VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-86867Medium· 6.5
4d ago

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pag…

▾ SunlitCinnamon AI · KotaemonEPSS 0.18%via NVD
CVE-2026-62998Medium· 4.3PoC
4d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. …

▾ Twilightredaxo · coreEPSS 0.27%via NVD
CVE-2026-93528Low· 3.7PoC
4d ago

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

▾ TwilightEPSS 0.22%via NVD
CVE-2026-90985Medium· 5.3
4d ago

The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description…

The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-89331Medium· 5.3
4d ago

The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, ty…

The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, ty…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-88929Medium· 5.3
4d ago

The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description an…

The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description an…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-86783Medium· 5.3
4d ago

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose …

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose …

▾ SunlitEPSS 0.21%via NVD
CVE-2026-86603Medium· 4.3
4d ago

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.

▾ SunlitEPSS 0.18%via NVD
CVE-2026-86602Medium· 4.3
4d ago

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.

▾ SunlitEPSS 0.18%via NVD
CVE-2026-84741Medium· 5.3
4d ago

The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records tha…

The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records tha…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-84168Medium· 5.3
4d ago

The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover th…

The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover th…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-84026Medium· 5.3
4d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' p…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' p…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-18365Medium· 4.3
4d ago

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user,…

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user,…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-62364Low· 2.3
5d ago

wlc is a Weblate command-line client using Weblate's REST API

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_…

▾ SunlitWeblateOrg · wlcEPSS 0.08%via NVD
CVE-2026-76710High· 7.5
5d ago

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially c…

▾ TwilightHewlett Packard Enterprise (HPE) · ALEEPSS 0.54%via NVD
CVE-2026-76712High· 7.3
5d ago

A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service

A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending spe…

▾ TwilightHewlett Packard Enterprise (HPE) · ALEEPSS 0.43%via NVD
CVE-2026-76717Medium· 5.3
5d ago

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to…

▾ SunlitHewlett Packard Enterprise (HPE) · ALEEPSS 0.42%via NVD
CVE-2026-77246High· 7.4PoC
5d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits …

▾ Midnightsooperset · mcp-atlassianEPSS 0.22%via NVD
CVE-2026-86059Critical· 9.6PoC
5d ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucke…

▾ AbyssalDokploy · dokployEPSS 0.49%via NVD
CVE-2026-76805Medium· 5.3
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.41%via NVD
CVE-2026-85055High· 7.1
5d ago

Twenty is an open-source CRM (customer relationship management) platform

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL or REST filter predicates. A workspace member or API key with…

▾ Twilighttwentyhq · twentyEPSS 0.43%via NVD
CVE-2026-92706Low· 3.4
5d ago

Dark Reader is an accessibility browser extension that makes web pages colors dark

Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion pipeline to request an unauthenticated icon-like bitmap from a locally runn…

▾ Sunlitdarkreader · darkreaderEPSS 0.17%via NVD
CVE-2026-95693Medium· 5.3
5d ago

In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP uplo…

In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP uplo…

▾ SunlitMISP · MISPEPSS 0.51%via NVD
CVE-2026-95703Medium· 5.1
5d ago

In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP fi…

In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP fi…

▾ SunlitMISP · MISPEPSS 0.51%via NVD
CVE-2026-63278Medium· 6.7
5d ago

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.15%via NVD
CVE-2026-9004Medium· 4.3
5d ago

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 via the 'contact_id' parameter. This makes it possible for authenticated att…

▾ Sunlitnofearinc · WP-CRM System – Manage Clients and ProjectsEPSS 0.37%via NVD
CVE-2026-78806Medium· 5.5
6d ago

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

▾ SunlitEPSS 0.11%via NVD
CVE-2026-49449Low· 2.5
6d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note au…

▾ Sunlitlaurent22 · joplinEPSS 0.17%via NVD
CVE-2026-79319Medium· 5.3
6d ago

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

▾ SunlitEPSS 0.20%via NVD
CVE-2026-61746Medium· 5.3PoC
6d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…

▾ Twilightinventree · InvenTreeEPSS 0.40%via NVD
CWE-200 vulnerabilities (CVEs) — page 3 · VulnSea