Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-108544 — Lippu Docx Reader Office Viewer App path traversal

A vulnerability was identified in Lippu Docx Reader Office Viewer App up to 1.4.5 on Android. This affects the function word.office.docxviewer.document.docx.reader.ViewTxt. Such manipulation of the a…

docx_reader_office_viewer_app | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108543 — ag2ai ag2 UserProxyAgent os.path.join path traversal

A vulnerability was determined in ag2ai ag2 up to 0.13.4. Affected by this issue is the function os.path.join of the component UserProxyAgent. This manipulation of the argument filename causes path t…

ag2 | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108542 — 021is elvix-sdk MCP Request index.ts server-side request forgery

A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulati…

elvix-sdk | Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-97183 — WP-Invoice <= 4.3.1 - Subscriber+ User PII Disclosure via Unprotected AJAX Handlers

The WP-Invoice WordPress plugin through 4.3.1 does not perform capability checks in several of its AJAX handlers, allowing any authenticated user, such as a Subscriber, to retrieve the email address…

wp-invoice | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-96227 — Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthentica…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-94235 — Simple User Registration <= 6.9 - Subscriber+ Arbitrary Email Sending via wpr_send_email_…

The MemberHero WordPress plugin through 6.9 does not perform any capability or nonce check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to make the site send ar…

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-93550 — Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connec…

The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it,…

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-91829 — Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter

The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-S…

| Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89305 — Paymendo Bank Transfer <= 1.1 - Subscriber+ SQLi via 'orderBy' Parameter

The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89304 — Paymendo Bank Transfer <= 1.1 - Unauthenticated Blind SQLi via 'paymendo_bank_transfer_co…

The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform blind SQL injection attacks.

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89302 — Post Voting System <= 1.0 - Unauthenticated SQLi via 'id' Parameter

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89299 — WP Verify API <= 1.0.0 - Unauthenticated SQLi via 'verify' Parameter

The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89297 — Loja Automática <= 1.0.0 - Unauthenticated SQLi via 'id' Parameter

The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89287 — ASPL Product Quotation <= 1.1.0 - Unauthenticated SQLi via 'quote_id' Parameter

The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and r…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89285 — Datalist it <= 0.0.3 - Unauthenticated SQLi via dli_fronted_action

The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL inject…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89283 — WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite

The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing un…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89234 — WP-Partner <= 1.2.1 - Unauthenticated SQLi via 'id' Parameter

The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract …

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89232 — RecordBrowser <= 1.1.7 - Unauthenticated SQLi via 'recordid' Parameter

The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extra…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89214 — WpCues Basic Quiz <= 1.6.5 - Unauthenticated SQLi via Quiz Result Submission

The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-89213 — Llavero.io <= 0.1.4 - Unauthenticated Blind SQLi via 'cill_login' Parameter

The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection att…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14148 Results