Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-32479 — WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulner…

Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-27330 — WordPress Mobile App for WooCommerce plugin <= 0.4.62 - Broken Access Control vulnerabili…

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-78333 — 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an adm…

| Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-78139 — Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR

The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing aut…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-78138 — Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_…

The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticate…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-78137 — StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Pric…

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the car…

| Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-78125 — LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure

The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to …

learnpress | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.4 CRITICAL
CVE-2026-77991 — Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Ev…

Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to…

Remote | Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-77990 — Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user…

Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration da…

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-77989 — Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joom…

Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button UR…

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.1 MEDIUM
CVE-2026-77035 — Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through f…

Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 s…

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.9 MEDIUM
CVE-2026-77034 — Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-p…

Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwri…

Remote | Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-77018 — Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate …

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory…

| Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-77017 — Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via Candidate Pr…

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing use…

| Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-77016 — Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidat…

The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, …

| Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
0.0 NA
CVE-2026-76549 — UpdraftPlus < 1.26.7 - Backup Restoration via CSRF

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin r…

| Cross-Site Request Forgery
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.5 MEDIUM
CVE-2026-59278 — In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types…

JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener con…

spring_for_apache_kafka | Remote | Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.6 MEDIUM
CVE-2026-59275 — Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers St…

A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.5 MEDIUM
CVE-2026-59274 — Unbounded decompression in UnZipTransformer enables zip-bomb DoS

The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denia…

spring_integration | Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-59271 — Admin password disclosed in BrokerNotAliveException message

When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2…

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12225 Results