Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-89133 — NameConstraints not enforced across unconstrained intermediate CA

wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier betwee…

Remote | Cryptography
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-89102 — OCSP stapling v2 multi accepts non-CA chain certificates as issuers

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables O…

Remote | Cryptography
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.3 LOW
CVE-2026-15442 — Heap use-after-free on read during bidirectional (D)TLS shutdown

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up …

Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.3 LOW
CVE-2026-94419 — Client session cache reference poisoning allows resumption with wrong server

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and …

| Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.3 LOW
CVE-2026-94418 — Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY

Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signatu…

| Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-100741 — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in…

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScri…

Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-97319 — PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor…

powerpress | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-97227 — NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credentia…

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an …

social_networks_auto_poster | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-96899 — Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script

The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head wh…

| Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-96897 — Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Pass…

The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to f…

| Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-96896 — Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Delet…

The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator ro…

| Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-96895 — WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes

The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow user…

wp_youtube_lyte | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-92995 — Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file

The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached …

| Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-92436 — Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via …

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a cus…

mailchimp_for_woocommerce | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-89006 — WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform …

wpematico_rss_feed_fetcher | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-89003 — WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level…

wpematico_rss_feed_fetcher | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-89001 — WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing v…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing us…

wpematico_rss_feed_fetcher | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-89000 — WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing user…

wpematico_rss_feed_fetcher | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-86841 — Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced …

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature…

| Misconfiguration
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-86839 — Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via …

The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the req…

| Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14218 Results