Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.8 LOW
CVE-2025-14779 — Improper Access Control via Secret Type Management API in WSO2 Identity Server

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, le…

identity_server | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.3 MEDIUM
CVE-2025-13909 — Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allo…

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequ…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
3.7 LOW
CVE-2025-13736 — Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Di…

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.4 MEDIUM
CVE-2025-13394 — Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables…

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for th…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.4 LOW
CVE-2025-12627 — Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server…

The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impe…

identity_server | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.3 MEDIUM
CVE-2025-11850 — Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Iden…

When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness check…

identity_server | Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.9 MEDIUM
CVE-2024-8995 — Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unautho…

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reuse…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.9 MEDIUM
CVE-2024-6832 — Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Product…

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured use…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.0 MEDIUM
CVE-2024-10302 — Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Ma…

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-19007 — mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management

A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulati…

openclaw-cn | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-19006 — mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization

A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation result…

openclaw-cn | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-19005 — nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges manag…

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/create-agent.ts of the component Child-Agent Creation…

nanoclaw | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.4 MEDIUM
CVE-2026-18967 — Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated b…

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the One…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.2 HIGH
CVE-2026-18510 — TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versio…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.4 MEDIUM
CVE-2026-18400 — Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored C…

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-18395 — Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and abo…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-18050 — Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/up…

The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve anothe…

| Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16954 — AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens

The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the si…

| Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16734 — Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manip…

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allo…

| Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
0.0 NA
CVE-2026-16537 — Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above t…

| Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 9848 Results