Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-93971 — aiyiyi121 SxDevOps settings.py information disclosure

A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-93969 — aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded crede…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.1 MEDIUM
CVE-2026-93968 — aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management

A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can le…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-93967 — aiyiyi121 SxDevOps Command services.py generate_host_task command injection

A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.8 MEDIUM
CVE-2026-93966 — aiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command…

A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TAS…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-92965 — TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choos…

| Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-92541 — Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admin…

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users …

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-92540 — Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admin…

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the …

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-92423 — Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated use…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-92422 — Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_col…

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a p…

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-92410 — Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request…

| Cross-Site Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-87840 — Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering

The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated user…

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-87839 — Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, …

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-87068 — Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may imp…

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-87067 — Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its form…

| Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-85017 — Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it p…

| Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-84223 — Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing Jav…

| Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-82842 — SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity b…

| Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-81654 — NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its g…

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-81653 — NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management…

| Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13916 Results