Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-83743 — invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization

A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipul…

invoice_ninja | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-19948 — Cozy Blocks <= 2.2.17 - Missing Authorization to Unauthenticated Unpublished Product Info…

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.…

| Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-77823 — LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient…

| Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-12747 — Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site …

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient inpu…

| Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-19573 — Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via ‘do…

The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient …

| Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-13203 — Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'c…

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modul…

| Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-16787 — Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'd…

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due…

| Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-76006 — Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Para…

The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient e…

| Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-19952 — Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Pat…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and includi…

| Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-75965 — User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all …

| Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-18752 — Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wppl_device_id…

The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user suppl…

| Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-17589 — Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL Injection v…

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escap…

| Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-19806 — Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administra…

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in a…

| Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-75921 — Master Addons for Elementor <= 3.1.9 - Incorrect Authorization to Authenticated (Editor+)…

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versio…

| Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-19796 — Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthent…

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and…

| Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-82749 — Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is…

Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading a…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
2.1 LOW
CVE-2026-82748 — Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under anot…

Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies that do not match the ac…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-82746 — Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to fo…

Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a sing…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-82745 — ETS and Mnesia data layers overwrite an existing record on create instead of enforcing pr…

Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness o…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
2.1 LOW
CVE-2026-82744 — Ash.Reactor change step fails open, skipping a change when its where guard raises

Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so a change meant to run does not. An Ash.Reactor change step c…

ash | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 12189 Results