VYPR

CVEs

383,399 total · page 345 of 7,668

  • CVE-2026-27330HigAug 27, 2026
    risk 0.56cvss 8.6epss 0.00

    Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

  • CVE-2026-78333HigAug 27, 2026
    risk 0.57cvss 8.8epss 0.01

    The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used…

  • CVE-2026-78139MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary…

  • CVE-2026-78138MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before…

  • CVE-2026-78137HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout…

  • CVE-2026-78125MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.

  • CVE-2026-77991CriAug 27, 2026
    risk 0.61cvss —epss 0.01

    Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.

  • CVE-2026-77990MedAug 27, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to…

  • CVE-2026-77989MedAug 27, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.

  • CVE-2026-77035MedAug 27, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their…

  • CVE-2026-77034MedAug 27, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.

  • CVE-2026-77018HigAug 27, 2026
    risk 0.57cvss 8.8epss 0.01

    The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and…

  • CVE-2026-77017HigAug 27, 2026
    risk 0.50cvss 7.7epss 0.00

    The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server,…

  • CVE-2026-77016CriAug 27, 2026
    risk 0.62cvss 9.6epss 0.00

    The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the…

  • CVE-2026-76549MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier…

  • CVE-2026-59278MedAug 27, 2026
    risk 0.42cvss 6.5epss 0.00

    JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type…

  • CVE-2026-59275MedAug 27, 2026
    risk 0.43cvss 6.6epss 0.00

    A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18…

  • CVE-2026-59274MedAug 27, 2026
    risk 0.42cvss 6.5epss 0.00

    The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5…

  • CVE-2026-59271MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

  • CVE-2026-59270CriAug 27, 2026
    risk 0.61cvss 9.4epss 0.00

    Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring…

  • CVE-2026-47894MedAug 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

  • CVE-2026-47893HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework…

  • CVE-2026-47892CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 -…

  • CVE-2026-47891CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring…

  • CVE-2026-47890CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

  • CVE-2026-47889HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

  • CVE-2026-47888HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE -…

  • CVE-2026-47887MedAug 27, 2026
    risk 0.40cvss 6.1epss 0.00

    A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring…

  • CVE-2026-47886HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8…

  • CVE-2026-47885HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

  • CVE-2026-47884CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring…

  • CVE-2026-47883MedAug 27, 2026
    risk 0.40cvss 6.1epss 0.00

    UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

  • CVE-2026-47881MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader assembles those multi-line…

  • CVE-2026-47880MedAug 27, 2026
    risk 0.35cvss 5.4epss 0.00

    A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration…

  • CVE-2026-47879HigAug 27, 2026
    risk 0.50cvss 7.7epss 0.00

    Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier

  • CVE-2026-47878MedAug 27, 2026
    risk 0.36cvss 5.6epss 0.00

    DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring…

  • CVE-2026-47877HigAug 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

  • CVE-2026-47875MedAug 27, 2026
    risk 0.36cvss 5.6epss 0.00

    Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types…

  • CVE-2026-47864MedAug 27, 2026
    risk 0.35cvss 6.4epss 0.06

    SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via…

  • CVE-2026-47849HigAug 27, 2026
    risk 0.46cvss 7.1epss 0.00

    Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 -…

  • CVE-2026-19715HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has…

  • CVE-2026-19454MedAug 27, 2026
    risk 0.29cvss 4.4epss 0.00

    The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network,…

  • CVE-2026-19225MedAug 27, 2026
    risk 0.43cvss 6.6epss 0.00

    The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

  • CVE-2026-19223HigAug 27, 2026
    risk 0.47cvss 7.2epss 0.00

    The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

  • CVE-2026-16569MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a…

  • CVE-2026-16568MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a…

  • CVE-2026-16567MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private…

  • CVE-2026-13416LowAug 27, 2026
    risk 0.23cvss 3.5epss 0.00

    The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's…

  • CVE-2026-13415HigAug 27, 2026
    risk 0.47cvss 7.2epss 0.00

    The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's…

  • CVE-2026-13414MedAug 27, 2026
    risk 0.31cvss 4.8epss 0.00

    The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's…