Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-15241 — ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_g…

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's st…

| Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-15206 — SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover vi…

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone…

| Authentication
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-15151 — Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via r…

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by …

| Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-14938 — FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authe…

| Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-14920 — AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter

## Summary

Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-14864 — JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored…

| Cross-Site Scripting
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-14841 — King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing a…

| Cross-Site Scripting
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-18573 — Keycloak-services: keycloak-services: client access-type policy condition bypass during c…

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client polic…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-18572 — Keycloak-services: keycloak-services: uma claim token can override authorization time-pol…

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discove…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.6 MEDIUM
CVE-2026-18571 — Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add t…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
5.4 MEDIUM
CVE-2026-18570 — Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass…

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-9335 — Improper Handling of HDF5 ExternalLinks in keras-team/keras

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load…

Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.8 CRITICAL
CVE-2026-8457 — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Ap…

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the App…

woocommerce_social_login | Remote | Authentication
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.5 HIGH
CVE-2026-18352 — User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Para…

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for una…

Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.5 HIGH
CVE-2026-13339 — CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon …

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unaut…

cubewp | Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.2 HIGH
CVE-2026-18556 — Unauthenticated administrative account takeover

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

n-central | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.2 HIGH
CVE-2026-55735 — Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocati…

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decod…

guardian | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.9 MEDIUM
CVE-2026-55734 — guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1

Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability i…

guardian | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.9 MEDIUM
CVE-2026-55733 — Atom-table exhaustion denial of service in Guardian permissions AtomEncoding via unbounde…

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncodi…

guardian | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.9 MEDIUM
CVE-2026-54894 — Atom-table exhaustion denial of service in Guardian via unbounded atom creation from bina…

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives conn…

guardian | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
Showing 20 of 9297 Results