Total
396163 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-8301 | 2026-09-11 | N/A | 7.8 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8. | |||||
| CVE-2026-14562 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order and attachment data. | |||||
| CVE-2026-8303 | 2026-09-11 | N/A | 7.8 HIGH | ||
| Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5. | |||||
| CVE-2026-85677 | 2026-09-11 | N/A | 8.8 HIGH | ||
| The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved. | |||||
| CVE-2026-14559 | 2026-09-11 | N/A | 9.8 CRITICAL | ||
| The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address. | |||||
| CVE-2025-15695 | 2026-09-11 | N/A | 3.5 LOW | ||
| The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. | |||||
| CVE-2026-86815 | 2026-09-11 | N/A | 5.5 MEDIUM | ||
| The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination. | |||||
| CVE-2026-7863 | 2026-09-11 | N/A | 8.4 HIGH | ||
| Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus Software: before 1.0.5. | |||||
| CVE-2026-82213 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation signature. | |||||
| CVE-2026-14563 | 2026-09-11 | N/A | 9.8 CRITICAL | ||
| The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts. | |||||
| CVE-2026-86813 | 2026-09-11 | N/A | 4.8 MEDIUM | ||
| The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header. | |||||
| CVE-2026-86782 | 2026-09-11 | N/A | 5.5 MEDIUM | ||
| The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts. | |||||
| CVE-2026-14560 | 2026-09-11 | N/A | 10.0 CRITICAL | ||
| The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server. | |||||
| CVE-2026-86780 | 2026-09-11 | N/A | 6.8 MEDIUM | ||
| The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators. | |||||
| CVE-2026-87983 | 2026-09-11 | N/A | N/A | ||
| An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the active workspace to be read without user approval. | |||||
| CVE-2026-87987 | 2026-09-11 | N/A | N/A | ||
| An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution without user approval. | |||||
| CVE-2026-87986 | 2026-09-11 | N/A | N/A | ||
| An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval. | |||||
| CVE-2026-89264 | 2026-09-11 | N/A | 4.3 MEDIUM | ||
| MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | |||||
| CVE-2026-87984 | 2026-09-11 | N/A | N/A | ||
| An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process. | |||||
| CVE-2026-89173 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses. | |||||
