Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.9 LOW
CVE-2026-15037 — XML injection vulnerability in QDom comment, CDATA and processing-instruction serializati…

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application in…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-65897 — Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that g…

grav | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-65896 — Grav API Plugin before 1.0.10 Path Traversal via move

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug…

grav | Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.5 HIGH
CVE-2026-65895 — Grav API Plugin before 1.0.10 Broken Access Control

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limi…

grav | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-65608 — Grav before 2.0.9 Remote Code Execution via FlexDirectory

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on at…

grav | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-65607 — SiYuan before v3.7.2 Path Traversal via /export/temp/

SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch …

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.6 CRITICAL
CVE-2026-65606 — SiYuan before v3.7.2 Cross-Site Scripting to RCE

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the applic…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.6 CRITICAL
CVE-2026-65605 — SiYuan before v3.7.2 Stored XSS to RCE via Attribute View

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escap…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.9 MEDIUM
CVE-2026-65550 — WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-65540 — WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CS…

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

Remote | Cross-Site Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-65539 — WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

Remote | Cross-Site Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.9 MEDIUM
CVE-2026-65538 — WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-65537 — WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 -…

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-65536 — WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cr…

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

Remote | Cross-Site Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-65535 — WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

Remote | Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.9 MEDIUM
CVE-2026-65534 — WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Site Scripting…

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-65533 — WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.6 HIGH
CVE-2026-65532 — WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.8 MEDIUM
CVE-2026-65531 — WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

qubely | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-65530 — WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9822 Results