Total
9864 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81269 | 1 Data Field Project | 1 Data Field | 2026-09-09 | N/A | 5.3 MEDIUM |
| Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | |||||
| CVE-2026-87605 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.3 MEDIUM |
| Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87611 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87631 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 6.5 MEDIUM |
| Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-69465 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | N/A | 8.8 HIGH |
| Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-52766 | 2026-09-09 | N/A | 9.1 CRITICAL | ||
| YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl='*') on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6. | |||||
| CVE-2026-11821 | 2026-09-09 | N/A | 5.4 MEDIUM | ||
| The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to view, create, update, clone, and delete notification flow event automation workflows that should be restricted to administrators. | |||||
| CVE-2026-69724 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | N/A | 8.8 HIGH |
| Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-87443 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 6.5 MEDIUM |
| Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-85133 | 2026-09-09 | N/A | 5.4 MEDIUM | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration. | |||||
| CVE-2026-85132 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured. | |||||
| CVE-2026-82848 | 2026-09-09 | N/A | 5.3 MEDIUM | ||
| The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well. | |||||
| CVE-2026-82185 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite the cookie banner configuration shown to every visitor and to irreversibly reset the stored A/B test results. | |||||
| CVE-2026-82184 | 2026-09-09 | N/A | 5.3 MEDIUM | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data. | |||||
| CVE-2026-75905 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to take ownership of any admin-authored recipe by rewriting its post_author to the attacker's user ID, and unpublish it by overwriting its post_status with the contributor's draft or pending post status. This requires the default 'recipe_use_author' setting to be set to 'parent' for the ownership transfer to occur, though unpublishing remains possible regardless of this setting. | |||||
| CVE-2026-75861 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In 3.2.9 an ownership check was added on one of the two affected redemption paths; the one that remains requires a companion Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 from the same vendor to be active. | |||||
| CVE-2026-53769 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0. | |||||
| CVE-2026-3174 | 2026-09-09 | N/A | 7.5 HIGH | ||
| The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant credentials (access tokens, publishable keys, and account ID), diverting all subsequent payment processing to the attacker's Stripe account. | |||||
| CVE-2026-19802 | 2026-09-09 | N/A | 4.3 MEDIUM | ||
| The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate an arbitrary attacker-hosted plugin, resulting in remote code execution on the server. The required nonce is emitted inline on all admin pages accessible to subscribers when WooCommerce is inactive, meaning any subscriber-level user can harvest it and trigger the exploit without any additional privileges. | |||||
| CVE-2026-18042 | 2026-09-09 | N/A | 5.3 MEDIUM | ||
| The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its front-end payment-message handlers, allowing unauthenticated attackers to cancel the payment on any customer's booking. | |||||
