Total
398447 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-58192 | 1 Appium | 1 Appium\/storage-plugin | 2026-08-26 | N/A | 8.6 HIGH |
| Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to escape the storage root with ../ sequences and recursively delete arbitrary writable files or directories. This issue is fixed in version 1.1.6. | |||||
| CVE-2026-49307 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |||||
| CVE-2026-49302 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |||||
| CVE-2026-49306 | 2026-08-26 | N/A | 3.3 LOW | ||
| UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-58561 | 2026-08-26 | N/A | 4.0 MEDIUM | ||
| Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-58560 | 2026-08-26 | N/A | 4.0 MEDIUM | ||
| Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-49304 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-49305 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability. | |||||
| CVE-2026-49308 | 2026-08-26 | N/A | 5.5 MEDIUM | ||
| Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |||||
| CVE-2026-49301 | 2026-08-26 | N/A | 6.2 MEDIUM | ||
| Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | |||||
| CVE-2026-15930 | 2026-08-26 | N/A | 9.4 CRITICAL | ||
| The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow. | |||||
| CVE-2026-15206 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file. | |||||
| CVE-2026-16285 | 2026-08-26 | N/A | 7.5 HIGH | ||
| The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID. | |||||
| CVE-2026-14922 | 2026-08-26 | N/A | 6.1 MEDIUM | ||
| WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `&lt;img src=... onload=...&gt;`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`). | |||||
| CVE-2026-14317 | 2026-08-26 | N/A | 5.3 MEDIUM | ||
| The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled. | |||||
| CVE-2026-14938 | 2026-08-26 | N/A | 4.3 MEDIUM | ||
| The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site. | |||||
| CVE-2025-15673 | 2026-08-26 | N/A | 4.9 MEDIUM | ||
| The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. | |||||
| CVE-2026-15209 | 2026-08-26 | N/A | 6.5 MEDIUM | ||
| The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | |||||
| CVE-2026-16256 | 2026-08-26 | N/A | 9.8 CRITICAL | ||
| The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site. | |||||
| CVE-2026-14920 | 2026-08-26 | N/A | 8.2 HIGH | ||
| ## Summary | |||||
