CVE-2026-96837High· 8.8▾ TwilightContributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
cartflows >= n/a <= 3.2.0Update the WordPress CartFlows plugin to the latest available version (at least 3.2.1).
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27085Low· 2.7WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability
CVE-2026-87741High· 8.8The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action
CVE-2026-62134Medium· 4.3WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability
CVE-2026-89294High· 7.5The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter
CVE-2026-39353Critical· 9.1InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
CVE-2026-50547High· 7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments