Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-75922 — Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-d…

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application perce…

| Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-9769 — justhtml before 1.10.0 Denial of Service via deeply nested HTML

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_sel…

Remote | Denial of Service
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-8630 — justhtml before 1.12.0 Mutation XSS via Raw Text Elements

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is pr…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-8445 — justhtml before 1.12.0 Sanitizer Bypass via Markdown

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). Wh…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-7808 — justhtml before 1.16.0 Multiple Security Issues via Sanitization

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scr…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-77088 — justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject …

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-74793 — justhtml before 3.11.0 XSS via selectedcontent projection

justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elem…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-6827 — justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous conten…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-5751 — justhtml before 1.14.0 Mutation XSS via custom sanitization policies

justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g.,…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-5389 — justhtml before 1.13.0 XSS via code fence breakout

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanit…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-5388 — justhtml before 1.15.0 Multiple Security Issues

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and se…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-4671 — justhtml before 1.18.0 Denial of Service via CSS Selector

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query()…

Remote | Denial of Service
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.9 CRITICAL
CVE-2026-78155 — Untrusted Search Path in StackGres

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.5 MEDIUM
CVE-2026-78115 — SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.ph…

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. …

class_and_exam_timetabling_system | Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78112 — itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection

A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes …

Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
8.5 HIGH
CVE-2026-10053 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authentic…

Remote | Path Traversal
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
4.3 MEDIUM
CVE-2026-77116 — Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content…

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.1 HIGH
CVE-2026-77115 — Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
2.7 LOW
CVE-2026-77003 — Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_conte…

The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and p…

content_mask | Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
4.3 MEDIUM
CVE-2026-14853 — WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Au…

The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with S…

Remote | Authorization
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
Showing 20 of 11471 Results