Vulnerabilities (CVE)

Total 398447 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-58192 1 Appium 1 Appium\/storage-plugin 2026-08-26 N/A 8.6 HIGH
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to escape the storage root with ../ sequences and recursively delete arbitrary writable files or directories. This issue is fixed in version 1.1.6.
CVE-2026-49307 2026-08-26 N/A 6.2 MEDIUM
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49302 2026-08-26 N/A 6.2 MEDIUM
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49306 2026-08-26 N/A 3.3 LOW
UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-58561 2026-08-26 N/A 4.0 MEDIUM
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-58560 2026-08-26 N/A 4.0 MEDIUM
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49304 2026-08-26 N/A 6.2 MEDIUM
Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49305 2026-08-26 N/A 6.2 MEDIUM
Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49308 2026-08-26 N/A 5.5 MEDIUM
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-49301 2026-08-26 N/A 6.2 MEDIUM
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-15930 2026-08-26 N/A 9.4 CRITICAL
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.
CVE-2026-15206 2026-08-26 N/A 7.5 HIGH
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to select the account and logs them in. An unauthenticated attacker can therefore log in as any user, including an administrator, who has a billing phone on file.
CVE-2026-16285 2026-08-26 N/A 7.5 HIGH
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
CVE-2026-14922 2026-08-26 N/A 6.1 MEDIUM
WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `<img src=... onload=...>`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`).
CVE-2026-14317 2026-08-26 N/A 5.3 MEDIUM
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled.
CVE-2026-14938 2026-08-26 N/A 4.3 MEDIUM
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.
CVE-2025-15673 2026-08-26 N/A 4.9 MEDIUM
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
CVE-2026-15209 2026-08-26 N/A 6.5 MEDIUM
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
CVE-2026-16256 2026-08-26 N/A 9.8 CRITICAL
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.
CVE-2026-14920 2026-08-26 N/A 8.2 HIGH
## Summary