Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-89333 — Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sens…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter …

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
9.1 CRITICAL
CVE-2026-89274 — WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comm…

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadat…

Remote | Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-89093 — Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP…

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. Thi…

Remote | Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.1 MEDIUM
CVE-2026-89081 — Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-88944 — Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly ver…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.5 HIGH
CVE-2026-87909 — WP Photo Album Plus <= 9.2.09.002 - Authenticated (Subscriber+) Remote Code Execution via…

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart uploa…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
9.8 CRITICAL
CVE-2026-84434 — Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload F…

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field v…

Remote | Misconfiguration
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.5 MEDIUM
CVE-2026-15760 — Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive…

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX acti…

Remote | Information Disclosure
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-15660 — SEO Booster <= 7.4.7 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Opt…

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capability check on the handle_oauth_callback() function …

seo_booster | Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.2 HIGH
CVE-2026-13354 — Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-Site Scriptin…

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input san…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.4 MEDIUM
CVE-2026-12042 — WP2Social Auto Publish <= 2.4.12 - Authenticated (Administrator+) Stored Cross-Site Scrip…

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.4 MEDIUM
CVE-2026-77820 — WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'emp…

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization a…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.8 HIGH
CVE-2026-93923 — SiYuan through 3.8.4 Stored XSS via Heading Style Attribute

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call admin…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.8 HIGH
CVE-2026-93922 — SiYuan through 3.8.4 Stored XSS via notebook names

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
5.3 MEDIUM
CVE-2026-93921 — SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.8 MEDIUM
CVE-2026-77875 — Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in …

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, su…

| Authentication
Sep 19, 2026 Sep 20, 2026
Sep 19, 2026
Sep 20, 2026
10.0 CRITICAL
CVE-2026-93740 — Totolink A3002MU formWlEncrypt buffer overflow

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to bu…

a3002mu | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.9 CRITICAL
CVE-2026-93739 — Totolink A3002MU formWlAc buffer overflow

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to …

a3002mu | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.3 CRITICAL
CVE-2026-75885 — Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via de…

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead…

openshift_container_platform | Remote | Server-Side Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
2.3 LOW
CVE-2026-93894 — Vinyl Cache Workspace Buffer Overflow

In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to …

varnish_cache vinyl_cache | Remote | Memory Corruption
Sep 18, 2026 Sep 19, 2026
Sep 18, 2026
Sep 19, 2026
Showing 20 of 13898 Results