Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-2506 — EM Cost Calculator <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting via 'customer_n…

The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name'…

cost_calculator | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.4 MEDIUM
CVE-2026-2499 — Custom Logo <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Logo …

The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2 due to insufficient input sanitization and output escapi…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.4 MEDIUM
CVE-2026-2498 — WP Social Meta <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via …

The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output e…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.4 MEDIUM
CVE-2026-2489 — TP2WP Importer <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'W…

The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, …

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.4 MEDIUM
CVE-2026-2029 — Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Contributor+) Stored Cross-S…

The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to…

beaver_builder_addons | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.0 MEDIUM
CVE-2026-27973 — Audiobookshelf has Stored XSS in ItemSearchCard.vue via Audiobook Metadata (Search Result…

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that a…

audiobookshelf | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.6 HIGH
CVE-2026-27970 — Angular i18n vulnerable to Cross-Site Scripting (XSS)

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cros…

angular | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.3 CRITICAL
CVE-2026-27969 — Vitess users with backup storage access can write to arbitrary file paths on restore

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manip…

vitess | Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-27968 — Packistry accepts expired access tokens

Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but di…

packistry | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-27966 — Langflow has Remote Code Execution in CSV Agent

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically expose…

langflow | Remote | Injection
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.9 CRITICAL
CVE-2026-27965 — Vitess users with backup storage access can gain unauthorized access to production deploy…

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manip…

vitess | Remote | Misconfiguration
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-27961 — Agenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allo…

Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vu…

agenta | Remote | Injection
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-27959 — Koa has Host Header Injection via `ctx.hostname`

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before t…

koa | Remote | Information Disclosure
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27954 — LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and tr…

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.…

live_helper_chat livehelperchat | Remote | Authorization
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
9.9 CRITICAL
CVE-2026-27952 — Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a san…

agenta | Remote | Injection
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-27948 — Copyparty vulnerable to eflected cross-site scripting via setck parameter

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

copyparty | Remote | Cross-Site Scripting
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27943 — OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or…

openemr | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27942 — fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with s…

fast-xml-parser fast-xml-parser | Remote | Denial of Service
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
9.9 CRITICAL
CVE-2026-27941 — OpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_reque…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out …

openlit_software_development_kit | Remote | Misconfiguration
Feb 26, 2026 Mar 06, 2026
Feb 26, 2026
Mar 06, 2026
7.7 HIGH
CVE-2026-27938 — WPGraphQL Repo Vulnerable to Command Injection via Unsanitized GitHub Actions Expression …

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command inject…

wpgraphql | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
Showing 20 of 5067 Results