Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2026-92423 — Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated use…

Remote | Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-92422 — Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_col…

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a p…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-92410 — Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request…

Remote | Cross-Site Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.3 MEDIUM
CVE-2026-87840 — Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering

The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated user…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-87839 — Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, …

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.6 MEDIUM
CVE-2026-87068 — Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may imp…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.5 HIGH
CVE-2026-87067 — Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its form…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-85017 — Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it p…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.8 MEDIUM
CVE-2026-84223 — Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing Jav…

Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.1 HIGH
CVE-2026-82842 — SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity b…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.1 LOW
CVE-2026-81654 — NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its g…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.2 MEDIUM
CVE-2026-81653 — NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
2.7 LOW
CVE-2026-81652 — NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Cont…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.1 LOW
CVE-2026-81651 — NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an admi…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.2 HIGH
CVE-2026-81650 — NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a lo…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.1 MEDIUM
CVE-2026-16542 — Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar

The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to p…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.8 MEDIUM
CVE-2026-14844 — Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes

The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the C…

Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.6 MEDIUM
CVE-2026-93965 — aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injec…

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-93964 — NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.v…

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-93963 — itsourcecode Leave Management System controller.php sql injection

A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argumen…

leave_management_system | Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13832 Results