Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-88397 — ApiAdmin SQL Injection

ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88396 — ApiAdmin Arbitrary File Upload to Remote Code Execution

ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, …

| Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88395 — GouGuOA SQL Injection Vulnerability

GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88393 — WookTeam Remote Code Execution Vulnerability

WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() functio…

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-37719 — dormakaba evolo Service Remote Code Execution

An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component.

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-105397 — LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explana…

LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fie…

learnpress | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105329 — TallCMS PluginManager ThemeManager.php code injection

A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManager.php of the component PluginManager. Executing …

tallcms | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.7 HIGH
CVE-2026-104892 — Plane: Plaintext logging of API token

Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate …

Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-104891 — mppx-condition-gate: Free-access path grants on a self-declared wallet without proving co…

mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a w…

Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.2 HIGH
CVE-2026-104890 — Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators…

Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions che…

Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.9 MEDIUM
CVE-2026-102780 — Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assi…

Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its…

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-102778 — Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mi…

Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the fr…

Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.1 MEDIUM
CVE-2026-102776 — Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backen…

Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check …

Remote | Cross-Site Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.7 HIGH
CVE-2026-102775 — Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in …

Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the downloa…

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.3 CRITICAL
CVE-2026-102428 — Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < …

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection…

Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-102426 — Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in …

Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fiel…

Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-89039 — CVE-2026-89039 CVE Record

The convert_playwright_script prompt in the k6 MCP server accepts a file path as its playwright_script argument. Paths given in the documented '@'-prefixed form are restricted to the server's current…

Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88394 — WookTeam Directory Traversal

WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is sup…

| Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88392 — Unimall Directory Traversal Remote Code Execution

Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code.

| Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-88391 — Northstar H2 Console Unauthenticated Remote Code Execution

Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and t…

| Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14301 Results