Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19116 — WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form

The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenti…

| Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-16983 — Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST API

The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected posts to any authentica…

gutentor | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-16966 — Solace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Disclosure via …

The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-publis…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-15232 — Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion

The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, a…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-14357 — DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Them…

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-14215 — Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unau…

| Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-12865 — Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters

The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one…

photo_gallery | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-12526 — Advanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Account Takeov…

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Form…

| Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2025-15664 — BEAF < 4.7.19 - Author+ Stored XSS via Before Label

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the …

| Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2025-15663 — BEAF < 4.7.19 - Author+ Stored XSS via After Label

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the D…

| Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.8 CRITICAL
CVE-2026-9055 — Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthentic…

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the a…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.6 HIGH
CVE-2025-46418 — Westermo WeOS OS Command Injection

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

weos | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.6 HIGH
CVE-2024-35585 — Oxford Nanopore MinKNOW Authentication Bypass

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.4 MEDIUM
CVE-2026-3851 — Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Con…

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compoun…

divi divi | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.6 HIGH
CVE-2026-19754 — Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction

Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth ar…

baserow | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.4 MEDIUM
CVE-2026-84442 — MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt getDataColu…

A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapqu…

get_directions_app | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.5 HIGH
CVE-2026-84441 — Piwigo Image Derivative i.php path traversal

A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation l…

piwigo | Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.1 HIGH
CVE-2026-14982 — WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remo…

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenti…

wp_file_download | Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.5 HIGH
CVE-2026-14957 — FIPS mode assertion failure via malicious CERT payload

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction f…

libreswan | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84715 — FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Update

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser wi…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12503 Results