Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-39779 — WordPress Asgaros Forum plugin <= 3.4.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asgaros Forum: from n/a through 3…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-107419 — WordPress AI Translation for Polylang plugin <= 1.6.2 - Broken Access Control vulnerabili…

Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translations-for-polylang allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-103329 — Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signat…

The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by …

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-97791 — Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares vali…

In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests,…

cxf | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-97468 — Apache CXF: Authentication bypass via weak cache keys for validated STS tokens

Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens under a non-cryptographic 32-bit hash of the token (Java Arrays.hashCode/hashCode()), and treated a ca…

cxf | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-86463 — Apache CXF: FIQL Query Parser Denial of Service

Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions. The search pattern can get stuck trying many combinations when it encounters a long string wi…

cxf | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-79650 — Apache CXF: OIDC RP Open Redirect

Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL after successful authentication. The issue occurs because attacker-controlled state parameters are preserv…

cxf | Server-Side Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-78384 — Apache CXF: Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing (Decompre…

CompressionUtils.inflate() decompressed attacker-controlled DEFLATE data with no output-size cap. A small (~KB) crafted payload could expand to gigabytes on the heap. Reachable via JWE decryption whe…

cxf | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-73179 — Apache CXF: JPA authorization-code consume is non-atomic

Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a…

cxf | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-71575 — Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFi…

The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setM…

cxf | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-108039 — Apache CXF: Prevent unbounded XML document size in StaxUtils by adding default element an…

By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during par…

cxf | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-107938 — Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.

In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied…

cxf | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-107937 — Apache CXF: The attachment header size and count limits can be bypassed, which allows den…

In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default…

cxf | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-100227 — Apache CXF: XML Signature wrapping in JAX-RS XML Security

Improper Verification of Cryptographic Signature vulnerability in Apache CXF's JAX-RS XML Security module. The JAX-RS XML Signature interceptors (XmlSigInHandler, XmlSigInInterceptor and the streamin…

cxf | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-96809 — WordPress EduAdmin Booking plugin < 6.0.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MultiNet Interactive AB EduAdmin Booking eduadmin-booking allows Blind SQL Injection.This issue a…

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-96761 — WordPress Welcart e-Commerce plugin <= 2.12.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Welcart Welcart e-Commerce usc-e-shop allows Reflected XSS.This issue affects Welcart e-Commerce:…

e-commerce | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-96671 — WordPress Featured Image from URL plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vul…

Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-from-url allows Cross Site Request Forgery.This issue affects Featured Image from URL: from n/a thro…

Remote | Cross-Site Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-96607 — WordPress NEX-Forms plugin <= 9.3.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-For…

nex-forms | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-96553 — WordPress FiboSearch plugin <= 1.34.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Reflected XSS.This issue affects FiboSe…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.6 MEDIUM
CVE-2026-96539 — WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

ultimate_member | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14188 Results