VYPR

CVEs

383,870 total · page 379 of 7,678

  • CVE-2026-75574HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in…

  • CVE-2026-72702MedAug 25, 2026
    risk 0.28cvss 5.4epss 0.00

    Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who…

  • CVE-2026-72701LowAug 25, 2026
    risk 0.17cvss 3.7epss 0.00

    Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values…

  • CVE-2026-72700HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler).…

  • CVE-2026-72699MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while…

  • CVE-2026-72698MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like…

  • CVE-2026-72697MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply…

  • CVE-2026-72696HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a…

  • CVE-2026-72695HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.01

    Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the…

  • CVE-2026-56710CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from…

  • CVE-2026-56709HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the…

  • CVE-2026-56708MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups…

  • CVE-2026-56707HigAug 25, 2026
    risk 0.43cvss 7.7epss 0.00

    Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in…

  • CVE-2026-56706MedAug 25, 2026
    risk 0.37cvss 6.8epss 0.00

    Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the…

  • CVE-2026-56705CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote…

  • CVE-2026-56704MedAug 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary…

  • CVE-2026-56703HigAug 25, 2026
    risk 0.40cvss 7.2epss 0.01

    Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

  • CVE-2026-56702HigAug 25, 2026
    risk 0.50cvss 8.8epss 0.01

    Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in…

  • CVE-2026-34968HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.01

    Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any…

  • CVE-2026-34967MedAug 25, 2026
    risk 0.28cvss 5.4epss 0.00

    Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with…

  • CVE-2026-34964MedAug 25, 2026
    risk 0.31cvss 5.8epss 0.00

    Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port=…

  • CVE-2026-34959MedAug 25, 2026
    risk 0.31cvss 4.7epss 0.00

    Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into…

  • CVE-2026-19801MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to…

  • CVE-2026-16434LowAug 25, 2026
    risk 0.08cvss —epss 0.00

    Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com…

  • CVE-2026-15023MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.01

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied…

  • CVE-2026-10630MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a…

  • CVE-2026-66766HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.01

    SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful…

  • CVE-2026-59183MedAug 25, 2026
    risk 0.29cvss 5.5epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can…

  • CVE-2026-55373MedAug 25, 2026
    risk 0.33cvss 6.2epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a…

  • CVE-2026-55371MedAug 25, 2026
    risk 0.38cvss —epss 0.00

    OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exr_attr_set_bytes(). The public…

  • CVE-2026-55059MedAug 25, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int…

  • CVE-2026-54920NonAug 25, 2026
    risk 0.00cvss 0.0epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an…

  • CVE-2026-53532HigAug 24, 2026
    risk 0.39cvss —epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls…

  • CVE-2026-78435LowAug 24, 2026
    risk 0.25cvss 3.8epss 0.01

    A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be…

  • CVE-2026-78434MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The…

  • CVE-2026-78284HigAug 24, 2026
    risk 0.49cvss 8.6epss 0.01

    Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

  • CVE-2026-78282HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

  • CVE-2026-78268HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

  • CVE-2026-78267CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

  • CVE-2026-78266MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

  • CVE-2026-78265CriAug 24, 2026
    risk 0.57cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

  • CVE-2026-78264HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

  • CVE-2026-78263HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

  • CVE-2026-78262CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

  • CVE-2026-78259HigAug 24, 2026
    risk 0.47cvss 7.3epss 0.00

    Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

  • CVE-2026-77384HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.01

    libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer…

  • CVE-2026-77337CriAug 24, 2026
    risk 0.52cvss —epss 0.01

    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when…

  • CVE-2026-68516MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ…

  • CVE-2026-45404MedAug 24, 2026
    risk 0.31cvss —epss 0.00

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent…

  • CVE-2026-32563CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.