CVE-2026-97853
— Unbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoS
Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.
Decimal.round/3 builds the full result for the requested number of decimal places before the con…
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-81797
— WordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - PHP Object …
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78535
— WordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78534
— WordPress Educavo theme <= 3.4.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.
Remote
|
Cross-Site Scripting
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78533
— WordPress Qwery theme <= 3.6.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78532
— WordPress LMS theme <= 8.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.
Remote
|
Cross-Site Scripting
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78531
— WordPress Jacqueline theme <= 2.22 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78530
— WordPress FoodBakery theme <= 4.6 - Arbitrary File Deletion vulnerability
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-78529
— WordPress Alliance theme <= 3.11 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66569
— WordPress Kicker theme <= 2.2.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66568
— WordPress Original theme <= 1.9.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66567
— WordPress Anesta theme <= 1.5.3 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66566
— WordPress Ambient theme <= 1.7 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66565
— WordPress FC United theme <= 1.1.1 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66564
— WordPress ShiftCV theme <= 3.0.14 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66563
— WordPress Windsor theme <= 2.10 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66483
— WordPress Education Center theme <= 3.6.12 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66482
— WordPress Drone Media theme <= 2.2.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.
Remote
|
Injection
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66481
— WordPress Presto Player Pro plugin <= 3.0.1 - Arbitrary File Deletion vulnerability
Author Arbitrary File Deletion in Presto Player Pro <= 3.0.1 versions.
Remote
|
Path Traversal
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
CVE-2026-66480
— WordPress YITH WooCommerce Product Add-Ons plugin <= 4.34.0 - Sensitive Data Exposure vul…
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data.
This issue affects YITH Woo…
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Oct 10, 2026