| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45129 | Med | 0.23 | 4.6 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Admin CP Home, Preferences,… | ||
| CVE-2026-45128 | Low | 0.16 | 3.5 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a specially crafted URL. The Set as Default… | ||
| CVE-2026-45127 | Low | 0.16 | 3.5 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially crafted URL. The Resend route in Admin CP,… | ||
| CVE-2026-45126 | Low | 0.16 | 3.5 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with a specially crafted URL. The controller… | ||
| CVE-2026-45125 | Med | 0.27 | 5.3 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the stored username for… | ||
| CVE-2026-45124 | Med | 0.21 | 4.3 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is… | ||
| CVE-2026-45123 | Med | 0.21 | 4.3 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in… | ||
| CVE-2026-45122 | Med | 0.21 | 4.3 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user… | ||
| CVE-2026-45121 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected calendar-selection paths in… | ||
| CVE-2026-45120 | Med | 0.28 | 5.4 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The private-event check used by get_events() in… | ||
| CVE-2026-45119 | Med | 0.23 | 4.6 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially crafted URL. The do=all control flow in… | ||
| CVE-2026-45118 | Cri | 0.53 | 9.3 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in… | ||
| CVE-2026-45117 | Cri | 0.57 | 9.8 | 0.01 | Aug 18, 2026 | MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is… | ||
| CVE-2026-45116 | Hig | 0.50 | 8.7 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only performs the specialized… | ||
| CVE-2026-45115 | Hig | 0.50 | 8.7 | 0.00 | Aug 18, 2026 | MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list… | ||
| CVE-2026-19501 | Hig | 0.57 | 8.8 | 0.00 | Aug 18, 2026 | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's… | ||
| CVE-2026-19500 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators… | ||
| CVE-2026-15806 | Med | 0.32 | — | 0.00 | Aug 18, 2026 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an… | ||
| CVE-2026-12564 | Cri | 0.62 | 9.6 | 0.00 | Aug 18, 2026 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault… | ||
| CVE-2026-75898 | Hig | 0.48 | 8.5 | 0.00 | Aug 18, 2026 | RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get,… | ||
| CVE-2026-75890 | — | 0.00 | — | — | Aug 18, 2026 | Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment. | ||
| CVE-2026-75872 | Med | 0.38 | — | 0.01 | Aug 18, 2026 | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the… | ||
| CVE-2026-75784 | Cri | 0.65 | 10.0 | 0.01 | Aug 18, 2026 | A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack… | ||
| CVE-2026-75032 | Med | 0.41 | 6.3 | 0.00 | Aug 18, 2026 | A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability,… | ||
| CVE-2026-74015 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||
| CVE-2026-74012 | Hig | 0.57 | 8.8 | 0.00 | Aug 18, 2026 | Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. | ||
| CVE-2026-74009 | Med | 0.34 | 5.3 | 0.00 | Aug 18, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | ||
| CVE-2026-74008 | Med | 0.34 | 5.3 | 0.00 | Aug 18, 2026 | Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. | ||
| CVE-2026-74007 | Med | 0.34 | 5.3 | 0.00 | Aug 18, 2026 | Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | ||
| CVE-2026-74006 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||
| CVE-2026-74004 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | ||
| CVE-2026-74003 | Med | 0.28 | 4.3 | 0.00 | Aug 18, 2026 | Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | ||
| CVE-2026-73997 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | ||
| CVE-2026-73996 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||
| CVE-2026-73995 | Med | 0.35 | 5.4 | 0.00 | Aug 18, 2026 | Subscriber Broken Authentication in User Registration <= 5.2.6 versions. | ||
| CVE-2026-73994 | Hig | 0.49 | 7.5 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | ||
| CVE-2026-73426 | Med | 0.23 | 4.6 | 0.00 | Aug 18, 2026 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a… | ||
| CVE-2026-73404 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | ||
| CVE-2026-73400 | Hig | 0.53 | 8.1 | 0.00 | Aug 18, 2026 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | ||
| CVE-2026-73399 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | ||
| CVE-2026-73398 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | ||
| CVE-2026-73397 | Cri | 0.64 | 9.8 | 0.00 | Aug 18, 2026 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | ||
| CVE-2026-73396 | Hig | 0.46 | 7.1 | 0.00 | Aug 18, 2026 | Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||
| CVE-2026-73395 | Med | 0.42 | 6.5 | 0.00 | Aug 18, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | ||
| CVE-2026-73393 | Hig | 0.46 | 7.1 | 0.00 | Aug 18, 2026 | Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | ||
| CVE-2026-73392 | — | 0.00 | — | 0.00 | Aug 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965. | ||
| CVE-2026-73383 | Med | 0.32 | 4.9 | 0.00 | Aug 18, 2026 | Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. | ||
| CVE-2026-73382 | Hig | 0.46 | 7.1 | 0.00 | Aug 18, 2026 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | ||
| CVE-2026-73381 | Cri | 0.59 | 9.1 | 0.01 | Aug 18, 2026 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | ||
| CVE-2026-73380 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. |
- risk 0.23cvss 4.6epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Admin CP Home, Preferences,…
- risk 0.16cvss 3.5epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a specially crafted URL. The Set as Default…
- risk 0.16cvss 3.5epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially crafted URL. The Resend route in Admin CP,…
- risk 0.16cvss 3.5epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with a specially crafted URL. The controller…
- risk 0.27cvss 5.3epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the stored username for…
- risk 0.21cvss 4.3epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is…
- risk 0.21cvss 4.3epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in…
- risk 0.21cvss 4.3epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user…
- risk 0.28cvss 4.3epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected calendar-selection paths in…
- risk 0.28cvss 5.4epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The private-event check used by get_events() in…
- risk 0.23cvss 4.6epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially crafted URL. The do=all control flow in…
- risk 0.53cvss 9.3epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in…
- risk 0.57cvss 9.8epss 0.01
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is…
- risk 0.50cvss 8.7epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only performs the specialized…
- risk 0.50cvss 8.7epss 0.00
MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list…
- risk 0.57cvss 8.8epss 0.00
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's…
- risk 0.49cvss 7.5epss 0.00
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators…
- risk 0.32cvss —epss 0.00
The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an…
- risk 0.62cvss 9.6epss 0.00
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault…
- risk 0.48cvss 8.5epss 0.00
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get,…
- CVE-2026-75890Aug 18, 2026risk 0.00cvss —epss —
Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.
- risk 0.38cvss —epss 0.01
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the…
- risk 0.65cvss 10.0epss 0.01
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack…
- risk 0.41cvss 6.3epss 0.00
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability,…
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
- risk 0.57cvss 8.8epss 0.00
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
- risk 0.28cvss 4.3epss 0.00
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
- risk 0.35cvss 5.4epss 0.00
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
- risk 0.28cvss 4.3epss 0.00
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
- risk 0.35cvss 5.4epss 0.00
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
- risk 0.23cvss 4.6epss 0.00
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a…
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
- CVE-2026-73392Aug 18, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.
- risk 0.32cvss 4.9epss 0.00
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
- risk 0.59cvss 9.1epss 0.01
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.