CVE-2026-103439
— Various rawParams() and escaped() updates to prevent XSS in Wikibase extension
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS).
This issue affe…
|
Cross-Site Scripting
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-103438
— Various rawParams() and escaped() updates to prevent XSS in Wikistories extension
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS).
This issue …
|
Cross-Site Scripting
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-103437
— ReadingLists imported metadata permits JavaScript URL XSS
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS.
This issue affects Medi…
Remote
|
Cross-Site Scripting
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-103399
— Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body
A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the bod…
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-102397
— WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
Remote
|
Authorization
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-102392
— WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin…
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
Remote
|
Injection
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-102391
— WordPress JetFormBuilder plugin <= 3.6.5.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
Remote
|
Cross-Site Scripting
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-102377
— WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vulnerability
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
Remote
|
Injection
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-102376
— WordPress Branda plugin <= 3.4.32 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
branda
|
Remote
|
Cross-Site Scripting
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-102375
— WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
Remote
|
Authorization
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-100512
— WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Remote
|
Injection
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-100510
— WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS…
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
Remote
|
Cross-Site Scripting
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware up…
Remote
|
Authentication
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-62308
— Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoi…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to a…
tugtainer
|
Remote
|
Server-Side Request Forgery
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-55494
— Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SE…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not c…
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-55181
— Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oid…
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-55177
— CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched…
CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a f…
Remote
|
Server-Side Request Forgery
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-55176
— Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET`…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticat…
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-46711
— Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfil…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Mach…
|
Path Traversal
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
CVE-2026-19553
— SSLContext.wrap_bio() missing validation of server_hostname parameter
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument
to not be None if ssl.SSLContext.check_hostname was set. Due to a
missing parameter check in SSLObject, if the server_hostname ar…
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Sep 30, 2026