Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-82384 — Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint

Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor e…

roller | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.2 HIGH
CVE-2026-82383 — Apache Roller: Anonymous setup action allows frontpage configuration tampering

Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection)…

roller | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.1 MEDIUM
CVE-2026-82382 — Apache Roller: Reflected cross-site scripting in the frontpage directory parameter

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a w…

roller | Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.4 MEDIUM
CVE-2026-82381 — Apache Roller: Stored cross-site scripting in the authoring UI

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later writ…

roller | Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.1 HIGH
CVE-2026-82380 — Apache Roller: CSRF protection bypass via self-generated salt validation

Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation…

roller | Remote | Cross-Site Request Forgery
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.7 HIGH
CVE-2026-82379 — Apache Roller: WSSE digest authentication headers can be replayed

Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because …

roller | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.0 CRITICAL
CVE-2026-82378 — Apache Roller: OAuth authorization endpoint trusts request-supplied identity

Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide co…

roller | Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.9 CRITICAL
CVE-2026-82377 — Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers

Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, …

roller | Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.7 HIGH
CVE-2026-82376 — Apache Roller: XML external entity processing in trackback response parser

Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response…

roller | Remote | XML External Entity
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-82375 — Apache Roller: Server-side request forgery via entry trackback and enclosure URLs

Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through le…

roller | Remote | Server-Side Request Forgery
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.7 HIGH
CVE-2026-82348 — Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups

Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another webl…

roller | Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101013 — mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.p…

cloudclassroom-php-project | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101012 — mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulatio…

cloudclassroom-php-project | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.8 MEDIUM
CVE-2026-101011 — aaPanel BaoTa Domain domainMod.py get_domain_status sql injection

A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Ha…

baota | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.8 MEDIUM
CVE-2026-101010 — aaPanel BaoTa data.py getData sql injection

A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads…

baota | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-93000 — SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search

The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to pe…

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-92996 — Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done

The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users t…

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-89411 — Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent

The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pen…

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-89303 — Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-89300 — WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Rec…

The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, …

| Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14108 Results