Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-84807 — Kimai before 2.65.0 Authentication Bypass via Team Creation

Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management pr…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84806 — Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints

Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to c…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84805 — Kimai 2.61.0 before 2.63.0 Authentication Bypass via API

Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gat…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84804 — Kimai before 2.65.0 Authorization Bypass via Team Activity API

Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.0 CRITICAL
CVE-2026-84803 — SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files w…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84802 — Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController

Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel …

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84801 — Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers

Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for a…

cms | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-84800 — Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits …

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84799 — Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations

Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scop…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-84798 — Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraf…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.3 MEDIUM
CVE-2026-84797 — Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate

Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer p…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84796 — Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers wit…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.8 CRITICAL
CVE-2026-84795 — Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email add…

cms | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-84794 — Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset

Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets in…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.8 MEDIUM
CVE-2026-84793 — Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name

Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScrip…

cms | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84792 — Craft CMS before 5.10.11 Broken Access Control via element-indexes

Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot…

cms | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-84781 — WordPress Gallery PhotoBlocks plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.

gallery_photoblocks | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84780 — WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability

Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.

wp_go_maps | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84775 — WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulnerability

Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.

Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.5 MEDIUM
CVE-2026-84772 — WordPress Broken Link Checker plugin <= 2.4.14 - Server Side Request Forgery (SSRF) vulne…

Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.

broken_link_checker | Remote | Server-Side Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12591 Results