Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-3572 — iTracker360 <= 2.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itr…

The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verific…

Remote | Cross-Site Request Forgery
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
5.3 MEDIUM
CVE-2026-3567 — RepairBuddy <= 4.1132 - Missing Authorization to Authenticated (Subscriber+) Plugin Setti…

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when com…

Remote | Authorization
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
6.4 MEDIUM
CVE-2026-3516 — Contact List <= 3.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_c…

The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in all versions up to, and including, 3.0.18. This is due to insufficient input s…

Remote | Cross-Site Scripting
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
4.9 MEDIUM
CVE-2026-3474 — EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-te…

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the actio…

Remote | Path Traversal
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
7.2 HIGH
CVE-2026-3368 — Injection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Paramete…

The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and including 1.2.9. This is due to insufficient input …

injection_guard | Remote | Cross-Site Scripting
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
6.4 MEDIUM
CVE-2026-3350 — Image Alt Text Manager <= 1.8.2 - Authenticated (Author+) Stored Cross-Site Scripting via…

The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.8.2. This is due to insufficient input sanitiza…

Remote | Cross-Site Scripting
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
2.7 LOW
CVE-2026-3339 — Keep Backup Daily <= 2.1.1 - Authenticated (Admin+) Limited Path Traversal via 'kbd_path'…

The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient v…

keep_backup_daily | Remote | Path Traversal
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-33428 — Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group membership could access deleted posts belonging to a…

discourse | Remote | Authorization
Mar 21, 2026 Mar 24, 2026
Mar 21, 2026
Mar 24, 2026
7.5 HIGH
CVE-2026-33427 — Discourse Authorization Page Displays Unvalidated Redirect Domain

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a legitimate Discourse authorization page to displa…

discourse | Remote | Authorization
Mar 21, 2026 Mar 24, 2026
Mar 21, 2026
Mar 24, 2026
3.8 LOW
CVE-2026-33426 — Discourse users can edit or synonymize hidden tags they can't see

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users with tag-editing permissions could edit and create synonyms for tags hidden in rest…

discourse | Remote | Authorization
Mar 21, 2026 Mar 24, 2026
Mar 21, 2026
Mar 24, 2026
6.9 MEDIUM
CVE-2026-33425 — Discourse has inferable private group membership or existence via exclude_groups parameter

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whether a specific user is a member of a private grou…

discourse | Remote | Information Disclosure
Mar 21, 2026 Mar 24, 2026
Mar 21, 2026
Mar 24, 2026
5.9 MEDIUM
CVE-2026-33424 — PM access granted through invites after access revocation

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacker can grant access to a private message topic through invites even after they l…

discourse | Authorization
Mar 21, 2026 Mar 24, 2026
Mar 21, 2026
Mar 24, 2026
4.3 MEDIUM
CVE-2026-33238 — AVideo has a Path Traversal in listFiles.json.php that Enables Server Filesystem Enumerat…

WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path …

avideo | Remote | Path Traversal
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
5.5 MEDIUM
CVE-2026-33237 — AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable …

avideo | Remote | Server-Side Request Forgery
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
7.5 HIGH
CVE-2026-32666 — Automated Logic WebCTRL Premium Server Authentication Bypass by Spoofing

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with netw…

Remote | Authentication
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
6.4 MEDIUM
CVE-2026-2430 — Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy…

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an over…

autoptimize | Remote | Cross-Site Scripting
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
6.4 MEDIUM
CVE-2026-2352 — Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_…

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input …

autoptimize | Remote | Cross-Site Scripting
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
7.7 HIGH
CVE-2026-25086 — Automated Logic WebCTRL Premium Server Multiple Binds to the Same Port

Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requ…

| Denial of Service
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
9.1 CRITICAL
CVE-2026-24060 — Automated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive Information

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Posi…

Remote | Information Disclosure
Mar 21, 2026 Mar 23, 2026
Mar 21, 2026
Mar 23, 2026
7.5 HIGH
CVE-2026-4508 — PbootCMS Member Login MemberController.php checkUsername sql injection

A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The ma…

pbootcms | Remote | Injection
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
Showing 20 of 6066 Results