VYPR

CVEs

374,500 total · page 19 of 7,490

  • CVE-2026-90549MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video…

  • CVE-2026-90548MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image…

  • CVE-2026-90547MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint…

  • CVE-2026-90546MedSep 12, 2026
    risk 0.21cvss 4.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos…

  • CVE-2026-90545MedSep 12, 2026
    risk 0.21cvss 4.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST…

  • CVE-2026-90544MedSep 12, 2026
    risk 0.21cvss 4.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot…

  • CVE-2026-90543MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` parameters from $_REQUEST, resolves the…

  • CVE-2026-90542MedSep 12, 2026
    risk 0.28cvss 5.4epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot…

  • CVE-2026-90541MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and…

  • CVE-2026-90540MedSep 12, 2026
    risk 0.21cvss 4.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot watch to playlists they own by…

  • CVE-2026-90539MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a…

  • CVE-2026-90538MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve…

  • CVE-2026-90537HigSep 12, 2026
    risk 0.46cvss 8.2epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can…

  • CVE-2026-90536MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to…

  • CVE-2026-90535MedSep 12, 2026
    risk 0.34cvss epss 0.00

    Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user…

  • CVE-2026-90534MedSep 12, 2026
    risk 0.33cvss epss 0.00

    Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName,…

  • CVE-2026-90533MedSep 12, 2026
    risk 0.32cvss epss 0.00

    Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query…

  • CVE-2026-15451HigSep 12, 2026
    risk 0.57cvss 8.8epss 0.00

    The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user'…

  • CVE-2026-10148MedSep 12, 2026
    risk 0.35cvss 6.4epss 0.00

    The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually'…

  • CVE-2026-90474MedSep 12, 2026
    risk 0.37cvss 6.8epss 0.00

    MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it…

  • CVE-2026-90473MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor…

  • CVE-2026-90472MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and…

  • CVE-2026-89172MedSep 12, 2026
    risk 0.36cvss epss 0.00

    Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.

  • CVE-2026-85200HigSep 12, 2026
    risk 0.42cvss 7.5epss 0.01

    The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on…

  • CVE-2026-85198MedSep 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-78175HigSep 12, 2026
    risk 0.57cvss 8.8epss 0.01

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler…

  • CVE-2026-78159CriSep 12, 2026
    risk 0.57cvss 9.8epss 0.01

    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the…

  • CVE-2026-78006CriSep 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires…

  • CVE-2026-77161MedSep 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-17585MedSep 12, 2026
    risk 0.27cvss 5.3epss 0.00

    The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to…

  • CVE-2026-16482HigSep 12, 2026
    risk 0.42cvss 7.5epss 0.00

    The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-11355MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings) in versions…

  • CVE-2026-87919MedSep 12, 2026
    risk 0.32cvss 4.9epss 0.00

    The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary…

  • CVE-2026-87918MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using…

  • CVE-2026-87916MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date…

  • CVE-2026-87894MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any…

  • CVE-2026-87892MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to…

  • CVE-2026-87891MedSep 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate…

  • CVE-2026-87888HigSep 12, 2026
    risk 0.52cvss 8.0epss 0.00

    The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing …

  • CVE-2026-87842HigSep 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

  • CVE-2026-87797MedSep 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records…

  • CVE-2026-87759HigSep 12, 2026
    risk 0.57cvss 8.8epss 0.00

    The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator…

  • CVE-2026-86790MedSep 12, 2026
    risk 0.44cvss 6.8epss 0.00

    The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2026-85681CriSep 12, 2026
    risk 0.64cvss 9.8epss 0.00

    The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to…

  • CVE-2026-84171CriSep 12, 2026
    risk 0.64cvss 9.8epss 0.00

    The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

  • CVE-2026-84099HigSep 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be…

  • CVE-2026-84047HigSep 12, 2026
    risk 0.56cvss 8.6epss 0.00

    The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

  • CVE-2026-84025LowSep 12, 2026
    risk 0.14cvss 2.2epss 0.00

    The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected…

  • CVE-2026-84024MedSep 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

  • CVE-2026-84023MedSep 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.