Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-87839 — Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, …

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.6 MEDIUM
CVE-2026-87068 — Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may imp…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.5 HIGH
CVE-2026-87067 — Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its form…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-85017 — Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it p…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.8 MEDIUM
CVE-2026-84223 — Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing Jav…

Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.1 HIGH
CVE-2026-82842 — SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity b…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.1 LOW
CVE-2026-81654 — NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its g…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.2 MEDIUM
CVE-2026-81653 — NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
2.7 LOW
CVE-2026-81652 — NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Cont…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.1 LOW
CVE-2026-81651 — NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an admi…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.2 HIGH
CVE-2026-81650 — NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a lo…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.1 MEDIUM
CVE-2026-16542 — Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar

The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to p…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.8 MEDIUM
CVE-2026-14844 — Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes

The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the C…

Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.6 MEDIUM
CVE-2026-93965 — aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injec…

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-93964 — NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.v…

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-93963 — itsourcecode Leave Management System controller.php sql injection

A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argumen…

leave_management_system | Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.3 HIGH
CVE-2026-93962 — Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Rec…

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.9 MEDIUM
CVE-2026-93961 — Dromara UJCMS UserController UserController.java usernameExist improper authorization

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.jav…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-93960 — Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such ma…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.8 HIGH
CVE-2026-86553 — A password reset vulnerability in ZTE SmartLife APP

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker c…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13860 Results