Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-86211 — rabindralamsal inventory-management-system Login index.php sql injection

A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username…

inventory-management-system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86210 — SourceCodester Class and Exam Timetabling System delete_user_account.php sql injection

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Su…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86209 — SourceCodester Class and Exam Timetabling System delete_user.php sql injection

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql i…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86208 — SourceCodester Class and Exam Timetabling System delete_teacher.php sql injection

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID resu…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2026-80439 — Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execu…

The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's…

redirection_for_contact_form_7 | Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2026-80437 — Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and R…

The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shor…

ninja_forms | Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2026-19862 — JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-19859 — JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Par…

The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registe…

Remote | Information Disclosure
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.5 MEDIUM
CVE-2026-86183 — diem-project diem dmWidget BasedmWidgetActions.class.php authorization

A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component …

diem | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.0 MEDIUM
CVE-2026-86182 — diem-project diem dmConsole actions.class.php executeCommand cross-site request forgery

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmCons…

diem | Remote | Cross-Site Request Forgery
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.0 MEDIUM
CVE-2026-86181 — code-projects Task Management System User Profile Update UpdateUserProfile.php cross site…

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Updat…

task_management_system | Remote | Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86180 — code-projects Task Management System In PHP Login index.php sql injection

A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipu…

task_management_system_in_php | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.5 MEDIUM
CVE-2026-86179 — code-projects Daily Expense Manager Database Backup exp_ak.sql information disclosure

A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a m…

daily_expense_manager | Remote | Information Disclosure
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-86172 — DefaultFuction CRM delete.php sql injection

A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injec…

crm | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-86171 — DefaultFuction CRM delete.php sql injection

A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql inje…

crm | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.3 MEDIUM
CVE-2026-85038 — B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrat…

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one a…

Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-84219 — Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then r…

Remote | Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.8 MEDIUM
CVE-2026-84028 — Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_setti…

The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to…

bold_page_builder | Remote | Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-75793 — SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a…

Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.8 HIGH
CVE-2026-18480 — SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level …

Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
Showing 20 of 12379 Results