| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57716 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | ||
| CVE-2026-57704 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | ||
| CVE-2026-57703 | Med | 0.00 | 6.3 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. | ||
| CVE-2026-57701 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | ||
| CVE-2026-57699 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | ||
| CVE-2026-57696 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | ||
| CVE-2026-57626 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | ||
| CVE-2026-57428 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | ||
| CVE-2026-57427 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | ||
| CVE-2026-57425 | Med | 0.35 | 6.5 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions. | ||
| CVE-2026-57397 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. | ||
| CVE-2026-57384 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. | ||
| CVE-2026-57374 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | ||
| CVE-2026-57373 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | ||
| CVE-2026-57370 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | ||
| CVE-2026-57367 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | ||
| CVE-2026-27423 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | ||
| CVE-2026-27422 | Med | 0.34 | 5.3 | 0.00 | Jul 23, 2026 | Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2. | ||
| CVE-2026-27418 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. | ||
| CVE-2026-27403 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3. | ||
| CVE-2026-27399 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | ||
| CVE-2026-27392 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||
| CVE-2026-27391 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||
| CVE-2026-27377 | Med | 0.00 | 6.7 | 0.00 | Jul 23, 2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | ||
| CVE-2026-27372 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||
| CVE-2026-27355 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. | ||
| CVE-2026-27064 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | ||
| CVE-2026-25466 | Med | 0.27 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | ||
| CVE-2026-25427 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. | ||
| CVE-2026-25424 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | ||
| CVE-2026-25405 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in eRoom <= 1.7.1 versions. | ||
| CVE-2026-24639 | Med | 0.00 | 4.4 | 0.00 | Jul 23, 2026 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. | ||
| CVE-2026-24628 | Med | 0.00 | 5.9 | 0.00 | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. | ||
| CVE-2026-24552 | Hig | 0.55 | 8.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3. | ||
| CVE-2026-24537 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||
| CVE-2025-68081 | Med | 0.38 | 5.9 | 0.00 | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. | ||
| CVE-2026-64611 | Hig | 0.49 | 7.5 | 0.01 | Jul 23, 2026 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by… | ||
| CVE-2026-16745 | Hig | 0.57 | 8.8 | 0.00 | Jul 23, 2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker… | ||
| CVE-2026-65758 | Hig | 0.00 | — | 0.00 | Jul 23, 2026 | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | ||
| CVE-2026-65757 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | ||
| CVE-2026-65756 | Med | 0.00 | 6.1 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. | ||
| CVE-2026-65755 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries,… | ||
| CVE-2026-65754 | Hig | 0.00 | 7.5 | 0.01 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. | ||
| CVE-2026-65713 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. | ||
| CVE-2026-65712 | Med | 0.00 | 6.2 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata. | ||
| CVE-2026-65431 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. | ||
| CVE-2026-65430 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability. | ||
| CVE-2026-64876 | Hig | 0.00 | 8.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates. | ||
| CVE-2026-64875 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass. | ||
| CVE-2026-64874 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. |
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
- risk 0.00cvss 6.3epss 0.00
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
- risk 0.00cvss 7.1epss 0.00
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
- risk 0.00cvss 7.1epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
- risk 0.35cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
- risk 0.00cvss 6.5epss 0.00
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
- risk 0.00cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in uListing <= 2.2.0 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
- risk 0.00cvss 6.7epss 0.00
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
- risk 0.00cvss 9.1epss 0.01
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
- risk 0.27cvss 5.3epss 0.00
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in eRoom <= 1.7.1 versions.
- risk 0.00cvss 4.4epss 0.00
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
- risk 0.00cvss 5.9epss 0.00
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
- risk 0.38cvss 5.9epss 0.00
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by…
- risk 0.57cvss 8.8epss 0.00
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker…
- risk 0.00cvss —epss 0.00
Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
- risk 0.00cvss 8.1epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
- risk 0.00cvss 6.1epss 0.00
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries,…
- risk 0.00cvss 7.5epss 0.01
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.
- risk 0.00cvss 6.2epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
- risk 0.00cvss 9.8epss 0.01
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
- risk 0.00cvss 8.8epss 0.00
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
- risk 0.00cvss 9.8epss 0.01
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.