Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-100604 — ClawHub Authentication Bypass via Former Publisher Skill Control

ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and tra…

openclaw | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100603 — ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports

ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hidi…

openclaw | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100602 — ClawHub Changelog Preview Information Disclosure via Authorization Bypass

ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action…

openclaw | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100601 — ClawHub SSRF via Unchecked DNS Resolution in Profile Image

ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and c…

openclaw | Remote | Server-Side Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100600 — ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API

ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single default quota allowance.…

openclaw | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100315 — mathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injection

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulat…

cloudclassroom-php-project | Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100314 — mathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql injection

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromstu…

cloudclassroom-php-project | Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.0 MEDIUM
CVE-2026-100313 — mathurvishal CloudClassroom-PHP-Project updatequery.php cross site scripting

A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a man…

cloudclassroom-php-project | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
0.0 NA
CVE-2026-98163 — cgroup: Avoid iteration of dying tasks with zero refcount

In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup…

linux_kernel | Race Condition
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.5 MEDIUM
CVE-2026-100312 — mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection

A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php…

cloudclassroom-php-project | Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
4.0 MEDIUM
CVE-2026-100311 — mathurvishal CloudClassroom-PHP-Project Faculty Video Management managevideos2.php cross …

A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file managevideos2.php of …

cloudclassroom-php-project | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.8 MEDIUM
CVE-2026-96533 — Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users t…

testimonials_widget | Remote | Server-Side Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-96532 — Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modi…

testimonials_widget | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.8 MEDIUM
CVE-2026-96531 — Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block

The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author r…

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
2.7 LOW
CVE-2026-96526 — MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workf…

The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclo…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
2.7 LOW
CVE-2026-96525 — MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Mi…

The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-96524 — MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF

The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is pres…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.8 MEDIUM
CVE-2026-92411 — WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name

The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the…

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.8 MEDIUM
CVE-2026-89237 — Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters

The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and …

Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-85081 — Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass

The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages r…

file_manager fileorganizer filester | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14399 Results