Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-93618 — WordPress JetTricks plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a th…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-93529 — WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerabi…

Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.5 HIGH
CVE-2026-93527 — WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.1 HIGH
CVE-2026-93526 — WordPress Event Tickets plugin <= 5.29.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.3 MEDIUM
CVE-2026-93513 — WordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerabil…

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-93421 — Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and viola…

mesop | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.4 HIGH
CVE-2026-92730 — LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via …

LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.

limesurvey | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.3 MEDIUM
CVE-2026-92700 — Caddy: fileHidden() case-sensitive pattern bypass — exposes "hidden" files via case varia…

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks,…

caddy | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.9 MEDIUM
CVE-2026-92692 — Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Su…

sulu | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.9 MEDIUM
CVE-2026-92284 — Caddy: Unbounded body buffer via {http.request.body} placeholder — memory exhaustion DoS

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body reads the complete request body with an u…

caddy | Remote | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-90905 — Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration…

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=a…

Remote | Cross-Site Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.6 HIGH
CVE-2026-90904 — Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController R…

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded retu…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-90903 — Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator …

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF t…

Remote | Cross-Site Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-90902 — Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bul…

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com…

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.6 HIGH
CVE-2026-90901 — Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Imag…

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest …

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-90900 — Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product…

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?opt…

Remote | Cross-Site Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-90899 — Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checko…

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.9 CRITICAL
CVE-2026-84502 — Automation-controller: automation-controller-container: automation-controller: project sc…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.7 HIGH
CVE-2026-84499 — Automation-controller: automation-controller-container: automation-controller: write-only…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When …

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-84486 — Automation-controller: automation-controller-container: automation-controller: unauthenti…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user…

ansible_automation_platform | Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14364 Results