VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15548 CVEsRSS

CVE-2026-89002Medium· 6.8
4d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Sc…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Sc…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-88847Medium· 4.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create cou…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create cou…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88846Medium· 5.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated use…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated use…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-88845Medium· 4.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88843High· 7.2
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute …

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-84151Low· 3.5
4d ago

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input e…

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input e…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-82850Medium· 4.3
4d ago

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses the…

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses the…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-82849Medium· 4.3
4d ago

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another use…

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another use…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-82195Medium· 6.5
4d ago

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete …

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete …

▾ SunlitEPSS 0.23%via NVD
CVE-2026-80513High· 7.5
4d ago

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a …

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a …

▾ TwilightEPSS 0.31%via NVD
CVE-2026-80338Medium· 6.8
4d ago

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-74991Medium· 6.8
4d ago

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate …

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate …

▾ SunlitEPSS 0.18%via NVD
CVE-2026-14780High· 7.5
4d ago

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the…

▾ TwilightPaperCut · PaperCut NG/MFEPSS 0.31%via NVD
CVE-2026-97155Medium· 6.5
4d ago

Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default

Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDO…

▾ SunlitFabasoft · Folio ClientEPSS 0.11%via NVD
CVE-2026-96898High· 7.3
4d ago

A vulnerability was detected in yhx070424 ShopXO up to 2.2.7

A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type…

▾ Twilightyhx070424 · ShopXOEPSS 0.42%via NVD
CVE-2026-97151High· 8.4
4d ago

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 thro…

▾ Twilightmwilliamson · mammothEPSS 0.36%via NVD
CVE-2026-96892Medium· 4.3PoC
4d ago

A flaw has been found in Edimax BR-6428nC 1.16

A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open redirect. The attack may be launched …

▾ TwilightEdimax · BR-6428nCEPSS 0.34%via NVD
CVE-2026-97152High· 8.6
4d ago

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

▾ TwilightNanomsg · NanomsgEPSS 0.31%via NVD
CVE-2026-96891Critical· 9.8
4d ago

A vulnerability was identified in D-Link DIR-825 3.00b32

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack …

▾ MidnightD-Link · DIR-825EPSS 0.65%via NVD
CVE-2026-96884Medium· 6.3PoC
4d ago

A security flaw has been discovered in MantisZip up to 0.4.5

A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the file MainWindow.UI.cs of the component Preview. The manipulation results in path traversal. It is possible to launch…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-97149Medium· 5.3
4d ago

In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests

In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense ag…

▾ SunlitOpenStack · SwiftEPSS 0.24%via NVD
CVE-2026-97056Medium· 6.8PoC
4d ago

SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is …

SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is …

▾ TwilightSigNoz · signozEPSS 0.35%via NVD
CVE-2026-96882Medium· 5.3
4d ago

A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1

A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component b…

▾ SunlitTaleLin · lin-cms-spring-bootEPSS 0.29%via NVD
CVE-2026-96881Medium· 5.3PoC
4d ago

A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1

A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Executing …

▾ TwilightTaleLin · lin-cms-spring-bootEPSS 0.29%via NVD
CVE-2026-97055High· 8.1PoC
4d ago

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the …

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the …

▾ MidnightSigNoz · signozEPSS 0.41%via NVD
CVE-2026-96880Medium· 5.3PoC
4d ago

A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1

A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a ma…

▾ TwilightTaleLin · lin-cms-spring-bootEPSS 0.29%via NVD
CVE-2026-96810Low· 3.5PoC
4d ago

A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1

A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonCont…

▾ Twilighthuanzi-qch · base-adminEPSS 0.19%via NVD
CVE-2026-18467Critical· 9.8
4d ago

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-u…

▾ Midnightpaytiumsupport · Paytium: Mollie payment forms & donationsEPSS 0.39%via NVD
CVE-2026-96803High· 7.3PoC
4d ago

A vulnerability was identified in java110 MicroCommunity up to 2.0

A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql …

▾ Midnightjava110 · MicroCommunityEPSS 0.25%via NVD
CVE-2026-96777Medium· 6.3
4d ago

A vulnerability was determined in Forma LMS up to 4.1.43

A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.adm_server.php?r=adm/userselector/getData of the component Multi-User-Selector AJAX Endp…

▾ SunlitForma · LMSEPSS 0.20%via NVD
CVEs tagged “cve.org” — page 56 · VulnSea