CVE-2026-96546
— Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader
A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ah…
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-96545
— Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized r…
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-96541
— Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake …
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots ind…
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95604
— WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Remote
|
Authorization
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95603
— WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection vulnerabili…
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
Remote
|
Injection
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95602
— WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct Object Refer…
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects YI…
Remote
|
Authorization
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95601
— WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
Remote
|
Injection
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95600
— WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
Remote
|
Authentication
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95593
— WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
Remote
|
Injection
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95592
— WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
Remote
|
Authorization
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95590
— WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability
Subscriber SQL Injection in Tainacan <= 1.2.0 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95586
— WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS…
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95530
— WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Sc…
Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95529
— WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerabi…
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95528
— WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XS…
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
Remote
|
Cross-Site Scripting
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95527
— WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Remote
|
Authorization
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95525
— WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95524
— WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95523
— WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
CVE-2026-95522
— WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Sep 23, 2026