Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-105224 — YesWiki before 4.6.7 Stored XSS via Bazar valeur Action

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attacker…

yeswiki | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105089 — WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rende…

avideo | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105086 — WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because …

avideo | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
4.3 MEDIUM
CVE-2026-104402 — WordPress Mindio Magic MCP plugin <= 0.5.6 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a thr…

Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105215 — ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external …

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
2.3 LOW
CVE-2026-105214 — Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The chall…

zitadel | Remote | Server-Side Request Forgery
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-105213 — ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold val…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.7 HIGH
CVE-2026-105212 — ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.2 CRITICAL
CVE-2026-105211 — ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. …

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-105210 — ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only se…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.6 CRITICAL
CVE-2026-105209 — ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollme…

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitad…

zitadel | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.7 HIGH
CVE-2026-105208 — ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted f…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.8 CRITICAL
CVE-2026-105207 — ZITADEL before 4.17.3 Account Takeover via External IdP Linking

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on id…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.3 MEDIUM
CVE-2026-105206 — ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Servi…

ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organiz…

zitadel | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.9 MEDIUM
CVE-2026-105205 — SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled doc…

siyuan | Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-105158 — RainyGao DocSys Database Management BaseController.java BaseController.createDBForMysql s…

A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Managemen…

docsys | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
4.3 MEDIUM
CVE-2026-105157 — RainyGao DocSys Document Controller doGetTmpFile.do DocController.doGetTmp path traversal

A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Con…

docsys | Remote | Path Traversal
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
3.7 LOW
CVE-2026-105156 — YzmCMS MD5 system.func.php password weak password hash

A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argume…

yzmcms | Remote | Cryptography
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-105149 — mooSocial all-products sql injection

A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in …

moosocial | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-105148 — SciPhi-AI R2R Retrieval Completion API Endpoint llm.py server-side request forgery

A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such…

r2r | Remote | Server-Side Request Forgery
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
Showing 20 of 14414 Results