Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-42841 — Grav: Stored XSS via Markdown media attribute() action in Grav CMS

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML thro…

grav grav-plugin-admin | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
9.4 CRITICAL
CVE-2026-42613 — Grav: Privilege Escalation via Missing Server-Side Validation of groups/access

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without…

grav grav-plugin-admin | Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.5 HIGH
CVE-2026-42612 — Grav: Publisher-Level Stored XSS via Unquoted Event Attributes

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue …

grav grav-plugin-admin | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.9 HIGH
CVE-2026-42611 — Grav: Stored XSS via Tag Injection

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated t…

grav grav-plugin-admin | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.5 MEDIUM
CVE-2026-42610 — Grav: Sensitive Information Disclosure via Accounts Service Bypass

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing …

grav grav-plugin-admin | Remote | Information Disclosure
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.1 HIGH
CVE-2026-42609 — Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Lo…

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existi…

grav grav-plugin-admin | Remote | Authorization
May 11, 2026 May 14, 2026
May 11, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-42608 — Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POS…

grav grav-plugin-admin | Remote | Path Traversal
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
9.1 CRITICAL
CVE-2026-42607 — Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Featu…

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file throug…

grav grav-plugin-admin | Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.1 MEDIUM
CVE-2026-3320 — Multiple vulnerabilities in Cradle e-commerce

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitat…

Remote | Cross-Site Scripting
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
5.1 MEDIUM
CVE-2026-3319 — Multiple vulnerabilities in Cradle e-commerce

Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploi…

Remote | Cross-Site Scripting
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.5 HIGH
CVE-2026-34092 — Block UI elements in 'tools'-sidebar shows presence of an autoblocked IP

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue…

mediawiki | Remote | Information Disclosure
May 11, 2026 May 14, 2026
May 11, 2026
May 14, 2026
7.5 HIGH
CVE-2026-34091 — User localization leaked by AbuseFilter + EventStream

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

mediawiki | Remote | Information Disclosure
May 11, 2026 May 14, 2026
May 11, 2026
May 14, 2026
7.5 HIGH
CVE-2026-34090 — Suggested investigations: Handle suppressed usernames

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.

checkuser | Remote | Information Disclosure
May 11, 2026 May 14, 2026
May 11, 2026
May 14, 2026
2.3 LOW
CVE-2026-34089 — Memory leak in Scribunto causes runJobs.php to run out of memory

Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.

Remote
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-34088 — RecentChanges entries expose suppressed content via generated log page html

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

mediawiki | Remote | Information Disclosure
May 11, 2026 May 14, 2026
May 11, 2026
May 14, 2026
7.5 HIGH
CVE-2026-34087 — Users API leaks whether privileged users have their user groups disabled for lack of 2FA

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.

mediawiki | Remote | Information Disclosure
May 11, 2026 May 14, 2026
May 11, 2026
May 14, 2026
2.1 LOW
CVE-2026-34086 — AbuseFilter misuses ::userCanBitfield, exposing access-controlled information

Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2.

Remote
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-31247 — Docling JATS XML Backend XXE DoS

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craf…

Remote | XML External Entity
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
6.5 MEDIUM
CVE-2026-31246 — GPT-Pilot Command Injection Vulnerability

GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the Executor.run() method. During project execution, when the system…

Remote | Injection
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.5 HIGH
CVE-2025-65418 — DocuFORM Managed Print Service Client Directory Traversal Vulnerability

docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.

Remote | Path Traversal
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
Showing 20 of 7378 Results