VYPR

CVEs

373,703 total · page 2 of 7,475

  • CVE-2026-84171CriSep 12, 2026
    risk 0.64cvss 9.8epss

    The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.

  • CVE-2026-84099HigSep 12, 2026
    risk 0.53cvss 8.1epss

    The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be…

  • CVE-2026-84047HigSep 12, 2026
    risk 0.56cvss 8.6epss

    The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

  • CVE-2026-84025LowSep 12, 2026
    risk 0.14cvss 2.2epss

    The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected…

  • CVE-2026-84024MedSep 12, 2026
    risk 0.28cvss 4.3epss

    The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

  • CVE-2026-84023MedSep 12, 2026
    risk 0.42cvss 6.5epss

    The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.

  • CVE-2026-83532MedSep 12, 2026
    risk 0.44cvss 6.8epss

    The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content…

  • CVE-2026-82851LowSep 12, 2026
    risk 0.18cvss 2.7epss

    The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors'…

  • CVE-2026-82847MedSep 12, 2026
    risk 0.44cvss 6.8epss

    The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as…

  • CVE-2026-82845CriSep 12, 2026
    risk 0.64cvss 9.9epss

    The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with…

  • CVE-2026-81742HigSep 12, 2026
    risk 0.57cvss 8.8epss

    The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts…

  • CVE-2026-81429HigSep 12, 2026
    risk 0.46cvss 7.1epss

    The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a…

  • CVE-2026-81402CriSep 12, 2026
    risk 0.64cvss 9.8epss

    The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can…

  • CVE-2026-81090HigSep 12, 2026
    risk 0.47cvss 7.2epss

    The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code…

  • CVE-2026-80494HigSep 12, 2026
    risk 0.56cvss 8.6epss

    The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server,…

  • CVE-2026-80491HigSep 12, 2026
    risk 0.56cvss 8.6epss

    The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-78152MedSep 12, 2026
    risk 0.34cvss 5.3epss

    The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

  • CVE-2026-77753MedSep 12, 2026
    risk 0.36cvss 5.5epss

    The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working…

  • CVE-2026-77752HigSep 12, 2026
    risk 0.47cvss 7.2epss

    The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take…

  • CVE-2026-77705HigSep 12, 2026
    risk 0.47cvss 7.2epss

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management…

  • CVE-2026-77689MedSep 12, 2026
    risk 0.34cvss 5.3epss

    The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never…

  • CVE-2026-77006CriSep 12, 2026
    risk 0.62cvss 9.6epss

    The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete…

  • CVE-2026-77005CriSep 12, 2026
    risk 0.62cvss 9.6epss

    The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on…

  • CVE-2026-75800CriSep 12, 2026
    risk 0.64cvss 9.8epss

    The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary…

  • CVE-2026-87719CriSep 12, 2026
    risk 0.64cvss 9.9epss

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and…

  • CVE-2026-85706CriKEVSep 12, 2026
    risk 0.77cvss 10.0epss

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path…

  • CVE-2026-90467MedSep 12, 2026
    risk 0.19cvss 4.0epss

    aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like…

  • CVE-2026-89268MedSep 12, 2026
    risk 0.28cvss 5.4epss

    QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers,…

  • CVE-2026-89267MedSep 12, 2026
    risk 0.28cvss 4.3epss

    starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to…

  • CVE-2026-89266HigSep 12, 2026
    risk 0.53cvss 8.2epss

    stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes,…

  • CVE-2026-90461MedSep 11, 2026
    risk 0.41cvss 6.3epss

    OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

  • CVE-2026-90460HigSep 11, 2026
    risk 0.49cvss epss

    An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the…

  • CVE-2026-90457MedSep 11, 2026
    risk 0.38cvss epss

    The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a…

  • CVE-2026-90456CriSep 11, 2026
    risk 0.53cvss epss

    An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials…

  • CVE-2026-90455MedSep 11, 2026
    risk 0.34cvss epss

    A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a…

  • CVE-2026-90454MedSep 11, 2026
    risk 0.27cvss epss

    A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise…

  • CVE-2026-90453MedSep 11, 2026
    risk 0.26cvss epss

    A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's…

  • CVE-2026-90452MedSep 11, 2026
    risk 0.32cvss epss

    Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could…

  • CVE-2026-90451HigSep 11, 2026
    risk 0.46cvss epss

    An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that…

  • CVE-2026-90450MedSep 11, 2026
    risk 0.27cvss epss

    The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any…

  • CVE-2026-90449MedSep 11, 2026
    risk 0.38cvss epss

    When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative…

  • CVE-2026-90448HigSep 11, 2026
    risk 0.39cvss epss

    A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an…

  • CVE-2026-90447HigSep 11, 2026
    risk 0.39cvss epss

    A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service…

  • CVE-2026-90446MedSep 11, 2026
    risk 0.27cvss epss

    An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an…

  • CVE-2026-90445HigSep 11, 2026
    risk 0.39cvss epss

    An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries…

  • CVE-2026-90444HigSep 11, 2026
    risk 0.50cvss epss

    A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed…

  • CVE-2026-90443MedSep 11, 2026
    risk 0.27cvss epss

    A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes…

  • CVE-2026-54258MedSep 11, 2026
    risk 0.35cvss 6.5epss

    ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging…

  • CVE-2026-54248MedSep 11, 2026
    risk 0.35cvss 6.5epss

    Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy…

  • CVE-2026-54241HigSep 11, 2026
    risk 0.41cvss 7.4epss

    libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer…