Tagged “cve.org”
CVEs tagged cve.org, newest first.
18496 CVEsRSS
CVE-2026-89260High· 7.5PoCMoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an u…
CVE-2026-89259Critical· 9.8Hugo is a static site generator
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --al…
CVE-2026-89254High· 8.7AVideo CustomizeUser Stored XSS via field_name Parameter
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject …
CVE-2026-89249High· 8.7AVideo YPTWallet Stored XSS via CryptoWallet Configuration
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in…
CVE-2026-89244Medium· 6.1WWBN AVideo Reflected XSS via Gallery Category getBackURL
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href…
CVE-2026-89239Medium· 6.1WWBN AVideo Reflected XSS via Referer Header Comment Breakout
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding…
CVE-2026-89060High· 7.7A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
CVE-2026-6642Medium· 6.4Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset fi…
CVE-2026-62136Medium· 5.3WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.
CVE-2026-62114Medium· 5.3WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
CVE-2026-62109High· 7.6WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
CVE-2026-62102High· 8.8WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
CVE-2026-62088Medium· 5.3WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.
CVE-2026-19991High· 8.1UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from…
CVE-2026-18561High· 7.5Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the …
CVE-2026-50025Medium· 6.9Mousehole is a background service to update a seedbox IP for MAM and web app to manage it
Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…
CVE-2026-48490Medium· 6.9ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point…
CVE-2026-82617Critical· 9.8The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers
The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these …
CVE-2026-67211High· 7.5OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4
OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain t…
CVE-2026-54166High· 7.1Shelf is a platform for tracking physical assets
Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feat…
CVE-2026-54165Medium· 6.4PoCDobase is an open-source, self-hosted workspace with installable tools
Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthenticated shared-folder image gallery. A…
CVE-2026-47773High· 7.2ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models
ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt mem…
CVE-2026-90460High· 7.6PoCAn issue was discovered in OpenStack Keystone before 29.0.3
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…
CVE-2026-54241High· 7.4libde265 is an open source implementation of the h.265 video codec
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and …
CVE-2026-54240High· 7.4libde265 is an open source implementation of the h.265 video codec
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflo…
CVE-2026-45057Medium· 4.9matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself i…
CVE-2026-45056Medium· 6.9⚖ disputedmatrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…
CVE-2026-44715High· 8.7OpenMRS is an open source electronic medical record system platform
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, w…
CVE-2026-54258Medium· 6.5PoCZoneMinder is a free, open source closed-circuit television software application
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to …
CVE-2026-54248Medium· 6.5Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks
Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided …