Recent CVE entries
Stay updated about the Latest Security Vulnerabilities
Showing 243 CVEs published in the last 12 hours.
| CVE ID & CVSS | Description |
|---|---|
|
CVE-2026-108522
5.5 (Medium)
Show References |
A vulnerability was found in Studio-Saelix Sencho up to 0.94.1. This affects an unknown part of the file /api/auth/login of the component Login Endpoint. Performing a manipulation of the argument X-Forwarded-For results in improper authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The patch is named 79b86ddcd4aefdd6941f098e35990ab397b13c72. To fix this issue, it is recommended to deploy a patch. The vendor confirms: "The login limiter relied on client-supplied X-Forwarded-For data without an explicit trusted-proxy boundary, allowing an attacker to rotate the apparent client address. The remediation now ignores forwarding headers by default, accepts them only from explicitly configured proxy CIDRs, and adds a separate failed-attempt limit keyed by normalized account identity."
Published: October 11, 2026; 4:17:31 AM UTC
13 minutes ago
|
|
|
|
CVE-2026-108521
2 (Low)
Show References |
A vulnerability has been found in Studio-Saelix Sencho up to 0.97.1. Affected by this issue is the function isValidRemoteUrl of the file backend/src/utils/validation.ts of the component Add Remote Node API Endpoint. Such manipulation leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The node API URL could be configured by an authenticated user with node-management permission and used to initiate server-side requests. [T]he report demonstrates server-side request capability but not arbitrary internal response exfiltration."
Published: October 11, 2026; 3:16:39 AM UTC
1 hour ago
|
|
CVE-2026-108708
8.7 (High)
Show References |
Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide.
Published: October 11, 2026; 2:16:39 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108707
9.3 (Critical)
Show References |
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.
Published: October 11, 2026; 2:16:39 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108706
5.3 (Medium)
Show References |
eladmin through commit 55fbf70 contains a missing authorization vulnerability in the downloadS3Storage handler that allows any authenticated user to retrieve stored object URLs without storage permissions. Attackers can enumerate sequential ids against GET /api/s3Storage/download/{id} to collect URLs of all uploaded objects, exposing file contents on publicly readable buckets.
Published: October 11, 2026; 2:16:39 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108705
5.3 (Medium)
Show References |
CordysCRM through 1.9.3 contains a missing authorization vulnerability in the POST /custom-form/data/import endpoint that allows authenticated users to import data into any custom form by customFormId. Low-privileged attackers can upload Excel files with importType ADD or UPDATE to create records in, or overwrite existing records of, custom forms they cannot manage.
Published: October 11, 2026; 2:16:39 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108704
5.3 (Medium)
Show References |
CordysCRM through 1.9.3 contains an authorization bypass vulnerability that allows low-privileged authenticated users to skip permission checks by setting the owner field to their own user id. Attackers can send requests to the follow/record/add endpoints to add follow-up records and overwrite follow_time and follower on any known customer, clue or opportunity.
Published: October 11, 2026; 2:16:38 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108703
5.3 (Medium)
Show References |
CordysCRM through 1.9.3 contains a missing authorization vulnerability in POST /approval-resource/push that allows authenticated users to submit any resource for approval without ownership checks. Low-privileged attackers can supply arbitrary resourceId values for contracts, invoices, quotations or orders to alter their approval status and read approval details.
Published: October 11, 2026; 2:16:38 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108702
5.3 (Medium)
Show References |
1Panel-dev CordysCRM through 1.9.3 lacks a PROCESS_SETTING permission check on POST /approval-flow/webhook/test, allowing any authenticated user to trigger server-side requests to attacker-supplied URLs. Attackers can redirect GET requests from a controlled host to bypass SSRFValidator and probe internal addresses through success or failure results.
Published: October 11, 2026; 2:16:38 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108701
5.3 (Medium)
Show References |
1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability in the ContractController sortModule handler for POST /contract/sort, which lacks any permission annotation. Authenticated users without contract update permission can supply a dragNodeId, stage and field values to modify any contract, including contracts in other organizations.
Published: October 11, 2026; 2:16:38 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108700
7.1 (High)
Show References |
1Panel-dev CordysCRM before 1.9.2 contains a missing authorization vulnerability that allows authenticated users to list business titles by calling POST /field/source/business-title without permission checks. Users lacking CONTRACT_BUSINESS_TITLE_READ can retrieve organization invoicing entities, exposing tax identification numbers, bank account numbers, opening banks, registration addresses, and phone numbers.
Published: October 11, 2026; 2:16:38 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108696
5.3 (Medium)
Show References |
CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderConfirm or supply another reshipId to SendReship to confirm receipt of others' orders and overwrite return tracking details.
Published: October 11, 2026; 2:16:38 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108695
7.1 (High)
Show References |
MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings.
Published: October 11, 2026; 2:16:37 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108694
7.1 (High)
Show References |
ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
Published: October 11, 2026; 2:16:37 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108693
7.3 (High)
Show References |
ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by bare name when Ghostscript is unregistered. Attackers can plant a malicious gswin64c.exe in the working directory to execute code with ImageMagick privileges when PDF, PostScript, or EPS files are converted.
Published: October 11, 2026; 2:16:37 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108692
7.1 (High)
Show References |
1Panel-dev CordysCRM from 1.9.0 before 1.9.2 contains a missing authorization vulnerability in eight ModuleFieldController /field/source data-source endpoints lacking permission checks. Authenticated users denied module permission can page through organization-wide leads, contacts, quotations, contracts, payment plans, payment records, orders and invoices owned by other users.
Published: October 11, 2026; 2:16:37 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108691
5.3 (Medium)
Show References |
mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.
Published: October 11, 2026; 2:16:37 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108690
5.3 (Medium)
Show References |
mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.
Published: October 11, 2026; 2:16:37 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108689
5.3 (Medium)
Show References |
Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content.
Published: October 11, 2026; 2:16:36 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108688
5.3 (Medium)
Show References |
Eladmin through 2.7 contains a missing authorization vulnerability in the LocalStorageController uploadPicture handler that allows low-privileged authenticated users to bypass the storage:add permission. Attackers can send POST requests with image-named files to /api/localStorage/pictures to write files into server local storage and disclose absolute server paths.
Published: October 11, 2026; 2:16:35 AM UTC
2 hours ago
|
|
|
|
CVE-2026-108680
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to send template notifications by calling POST /sys/api/sendTemplateAnnouncement. Low-privileged attackers can supply forged sender, recipients, title, and template parameters to deliver messages appearing to come from admin or system accounts.
Published: October 10, 2026; 10:16:45 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108679
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.
Published: October 10, 2026; 10:16:45 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108678
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRoles handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send GET requests to /sys/api/queryUserRoles with an arbitrary username to enumerate role assignments and identify administrator accounts.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108677
7.1 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in GET /sys/api/getUserByName that allows low-privileged authenticated users to retrieve any user's stored password value. Attackers can decrypt the AES-CBC protected response using the hard-coded key exposed by /sys/getEncryptedString to obtain administrators' password ciphertexts for offline guessing.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108676
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController downLoadFiles handler that allows low-privileged authenticated users to download announcement attachments. Attackers can supply a known announcement id to retrieve a ZIP of attachments from unreleased announcements or those addressed only to other users.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108675
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController editIzTop handler that allows low-privileged authenticated users to change announcement pin status. Attackers can send POST or PUT requests with any announcement id to pin or unpin system notices shown at the top for all users.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108674
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OpenApiController queryById handler that allows low-privileged authenticated users to read OpenAPI definitions without openapi permissions. Attackers can request GET /openapi/queryById with an entry id to obtain internal origin URLs, virtual paths, IP whitelists, and header and parameter templates.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108673
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController exportXls handler that allows any authenticated user to export all AI prompts. Low-privileged attackers can request /airag/prompts/exportXls to download every user's prompts, including prompt content, model ids, and parameters, as an Excel workbook.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108672
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains an authorization bypass vulnerability in the getVideoRecords handler of VideoGenerationController that allows authenticated users to read other users' records via the userId parameter. Low-privileged attackers can supply another user id to retrieve their AI video generation history, including prompts, task ids, video URLs and cover URLs.
Published: October 10, 2026; 10:16:44 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108671
7.1 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to read MCP server configurations because the queryById permission check is commented out. Attackers can obtain record ids from the unguarded /airag/app/queryById endpoint and retrieve MCP endpoint URLs, headers, and outbound authentication tokens.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108670
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the promptExperiment handler of AiragPromptsController that allows any authenticated user to run AI prompt experiments. Low-privileged attackers can supply other users' prompt template and dataset ids to trigger large language model evaluation runs, write result rows into airag_ext_data, and change dataset status.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108669
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the embeddingSearch handler of AiragKnowledgeController that lacks Shiro permission annotations. Low-privileged authenticated attackers can supply knowledge base ids to the GET /airag/knowledge/embedding/search endpoint to read document text chunks from unauthorized knowledge bases.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108668
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController deleteRecycleBin handler that allows any authenticated user to purge AI prompt templates. Low-privileged attackers can send DELETE requests with prompt template ids to permanently remove recycle-bin templates belonging to administrators or other users.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108667
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to restore deleted AI prompt templates by calling the revertRecycleBin endpoint. Attackers can send PUT requests to /airag/prompts/revertRecycleBin with chosen template ids to clear deleted flags, undoing administrator removals.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108666
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the deleteBatch handler of AiragPromptsController that allows any authenticated user to delete AI prompt templates. Low-privileged attackers can obtain prompt ids from the unguarded list endpoint and pass them to deleteBatch to remove templates created by administrators or other users.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108665
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController edit handler that allows any authenticated user to modify AI prompt templates. Low-privileged attackers can send PUT or POST requests to /airag/prompts/edit with a template id to overwrite prompt text and model parameters created by administrators or other users.
Published: October 10, 2026; 10:16:43 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108664
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController queryById handler that allows low-privileged authenticated users to read any AI prompt template. Attackers can enumerate ids via the unguarded /airag/prompts/list endpoint and query each one to obtain prompt text, model parameters, and creator details belonging to administrators or other users.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108663
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController deleteApply handler that allows any authenticated user to reject tenant administrator applications. Low-privileged attackers can send PUT requests with chosen tenantId, packId and userId values to delete pending applications in any tenant and notify applicants of rejection.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108662
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove users from tenant product packs via PUT /sys/tenant/deleteTenantPackUser. Attackers can supply arbitrary userId and packId values in the request body to remove any user from any tenant's product pack, revoking permissions such as tenant administrator access.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108661
7.1 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to transfer tenant ownership via POST /sys/tenant/changeOwenUserTenant. Low-privileged attackers can supply userId and tenantId parameters to reassign any tenant's owner to a member, including themselves, and strip the legitimate owner.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108660
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attackers can supply any tenant id to overwrite its applyStatus field, enabling or disabling tenant administrator applications across tenants.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108659
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController listPackByTenantUserId handler that allows any authenticated user to query tenant product packs. Low-privileged attackers can supply arbitrary tenantId and userId parameters to enumerate any tenant's product pack configuration and reveal which users are tenant administrators.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108658
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController queryTenantAuthInfo handler that allows any authenticated user to read other tenants' records. Low-privileged attackers can iterate small integer tenant ids to retrieve full sys_tenant records, including house numbers used as tenant join codes and company profile fields.
Published: October 10, 2026; 10:16:42 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108657
8.6 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application via doApplyTenantPackUser and approve it through PUT /sys/tenant/passApply to gain tenant administrator pack permissions in any tenant.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108656
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant administrator applications. Low-privileged attackers can iterate the tenantId parameter to retrieve pending applicants' usernames, real names, phone numbers and departments for any tenant.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108655
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the QuartzJobController queryById handler that allows low-privileged authenticated users to read scheduled job records. Attackers can request GET /sys/quartzJob/queryById with a job id to retrieve job class names, cron expressions, job parameters and status reserved for administrators.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108654
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. Attackers who know a record id can request GET /sys/oss/file/queryById to obtain original file names and direct storage URLs of files uploaded by other users.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108653
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108652
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privileged attackers can send PUT requests with a target user id and an arbitrary value, such as an attacker-controlled image URL, to replace administrators' avatars.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108651
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getRolesByUserId handler of SystemApiController that allows authenticated users to retrieve any user's role codes. Low-privileged attackers can supply arbitrary userId values to GET /sys/api/getRolesByUserId to enumerate role assignments and identify administrator accounts.
Published: October 10, 2026; 10:16:41 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108650
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getUserPermissionSet handler of SystemApiController that allows any authenticated user to read other users' permission codes. Low-privileged attackers can supply an arbitrary userId to GET /sys/api/getUserPermissionSet to retrieve the full permission set of any account, including administrators.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108649
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRolesById handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send a userId to GET /sys/api/queryUserRolesById to enumerate role assignments and identify administrator accounts.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108648
7.1 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint of SystemApiController, which lacks Shiro permission or role annotations. Any authenticated low-privileged user can supply datasource codes in the dbSourceCode parameter to retrieve JDBC URLs, usernames and decrypted cleartext database passwords.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108647
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create validation rules through the SysCheckRuleController importExcel handler. Attackers can upload a crafted Excel workbook to bypass the system:checkRule:add permission and bulk-create system-wide encoding validation rules with arbitrary regular expression patterns.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108646
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController importExcel handler that allows any authenticated user to import category dictionary entries. Low-privileged attackers can upload crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary, including under existing parent nodes.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108645
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysCategoryController that allows any authenticated user to edit category dictionary nodes via /sys/category/edit. Low-privileged attackers can send POST or PUT requests supplying a node id to rename, recode, or move system-wide sys_category nodes, altering classification values used across forms.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108644
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController delete handler that allows any authenticated user to delete category dictionary nodes. Low-privileged attackers can obtain node ids from the unguarded rootList and childList endpoints and delete entire sys_category subtrees, breaking dependent forms and dictionary fields.
Published: October 10, 2026; 10:16:40 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108643
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attackers can obtain node ids from the unguarded rootList and childList endpoints and submit them to recursively delete entire sys_category subtrees, breaking dependent forms and dictionary fields.
Published: October 10, 2026; 10:16:39 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108642
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysAnnouncementSendController that allows authenticated users to modify other users' message delivery records. Attackers can obtain delivery ids from GET /sys/sysAnnouncementSend/list and submit edit requests that overwrite read flags, recipient ids, or linked announcements to hide messages from recipients.
Published: October 10, 2026; 10:16:39 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108641
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' in-application messages via the getOne handler of SysAnnouncementSendController. Attackers can obtain delivery record ids from the unguarded /sys/sysAnnouncementSend/list endpoint and supply them as the sendId parameter to retrieve message titles, bodies, senders and recipients.
Published: October 10, 2026; 10:16:39 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108640
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController queryById handler that lacks Shiro permission annotations. Low-privileged authenticated attackers can request GET /sys/sysDepartRole/queryById with any id to read department role names, codes, descriptions and audit fields.
Published: October 10, 2026; 10:16:39 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108639
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to permanently delete data dictionaries via the deletePhysic handler of SysDictController. Low-privileged attackers can send DELETE requests to /sys/dict/deletePhysic/{id} to irreversibly remove active dictionaries and all their items, bypassing the recycle bin.
Published: October 10, 2026; 10:16:39 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108638
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove group memberships via the deleteGroupUser handler in SysUserController. Attackers can send DELETE requests with arbitrary groupId and userId values to remove any user from any administrator-maintained user group without ownership or tenant checks.
Published: October 10, 2026; 10:16:39 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108637
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove user group members by calling DELETE /sys/user/deleteUserGroupBatch. Attackers can supply any groupId and comma-separated userIds to delete sys_ugroup_user rows without permission or tenant checks, tampering with administrator-maintained groups.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108636
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartController appImportExcel handler that allows any authenticated user to import departments. Low-privileged attackers can upload a crafted Excel workbook to POST /sys/sysDepart/appImportExcel to create arbitrary sys_depart records in the administrator-maintained department tree.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108635
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint of SysDepartController that allows any authenticated user to list department staff. Low-privileged attackers can enumerate departId values to retrieve staff names, avatars, posts, and mobile and telephone numbers, including contacts marked hidden.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108634
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete department permission bindings via the DELETE /sys/sysDepartPermission/deleteBatch endpoint. Attackers can obtain row ids from the unguarded list endpoint and submit them in the ids parameter to remove menus and buttons departments can grant to their roles.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108633
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create department permission bindings via POST /sys/sysDepartPermission/add. Attackers can submit arbitrary departId, permissionId and dataRuleIds fields to attach menu, button and data rule grants to any department for delegation to its roles.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108632
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController queryById handler that allows any authenticated user to read department permission records. Low-privileged attackers can request GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id and data_rule_ids for any department.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108631
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController delete handler that allows low-privileged authenticated users to delete department permission bindings. Attackers can obtain row ids from the unguarded list endpoint and send DELETE requests with the id parameter to remove menus or buttons departments can grant their roles.
Published: October 10, 2026; 10:16:38 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108630
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108629
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartPermissionController that allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add or clear data rules on any department-menu permission binding.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108628
8.6 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108627
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108626
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController queryById handler that allows low-privileged authenticated users to read any message push record. Attackers can supply arbitrary record ids to GET /sys/message/sysMessage/queryById to disclose message content and receiver addresses of other users.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108625
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message push records by calling PUT /sys/message/sysMessage/edit. Attackers can submit a request body naming any sys_sms record id to overwrite its title, content, receiver address and send status without ownership checks.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108624
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController deleteBatch handler that allows low-privileged authenticated users to delete message records. Attackers can obtain record ids from the unguarded list endpoint and submit them to deleteBatch to remove any message push records, including pending queued messages.
Published: October 10, 2026; 10:16:37 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108623
7.1 (High)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to delete system audit log entries. Low-privileged attackers can send a DELETE request with ids set to allclear to wipe the entire sys_log table, erasing all users' audit trails.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108622
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController delete handler that allows any authenticated user to delete audit log entries. Low-privileged attackers can obtain log ids from the unguarded /sys/log/list endpoint and delete chosen sys_log records to erase traces of their actions.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108621
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController edit handler that allows any authenticated user to modify organizational positions. Low-privileged attackers can obtain position ids from the unguarded list endpoint and send PUT or POST requests to /sys/position/edit to alter position names, codes, and ranks.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108620
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-privileged attackers can send comma-separated position ids, obtained from the unguarded list endpoint, to remove all sys_position rows and orphan user-position assignments.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108619
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete message templates via the DELETE /sys/message/sysMessageTemplate/deleteBatch endpoint. Attackers can supply comma-separated template ids from the unguarded list endpoint to delete all sys_sms_template rows, breaking template-based notifications such as workflow reminders.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108618
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attackers can obtain template ids from the unguarded list endpoint and overwrite system notification titles and content, delivering attacker-supplied text or links to other users.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108617
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. Attackers holding only minimal roles can insert arbitrary notification templates with chosen codes and content into the shared sys_sms_template library used for system, e-mail, SMS and IM notifications.
Published: October 10, 2026; 10:16:36 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108616
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privileged attackers can send comma-separated ids to DELETE /airag/extData/deleteBatch, which lacks owner or tenant checks, deleting other users' evaluator and test-tracking records.
Published: October 10, 2026; 10:16:35 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108615
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Attackers can send DELETE requests to /airag/extData/delete with any id parameter to remove other users' AI evaluator or test-tracking records without owner or tenant checks.
Published: October 10, 2026; 10:16:35 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108614
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook.
Published: October 10, 2026; 10:16:35 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108613
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI applications. Low-privileged attackers can send POST requests to /airag/app/release to obtain share tokens exposing applications to anonymous chat access, or invalidate existing share links.
Published: October 10, 2026; 10:16:35 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108612
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController deleteBatch handler that allows low-privileged authenticated users to delete word templates. Attackers can send a DELETE request to /airag/word/deleteBatch with comma-separated ids to permanently delete any templates in the shared library.
Published: October 10, 2026; 10:16:35 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108611
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController delete handler that allows any authenticated user to delete word templates. Low-privileged attackers can send DELETE requests to /airag/word/delete with an id parameter to permanently remove any template from the shared library.
Published: October 10, 2026; 10:16:35 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108610
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController edit handler that allows any authenticated user to modify word templates. Low-privileged attackers can send PUT or POST requests to /airag/word/edit to overwrite shared templates that other users rely on to generate documents.
Published: October 10, 2026; 10:16:34 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108609
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech input, voice settings, timestamps, and generated audio file names and paths stored in Redis.
Published: October 10, 2026; 10:16:34 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108608
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI voice records by supplying an arbitrary userId to DELETE /airag/voice/deleteVoiceRecord. Attackers can obtain record ids from the unchecked GET /airag/voice/listByUser endpoint and delete victims' text-to-speech history entries stored in Redis, one per request.
Published: October 10, 2026; 10:16:34 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108607
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request.
Published: October 10, 2026; 10:16:34 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108606
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.
Published: October 10, 2026; 10:16:34 PM UTC
6 hours ago
|
|
|
|
CVE-2026-108605
5.3 (Medium)
Show References |
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis key, corrupting OCR results for all users.
Published: October 10, 2026; 10:16:34 PM UTC
6 hours ago
|
|
|
|
CVE-2026-97853
6.9 (Medium)
Show References |
Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.
Decimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the places argument instead of with the size of the result. For positive places it appends places zero digits to the coefficient as a charlist before converting it to an integer, and for negative places it builds a charlist of -places zero digits. A single call such as Decimal.round(Decimal.new("1.5"), -50_000_000) allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to places.
Any application that passes a user-supplied number of decimal places or scale to Decimal.round/2 or Decimal.round/3 without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the places argument.
This issue affects decimal: from 0.1.0 before 3.1.2.
Published: October 10, 2026; 8:16:47 PM UTC
8 hours ago
|
|
|
|
CVE-2026-81797
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
Published: October 10, 2026; 8:16:47 PM UTC
8 hours ago
|
|
CVE-2026-78535
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
Published: October 10, 2026; 8:16:47 PM UTC
8 hours ago
|
|
CVE-2026-78534
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.
Published: October 10, 2026; 8:16:47 PM UTC
8 hours ago
|
|
CVE-2026-78533
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
Published: October 10, 2026; 8:16:47 PM UTC
8 hours ago
|
|
CVE-2026-78532
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-78531
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-78530
7.7 (High)
Show References |
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-78529
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-66569
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-66568
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-66567
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-66566
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
Published: October 10, 2026; 8:16:46 PM UTC
8 hours ago
|
|
CVE-2026-66565
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-66564
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-66563
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-66483
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-66482
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-66481
6.8 (Medium)
Show References |
Author Arbitrary File Deletion in Presto Player Pro <= 3.0.1 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-66480
5.3 (Medium)
Show References |
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data.
This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.34.0.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-65459
7.5 (High)
Show References |
Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
Published: October 10, 2026; 8:16:45 PM UTC
8 hours ago
|
|
CVE-2026-62130
7.2 (High)
Show References |
Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62129
9.9 (Critical)
Show References |
Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62125
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62124
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in N7 | Golf Club Sports & Events <= 2.21 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62123
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Invetex <= 2.18 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62120
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Law Office <= 3.20 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62118
7.3 (High)
Show References |
Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62117
8.5 (High)
Show References |
Subscriber SQL Injection in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Published: October 10, 2026; 8:16:44 PM UTC
8 hours ago
|
|
CVE-2026-62116
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62115
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in KuteShop <= 4.2.9 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62100
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in KuteShop <= 4.2.9 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62099
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Boutique <= 2.3.3 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62098
6.5 (Medium)
Show References |
Unauthenticated Content Injection in Boutique <= 2.3.3 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62096
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Biolife <= 3.2.3 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62095
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Biolife <= 3.2.3 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62094
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in TechOne <= 3.0.3 versions.
Published: October 10, 2026; 8:16:43 PM UTC
8 hours ago
|
|
CVE-2026-62093
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in TechOne <= 3.0.3 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62092
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Armania <= 1.4.8 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62091
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Armania <= 1.4.8 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62090
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in WineShop <= 3.20 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62087
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Equadio <= 1.1.4 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62086
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Juno <= 2.25 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62082
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Pin WP <= 7.0 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62077
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Avala <= 1.1.4 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62076
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Kalles <= 1.1.7.1 versions.
Published: October 10, 2026; 8:16:42 PM UTC
8 hours ago
|
|
CVE-2026-62075
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Backhoe <= 2.0 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62074
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Ozeum <= 1.3.0 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62070
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Flipmart <= 2.8 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62069
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Fabius <= 1.0 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62068
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Teoro <= 1.1 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62067
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Kaven <= 1.2 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62066
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Volos <= 1.2 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62065
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Cardea <= 2.3 versions.
Published: October 10, 2026; 8:16:41 PM UTC
8 hours ago
|
|
CVE-2026-62064
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Ambed <= 1.0.0 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62054
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Yacht Rental <= 2.6 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62053
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Wine House <= 3.20 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62052
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Tipsy <= 1.6 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62051
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Stargaze <= 1.10 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62050
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Splendour <= 1.23 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62043
7.5 (High)
Show References |
Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62038
7.3 (High)
Show References |
Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
Published: October 10, 2026; 8:16:40 PM UTC
8 hours ago
|
|
CVE-2026-62037
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Document Embedder <= 2.4.0 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62035
6.3 (Medium)
Show References |
Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62034
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62033
7.6 (High)
Show References |
Subscriber Settings Change in uListing <= 2.2.0 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62032
9.8 (Critical)
Show References |
Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62031
9.3 (Critical)
Show References |
Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62030
7.2 (High)
Show References |
Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
Published: October 10, 2026; 8:16:39 PM UTC
8 hours ago
|
|
CVE-2026-62027
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-62025
9 (Critical)
Show References |
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-62024
9.9 (Critical)
Show References |
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-62022
9.8 (Critical)
Show References |
Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-62021
8.8 (High)
Show References |
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-62020
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-57742
7.1 (High)
Show References |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS.
This issue affects Kids Planet: from n/a through 2.2.14.2.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-48194
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.
Published: October 10, 2026; 8:16:38 PM UTC
8 hours ago
|
|
CVE-2026-48193
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-45440
7.6 (High)
Show References |
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-42777
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-42724
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-42723
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-42722
7.6 (High)
Show References |
Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-42719
9.8 (Critical)
Show References |
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
Published: October 10, 2026; 8:16:37 PM UTC
8 hours ago
|
|
CVE-2026-42718
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42717
7.6 (High)
Show References |
Administrator SQL Injection in Leyka <= 3.32.3 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42716
9.8 (Critical)
Show References |
Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42715
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42712
8.5 (High)
Show References |
Subscriber SQL Injection in Qode Tours <= 3.1.3.2 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42711
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Slider by 10Web <= 1.2.63 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42709
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Food Menu – Restaurant Menu & Online Ordering for WooCommerce <= 6.0.5 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42706
7.5 (High)
Show References |
Unauthenticated Broken Access Control in DK <= 3.2.1 versions.
Published: October 10, 2026; 8:16:36 PM UTC
8 hours ago
|
|
CVE-2026-42705
7.5 (High)
Show References |
Unauthenticated Broken Access Control in Grand News <= 3.4 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42704
8.1 (High)
Show References |
Unauthenticated Local File Inclusion in Kids Care <= 3.2.4 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42702
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Tutor LMS <= 4.1.0 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42699
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42697
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42696
10 (Critical)
Show References |
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.19 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42693
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42633
8.5 (High)
Show References |
Subscriber SQL Injection in Events Manager <= 7.4.6 versions.
Published: October 10, 2026; 8:16:35 PM UTC
8 hours ago
|
|
CVE-2026-42632
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Qode Real Estate <= 1.1.7.3 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-42631
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-42630
7.5 (High)
Show References |
Unauthenticated Sensitive Data Exposure in Web Plura Backup & Restore Manager <= 0.2.25 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-42419
5.9 (Medium)
Show References |
Unauthenticated Sensitive Data Exposure in Swish Migrate and Backup <= 1.4.0 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-40808
6.5 (Medium)
Show References |
Subscriber Broken Access Control in Jetpack VideoPress <= 3.6 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-40805
7.7 (High)
Show References |
Subscriber Arbitrary File Deletion in PeepSo <= 9.0.5.4 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-40803
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Jotform – AI Chatbot <= 3.8.2 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-40802
7.6 (High)
Show References |
Subscriber Settings Change in Pubjet | پابجت <= 5.4.8 versions.
Published: October 10, 2026; 8:16:34 PM UTC
8 hours ago
|
|
CVE-2026-40801
8.1 (High)
Show References |
Subscriber Broken Access Control in Wordable <= 8.2.10 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-40800
9.3 (Critical)
Show References |
Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-40777
8.1 (High)
Show References |
Subscriber Broken Access Control in WPSection <= 1.5.1 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-39802
8.1 (High)
Show References |
Unauthenticated Remote Code Execution (RCE) in Everest Backup <= 2.3.13 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-39801
9.8 (Critical)
Show References |
Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-39800
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce <= 1.24 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-39799
7.1 (High)
Show References |
Unauthenticated Cross Site Scripting (XSS) in WP File Download <= 6.3.6 versions.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-27350
7.2 (High)
Show References |
Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery.
This issue affects Builderius: from 1.4 through 1.4-beta.
Published: October 10, 2026; 8:16:33 PM UTC
8 hours ago
|
|
CVE-2026-108604
5.8 (Medium)
Show References |
Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run_query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, or PostgreSQL query_to_xml with embedded DELETE to modify data without approval prompts.
Published: October 10, 2026; 8:16:32 PM UTC
8 hours ago
|
|
|
|
CVE-2026-108603
4.8 (Medium)
Show References |
slide-maker through 5.8.0 contains a path traversal vulnerability in generate_images_openai.py that allows attackers to write image files outside the output directory via manifest-supplied filenames. Attackers can influence deck source material so the image prompt manifest contains ../ or symlinked filenames, creating directories and overwriting existing files at arbitrary paths.
Published: October 10, 2026; 8:16:32 PM UTC
8 hours ago
|
|
|
|
CVE-2026-108602
5.3 (Medium)
Show References |
Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services.
Published: October 10, 2026; 8:16:32 PM UTC
8 hours ago
|
|
|
|
CVE-2026-107434
5.4 (Medium)
Show References |
Subscriber Bypass Vulnerability in MicroPayments <= 3.2.9 versions.
Published: October 10, 2026; 8:16:32 PM UTC
8 hours ago
|
|
CVE-2026-107420
5.3 (Medium)
Show References |
Unauthenticated Bypass Vulnerability in Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway <= 1.7.2 versions.
Published: October 10, 2026; 8:16:32 PM UTC
8 hours ago
|
|
CVE-2026-103685
4.3 (Medium)
Show References |
Missing Authorization vulnerability in VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 2.2.4.
Published: October 10, 2026; 8:16:32 PM UTC
8 hours ago
|
|
CVE-2026-96341
8.2 (High)
Show References |
Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.
Published: October 10, 2026; 7:16:59 PM UTC
9 hours ago
|
|
CVE-2026-94590
6.5 (Medium)
Show References |
Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
CVE-2026-57806
7.1 (High)
Show References |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in drfuri Martfury - WooCommerce Marketplace WordPress Theme martfury allows Reflected XSS.This issue affects Martfury - WooCommerce Marketplace WordPress Theme: from n/a through 3.3.9.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
CVE-2026-108600
5.7 (Medium)
Show References |
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file_write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108599
5.7 (Medium)
Show References |
phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate. Attackers can commit symlinks pointing outside the workspace and use prompt injection to make the write tool write attacker-influenced content to external files without approval.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108598
9.3 (Critical)
Show References |
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108597
5.9 (Medium)
Show References |
Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108596
6 (Medium)
Show References |
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.
Published: October 10, 2026; 7:16:58 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108595
6 (Medium)
Show References |
Phi 0.3.0 through 0.28.4 contains a permission bypass vulnerability that allows spawned sub-agents to escape workspace_only_writes and readonly mode by supplying an unchecked workdir to agent_spawn. Attackers can plant prompt-injected instructions in processed content so the agent spawns a worker rooted elsewhere, causing unapproved file writes anywhere the user can write.
Published: October 10, 2026; 7:16:57 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108594
2.3 (Low)
Show References |
Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.
Published: October 10, 2026; 7:16:57 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108593
7.3 (High)
Show References |
9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call.
Published: October 10, 2026; 7:16:57 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108592
6 (Medium)
Show References |
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
Published: October 10, 2026; 7:16:57 PM UTC
9 hours ago
|
|
|
|
CVE-2026-108591
5.9 (Medium)
Show References |
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials.
Published: October 10, 2026; 7:16:57 PM UTC
9 hours ago
|
|
|
|
CVE-2026-106610
9.8 (Critical)
Show References |
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
Published: October 10, 2026; 7:16:57 PM UTC
9 hours ago
|
|
CVE-2026-105892
9.8 (Critical)
Show References |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.
Published: October 10, 2026; 7:16:56 PM UTC
9 hours ago
|
|
CVE-2026-94160
7.1 (High)
Show References |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeStek ThemeStek Extras for LabtechCO Theme themestek-labtechco-extras allows Reflected XSS.This issue affects ThemeStek Extras for LabtechCO Theme: from n/a through 8.4.
Published: October 10, 2026; 5:17:01 PM UTC
11 hours ago
|
|
CVE-2026-62044
7.2 (High)
Show References |
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
Published: October 10, 2026; 5:17:00 PM UTC
11 hours ago
|
|
CVE-2026-108586
5.3 (Medium)
Show References |
1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.
Published: October 10, 2026; 5:17:00 PM UTC
11 hours ago
|
|
|
|
CVE-2026-108585
5.3 (Medium)
Show References |
argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injected models can supply dot-segment values like ../repositories/ to send authenticated DELETE requests deleting repositories, clusters, or projects within the token's RBAC permissions.
Published: October 10, 2026; 5:17:00 PM UTC
11 hours ago
|
|
|
|
CVE-2026-106609
7.5 (High)
Show References |
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.
Published: October 10, 2026; 5:17:00 PM UTC
11 hours ago
|
|
CVE-2026-106608
7.2 (High)
Show References |
Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
Published: October 10, 2026; 5:17:00 PM UTC
11 hours ago
|
|
CVE-2026-105889
9.3 (Critical)
Show References |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
Published: October 10, 2026; 5:17:00 PM UTC
11 hours ago
|
|
CVE-2026-104398
9.8 (Critical)
Show References |
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.
Published: October 10, 2026; 5:16:59 PM UTC
11 hours ago
|
|
CVE-2026-103357
6.9 (Medium)
Show References |
Missing Authorization vulnerability in VillaTheme GIFT4U gift4u-gift-cards-all-in-one-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GIFT4U: from n/a through 1.1.3.
Published: October 10, 2026; 5:16:59 PM UTC
11 hours ago
|
|
CVE-2026-103071
7.5 (High)
Show References |
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.
Published: October 10, 2026; 5:16:59 PM UTC
11 hours ago
|