VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

559 CVEsRSS

CVE-2026-94211Low· 2.4PoC
today

A vulnerability has been found in Hyve5 Leantime up to 3.9.8

A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …

TwilightHyve5 · Leantimevia NVD
CVE-2026-94210Low· 3.5
today

A flaw has been found in Hyve5 Leantime up to 3.9.8

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…

SunlitHyve5 · Leantimevia NVD
CVE-2026-94150Low· 2.4
today

A security flaw has been discovered in Omega Solution HRM OS up to 20260717

A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…

SunlitOmega Solution · HRM OSEPSS 0.20%via NVD
CVE-2026-94145Low· 3.5PoC
today

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…

Twilightxuxueli · xxl-jobEPSS 0.19%via NVD
CVE-2026-94103Medium· 4.7PoC
today

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection.…

TwilightEPSS 0.24%via NVD
CVE-2026-55071High· 8.4PoC
today

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…

MidnightSepineTam · mcp-for-statavia NVD
CVE-2026-94045Low· 3.5
yesterday

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argumen…

Sunlitnewbee-ltd · newbee-mallEPSS 0.39%via NVD
CVE-2026-88856Critical· 9.4
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.48%via NVD
CVE-2026-94035Medium· 4.3
yesterday

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.28%via NVD
CVE-2026-94034Low· 3.5
yesterday

A vulnerability was found in SourceCodester Drug Recommendation System 1.0

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.20%via NVD
CVE-2026-94033Low· 3.5
yesterday

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txt…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.20%via NVD
CVE-2026-94016Low· 2.4
yesterday

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross si…

SunlitSourceCodester · Drug Recommendation SystemEPSS 0.21%via NVD
CVE-2026-90817Critical· 9.8PoC
yesterday

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an uninte…

AbyssalVanderbilt University · REDCapEPSS 0.57%via NVD
CVE-2026-94004High· 7.3PoC
yesterday

A vulnerability was found in DedeCMS up to 5.7.118

A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument aid results in code injection. The attack can be launched remotely. The explo…

MidnightEPSS 0.30%via NVD
CVE-2026-93977Low· 3.5
yesterday

A vulnerability was determined in code-projects Assessment Management 1.0

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scri…

Sunlitcode-projects · Assessment ManagementEPSS 0.20%via NVD
CVE-2026-93976Low· 2.4
yesterday

A vulnerability was found in code-projects Assessment Management 1.0

A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remo…

Sunlitcode-projects · Assessment ManagementEPSS 0.21%via NVD
CVE-2026-93975Low· 2.4
yesterday

A vulnerability has been found in code-projects Assessment Management 1.0

A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/passwor…

Sunlitcode-projects · Assessment ManagementEPSS 0.21%via NVD
CVE-2026-87067High· 8.5
yesterday

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a fil…

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a fil…

TwilightEPSS 0.28%via NVD
CVE-2026-93956Low· 3.5PoC
2d ago

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query…

Twilightolivier-ls · PHP-FTSEPSS 0.24%via NVD
CVE-2026-93985Critical· 9.9PoC
2d ago

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can c…

AbyssalOpenpanel-dev · openpanelEPSS 0.48%via NVD
CVE-2026-4327High· 8.8
2d ago

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined …

Twilightsebwordpress · The WelcomizerEPSS 0.70%via NVD
CVE-2026-85658High· 8.1
2d ago

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 Th…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 Th…

Twilightproperfraction · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressEPSS 0.36%via NVD
CVE-2026-89274Critical· 9.1PoC
2d ago

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()…

Abyssalbrechtvds · WP Recipe MakerEPSS 0.38%via NVD
CVE-2026-92229Critical· 9.1PoC
2d ago

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…

Abyssalwpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form BuilderEPSS 0.40%via NVD
CVE-2026-92807High· 8.8
2d ago

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies…

Twilightpdfcrowd · Save as PDF Plugin by PDFCrowdEPSS 0.25%via NVD
CVE-2026-82340Critical· 9.8
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may…

MidnightIBM · Guardium Data ProtectionEPSS 0.51%via NVD
CVE-2026-61552High· 7.2
3d ago

Icinga 2 is an open source monitoring system

Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an o…

TwilightIcinga · icinga2EPSS 0.62%via NVD
CVE-2026-93759High· 8.6
3d ago

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application s…

TwilightMongoDB Inc. · MongoidEPSS 0.24%via NVD
CVE-2026-75031Critical· 9.8
3d ago

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unau…

MidnightInterchange · InterchangeEPSS 0.71%via NVD
CVE-2026-93505Low· 3.5PoC
3d ago

A vulnerability was found in SveltyCMS 0.0.6

A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The a…

TwilightEPSS 0.33%via NVD
CWE-94 vulnerabilities (CVEs) · VulnSea