Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-77116 — Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content…

| Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-77115 — Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

| Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-77003 — Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_conte…

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and p…

| Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-14853 — WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Au…

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with S…

| Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-13598 — RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain…

| Authentication
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.4 HIGH
CVE-2026-78063 — Tenda CH22 editFileName formeditFileName command injection

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results…

ch22 | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-78062 — vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of …

Remote | Misconfiguration
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78061 — vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation…

Remote | Server-Side Request Forgery
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78060 — SourceCodester Stock Management System getOrderReport.php cross site scripting

A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argume…

stock_management_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78059 — SourceCodester Stock Management System printOrder.php cross site scripting

A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientN…

stock_management_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78057 — sambitraj Student-Management-System Management Mutation sql injection

A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulati…

student-management-system | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78056 — sambitraj Student-Management-System Dashboard sql injection

A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. Th…

student-management-system | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78055 — SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.8 HIGH
CVE-2026-78136 — CHIRP Eval Injection

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

| Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78054 — SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lea…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.5 MEDIUM
CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This ma…

metube | Remote | Path Traversal
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.9 CRITICAL
CVE-2026-78050 — Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management.…

cf-n1-s | Remote | Memory Corruption
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-18027 — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.…

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the g…

Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
8.8 HIGH
CVE-2026-16149 — Security Hardener <= 2.4.4 - Authenticated (Subscriber+) Privilege Escalation via REST AP…

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protectio…

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
8.8 HIGH
CVE-2026-0551 — PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injecti…

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protect…

password_protect_wordpress | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
Showing 20 of 11580 Results