Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-80180 — Apache Allura: Stored XSS via markdown HTML processing

Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

allura | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-15354 — ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' P…

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allo…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.8 CRITICAL
CVE-2026-70403 — XING CPTrans-ME-X Use of Hard-coded Password

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.8 CRITICAL
CVE-2026-69657 — XING CPTrans-ME-X Use of Default Password

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-66840 — XING CPTrans-ME-X Exposure of Sensitive System Information

XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.

| Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.8 CRITICAL
CVE-2026-62928 — XING CPTrans-ME-X OS Command Injection Vulnerability

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

| Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85094 — Canva Android App WebView Cross-Origin Vulnerability

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s ses…

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.6 CRITICAL
CVE-2026-85085 — Canva Android App WebView Cross-Origin Resource Access Vulnerability

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using t…

Remote | Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-84146 — Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quic…

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product …

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-84066 — Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded fil…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-82194 — WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrar…

| Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-82193 — WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via…

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of …

| Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-82186 — WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL in…

| Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-81347 — Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion…

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to d…

| Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-80438 — Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Inf…

The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to fu…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79632 — WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcod…

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the re…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79631 — WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible L…

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to downl…

| Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79630 — WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substit…

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-74853 — Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, i…

| Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-19224 — Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to …

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12656 Results