Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-96577 — Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without …

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the…

openshift_container_platform | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.1 MEDIUM
CVE-2026-83589 — Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability b…

openshift_container_platform | Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-97661 — Business Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cross-Site Scrip…

The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient i…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-96813 — Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on …

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions …

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-96573 — Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scriptin…

The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in a…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.4 MEDIUM
CVE-2026-96268 — Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'g…

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 d…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-95687 — WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege E…

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not pr…

wpc_shop_as_a_customer_for_woocommerce | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-92244 — PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Sit…

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and inclu…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.4 MEDIUM
CVE-2026-90992 — Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via '…

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, and including, 4.5.14 due to insuffici…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.1 MEDIUM
CVE-2026-89427 — Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficie…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.4 MEDIUM
CVE-2026-89424 — Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'no…

The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization …

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-85235 — Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Te…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and inclu…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.1 HIGH
CVE-2026-15983 — Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion vi…

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` …

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-14995 — Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.8 MEDIUM
CVE-2026-103664 — MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter

MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScri…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.1 MEDIUM
CVE-2026-103662 — MISP Reflected XSS in Taxonomy Tag Confirmation Forms

MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag n…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-103659 — MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attri…

MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-103655 — MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-103431 — Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data…

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored ho…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.4 MEDIUM
CVE-2026-101925 — bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Aut…

The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all v…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 15007 Results