Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-19338 — automateyournetwork MCPyATS generate_mermaid_markdown index.ts processGenerateRequest pat…

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component genera…

mcpyats | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19337 — adenot mcp-google-search read_webpage index.ts server-side request forgery

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argumen…

mcp-google-search | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19336 — Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the…

spec-workflow-mcp | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19335 — Jane-xiaoer skill-vision-control config.ts getSkillVersionsDir path traversal

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of t…

skill-vision-control | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18603 — Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure …

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allo…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18473 — WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated user…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18465 — WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-c…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18464 — WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it …

| Denial of Service
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18357 — WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensiti…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18037 — Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicat…

The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested c…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18032 — WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Colu…

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, al…

wp_data_access | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-17044 — WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated …

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-17017 — CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation

The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability chec…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-17014 — WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexport…

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the gene…

wp_photo_album_plus | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-17011 — Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection

The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS …

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16992 — Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicat…

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content …

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16988 — GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers RES…

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose th…

geodirectory | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16965 — Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16957 — Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role t…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16032 — LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashbo…

| Cross-Site Scripting
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
Showing 20 of 9659 Results