CVE-2026-65457
— WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Remote
|
Authorization
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65456
— WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object Refer…
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65455
— WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Remote
|
Authentication
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65454
— WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65453
— WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Remote
|
Authorization
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65452
— WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Remote
|
Authorization
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65451
— WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Remote
|
Injection
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65450
— WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Remote
|
Injection
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-65449
— WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
Remote
|
Cross-Site Scripting
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64815
— JetBrains IntelliJ IDEA UI Designer Arbitrary Code Injection
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64814
— JetBrains IntelliJ IDEA Unauthorized File Access Vulnerability
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64813
— JetBrains IntelliJ IDEA Unauthorized Settings Modification Vulnerability
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64812
— JetBrains IntelliJ IDEA Input Injection Vulnerability
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64811
— JetBrains IntelliJ IDEA Arbitrary Code Execution Vulnerability
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64809
— JetBrains PhpStorm Arbitrary Code Execution Vulnerability
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
CVE-2026-64808
— JetBrains PhpStorm Arbitrary Code Execution Vulnerability
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Jul 23, 2026