Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2026-89004 — WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclos…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributo…

wpematico_rss_feed_fetcher | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.8 MEDIUM
CVE-2026-89002 — WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contri…

wpematico_rss_feed_fetcher | Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-88847 — MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated use…

masterstudy_lms | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-88846 — MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Dis…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registrati…

masterstudy_lms | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-88845 — MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as …

masterstudy_lms | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.2 HIGH
CVE-2026-88843 — MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Wid…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor …

masterstudy_lms | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
3.5 LOW
CVE-2026-84151 — The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-…

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and ab…

the_post_grid | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-82850 — Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the …

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-82849 — Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-regi…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-82195 — 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthentic…

10web_booster | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-80513 — wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscrib…

wpforo_forum | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.8 MEDIUM
CVE-2026-80338 — CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and cor…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.8 MEDIUM
CVE-2026-74991 — WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellat…

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to t…

wpforms | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-14780 — PaperCut NG/MF: Remote Code Execution via Scripting Subsystem

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated …

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-97155 — Fabasoft Folio Client Cross-Origin Request Vulnerability

Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions …

Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.6 HIGH
CVE-2026-97152 — Nanomsg WebSocket Transport Buffer Overflow

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprint…

Remote | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.4 HIGH
CVE-2026-97151 — Mammoth.js Prototype Pollution and Arbitrary File Disclosure

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properti…

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-96898 — yhx070424 ShopXO Ueditor Upload ueditor.php path traversal

A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The …

shopxo | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-96892 — Edimax BR-6428nC goform websRedirect redirect

A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open…

br-6428nc | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-97149 — OpenStack Swift TempURL Middleware Unauthorized Object Access Vulnerability

In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of dis…

swift | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14298 Results