CVE-2026-89285 |
Datalist it <= 0.0.3 - Unauthenticated SQLi via dli_fronted_action |
11.10.2026 |
|
| CVE-2026-89287 |
ASPL Product Quotation <= 1.1.0 - Unauthenticated SQLi via 'quote_id' Parameter |
11.10.2026 |
|
| CVE-2026-89297 |
Loja Automática <= 1.0.0 - Unauthenticated SQLi via 'id' Parameter |
11.10.2026 |
|
| CVE-2026-89299 |
WP Verify API <= 1.0.0 - Unauthenticated SQLi via 'verify' Parameter |
11.10.2026 |
|
| CVE-2026-89302 |
Post Voting System <= 1.0 - Unauthenticated SQLi via 'id' Parameter |
11.10.2026 |
|
| CVE-2026-89304 |
Paymendo Bank Transfer <= 1.1 - Unauthenticated Blind SQLi via 'paymendo_bank_transfer_completed_payment' Parameter |
11.10.2026 |
|
| CVE-2026-89305 |
Paymendo Bank Transfer <= 1.1 - Subscriber+ SQLi via 'orderBy' Parameter |
11.10.2026 |
|
| CVE-2026-91829 |
Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter |
11.10.2026 |
|
| CVE-2026-93550 |
Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process |
11.10.2026 |
|
| CVE-2026-94235 |
Simple User Registration <= 6.9 - Subscriber+ Arbitrary Email Sending via wpr_send_email_to_user |
11.10.2026 |
|
| CVE-2026-96227 |
Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload |
11.10.2026 |
|
| CVE-2026-97183 |
WP-Invoice <= 4.3.1 - Subscriber+ User PII Disclosure via Unprotected AJAX Handlers |
11.10.2026 |
|
| CVE-2026-108539 |
GPAC MP4Box filter_queue.c gf_fq_pop use after free |
11.10.2026 |
|
| CVE-2026-108538 |
GPAC MP4Box os_thread.c gf_mx_v use after free |
11.10.2026 |
|
| CVE-2026-108523 |
Studio-Saelix Sencho git-sources Browse API Endpoint outboundTarget.ts server-side request forgery |
11.10.2026 |
|
| CVE-2026-108522 |
Studio-Saelix Sencho Login Endpoint login improper authentication |
11.10.2026 |
|
| CVE-2026-108521 |
Studio-Saelix Sencho Add Remote Node API Endpoint validation.ts isValidRemoteUrl server-side request forgery |
11.10.2026 |
|
| CVE-2026-108688 |
Eladmin through 2.7 Missing Authorization via /api/localStorage/pictures Upload |
11.10.2026 |
|
| CVE-2026-108689 |
Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST /chat/send |
11.10.2026 |
|
| CVE-2026-108690 |
mall4j through 4.0 Operator Precedence Error Exposes Other Users' Cart Items via /p/shopCart/expiryProdList |
11.10.2026 |
|
| CVE-2026-108691 |
mall4j through 4.0 Operator Precedence Error Deletes Other Users' Cart Items via /p/shopCart/cleanExpiryProdList |
11.10.2026 |
|
| CVE-2026-108692 |
1Panel-dev CordysCRM 1.9.0 before 1.9.2 Missing Authorization via /field/source Endpoints |
11.10.2026 |
|
| CVE-2026-108693 |
ImageMagick through 7.1.2-33 and 6.9.13-58 Uncontrolled Search Path via Ghostscript Delegate |
11.10.2026 |
|
| CVE-2026-108694 |
ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter |
11.10.2026 |
|
| CVE-2026-108695 |
MultiVendorX through 5.0.19 Incorrect Authorization via Settings REST Endpoint |
11.10.2026 |
|
| CVE-2026-108696 |
CoreShop through 1.5.5 Authorization Bypass via OrderController OrderConfirm and SendReship |
11.10.2026 |
|
| CVE-2026-108700 |
1Panel-dev CordysCRM before 1.9.2 Missing Authorization via /field/source/business-title |
11.10.2026 |
|
| CVE-2026-108701 |
1Panel-dev CordysCRM before 1.9.2 Missing Authorization via POST /contract/sort |
11.10.2026 |
|
| CVE-2026-108702 |
CordysCRM through 1.9.3 Missing Authorization and Blind SSRF via Webhook Test |
11.10.2026 |
|
| CVE-2026-108703 |
CordysCRM through 1.9.3 Missing Authorization via /approval-resource/push |
11.10.2026 |
|
| CVE-2026-108704 |
CordysCRM through 1.9.3 Authorization Bypass via Follow-Up Record Add Endpoints |
11.10.2026 |
|
| CVE-2026-108705 |
CordysCRM through 1.9.3 Missing Authorization via /custom-form/data/import |
11.10.2026 |
|
| CVE-2026-108706 |
eladmin through commit 55fbf70 Missing Authorization via S3 Storage Download Endpoint |
11.10.2026 |
|
| CVE-2026-108707 |
Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect |
11.10.2026 |
|
| CVE-2026-108708 |
Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUtil |
11.10.2026 |
|
| CVE-2026-104841 |
|
10.10.2026 |
|
| CVE-2026-108605 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/edit Endpoint |
10.10.2026 |
|
| CVE-2026-108606 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
10.10.2026 |
|
| CVE-2026-108607 |
JeecgBoot through 3.9.5 IDOR via deleteVideoRecord userId Parameter |
10.10.2026 |
|
| CVE-2026-108608 |
JeecgBoot through 3.9.5 IDOR via deleteVoiceRecord userId Parameter |
10.10.2026 |
|
| CVE-2026-108609 |
JeecgBoot through 3.9.5 IDOR via /airag/voice/listByUser userId Parameter |
10.10.2026 |
|
| CVE-2026-108610 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/word/edit Endpoint |
10.10.2026 |
|
| CVE-2026-108611 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint |
10.10.2026 |
|
| CVE-2026-108612 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch |
10.10.2026 |
|
| CVE-2026-108613 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
10.10.2026 |
|
| CVE-2026-108614 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/exportXls |
10.10.2026 |
|
| CVE-2026-108615 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete |
10.10.2026 |
|
| CVE-2026-108616 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/deleteBatch |
10.10.2026 |
|
| CVE-2026-108617 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate/add Endpoint |
10.10.2026 |
|
| CVE-2026-108618 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Edit Endpoint |
10.10.2026 |
|
| CVE-2026-108619 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
10.10.2026 |
|
| CVE-2026-108620 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch |
10.10.2026 |
|
| CVE-2026-108621 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/position/edit |
10.10.2026 |
|
| CVE-2026-108622 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/log/delete Endpoint |
10.10.2026 |
|
| CVE-2026-108623 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch |
10.10.2026 |
|
| CVE-2026-108624 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
10.10.2026 |
|
| CVE-2026-108625 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessage Edit Endpoint |
10.10.2026 |
|
| CVE-2026-108626 |
JeecgBoot through 3.9.5 Missing Authorization via sysMessage queryById Endpoint |
10.10.2026 |
|
| CVE-2026-108627 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/role/datarule Endpoint |
10.10.2026 |
|
| CVE-2026-108628 |
JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
10.10.2026 |
|
| CVE-2026-108629 |
JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission datarule Endpoint |
10.10.2026 |
|
| CVE-2026-108630 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/edit |
10.10.2026 |
|
| CVE-2026-108631 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/delete |
10.10.2026 |
|
| CVE-2026-108632 |
JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission queryById Endpoint |
10.10.2026 |
|
| CVE-2026-108633 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/add |
10.10.2026 |
|
| CVE-2026-108634 |
JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint |
10.10.2026 |
|
| CVE-2026-108635 |
JeecgBoot through 3.9.5 Missing Authorization via getDepartmentHead Endpoint |
10.10.2026 |
|
| CVE-2026-108636 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepart/appImportExcel |
10.10.2026 |
|
| CVE-2026-108637 |
JeecgBoot through 3.9.5 Missing Authorization via deleteUserGroupBatch Endpoint |
10.10.2026 |
|
| CVE-2026-108638 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/user/deleteGroupUser |
10.10.2026 |
|
| CVE-2026-108639 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/deletePhysic/{id} |
10.10.2026 |
|
| CVE-2026-108640 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/queryById |
10.10.2026 |
|
| CVE-2026-108641 |
JeecgBoot through 3.9.5 IDOR via /sys/sysAnnouncementSend/getOne |
10.10.2026 |
|
| CVE-2026-108642 |
JeecgBoot through 3.9.5 IDOR via PUT /sys/sysAnnouncementSend/edit |
10.10.2026 |
|
| CVE-2026-108643 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch |
10.10.2026 |
|
| CVE-2026-108644 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
10.10.2026 |
|
| CVE-2026-108645 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/category/edit |
10.10.2026 |
|
| CVE-2026-108646 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/category/importExcel |
10.10.2026 |
|
| CVE-2026-108647 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/checkRule/importExcel |
10.10.2026 |
|
| CVE-2026-108648 |
JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
10.10.2026 |
|
| CVE-2026-108649 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRolesById |
10.10.2026 |
|
| CVE-2026-108650 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserPermissionSet |
10.10.2026 |
|
| CVE-2026-108651 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getRolesByUserId |
10.10.2026 |
|
| CVE-2026-108652 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/updateAvatar |
10.10.2026 |
|
| CVE-2026-108653 |
JeecgBoot through 3.9.5 Missing Authorization via GET /openapi/list |
10.10.2026 |
|
| CVE-2026-108654 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/oss/file/queryById |
10.10.2026 |
|
| CVE-2026-108655 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/quartzJob/queryById |
10.10.2026 |
|
| CVE-2026-108656 |
JeecgBoot through 3.9.5 Missing Authorization via getTenantPackApplyUsers Endpoint |
10.10.2026 |
|
| CVE-2026-108657 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
10.10.2026 |
|
| CVE-2026-108658 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/queryTenantAuthInfo |
10.10.2026 |
|
| CVE-2026-108659 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/listPackByTenantUserId |
10.10.2026 |
|
| CVE-2026-108660 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/updateApplyStatus |
10.10.2026 |
|
| CVE-2026-108661 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
10.10.2026 |
|
| CVE-2026-108662 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteTenantPackUser |
10.10.2026 |
|
| CVE-2026-108663 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteApply |
10.10.2026 |
|
| CVE-2026-108664 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/queryById |
10.10.2026 |
|
| CVE-2026-108665 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/edit |
10.10.2026 |
|
| CVE-2026-108666 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
10.10.2026 |
|
| CVE-2026-108667 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/revertRecycleBin |
10.10.2026 |
|
| CVE-2026-108668 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin |
10.10.2026 |
|
| CVE-2026-108669 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/knowledge/embedding/search |
10.10.2026 |
|
| CVE-2026-108670 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/experiment |
10.10.2026 |
|
| CVE-2026-108671 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
10.10.2026 |
|
| CVE-2026-108672 |
JeecgBoot through 3.9.5 Authorization Bypass via /airag/video/listByUser |
10.10.2026 |
|
| CVE-2026-108673 |
JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/exportXls |
10.10.2026 |
|
| CVE-2026-108674 |
JeecgBoot through 3.9.5 Missing Authorization via /openapi/queryById |
10.10.2026 |
|
| CVE-2026-108675 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/editIzTop |
10.10.2026 |
|
| CVE-2026-108676 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/downLoadFiles |
10.10.2026 |
|
| CVE-2026-108677 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
10.10.2026 |
|
| CVE-2026-108678 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRoles |
10.10.2026 |
|
| CVE-2026-108679 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusAnnouncement |
10.10.2026 |
|
| CVE-2026-108680 |
JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendTemplateAnnouncement |
10.10.2026 |
|