Search Results (43506 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106212 1 Google 1 Chrome 2026-10-06 8.8 High
Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-105166 1 Kishor-23 2 Food-waste-management-system, Food Waste Management System 2026-10-06 7.3 High
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-39762 2 Patterns In The Cloud, Wordpress-extensions 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1.
CVE-2026-39764 2 Radiustheme, Wordpress-extensions 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
CVE-2026-39771 2 Mightynetworks Vs Buddyboss, Wordpress-extensions 2 Buddyboss Platform, Buddyboss Platform 2026-10-06 8.5 High
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
CVE-2026-39785 2 Serhii Pasiuk, Wordpress-extensions 2 Gmedia Photo Gallery, Gmedia Photo Gallery 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
CVE-2026-39787 2 10web, Wordpress-extensions 2 10web Social Post Feed, 10web Social Photo Feed 2026-10-06 6.5 Medium
Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
CVE-2026-39794 2 Wclovers, Wordpress-extensions 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.
CVE-2026-39795 2 Brewlabs, Wordpress-extensions 2 Sendpress Newsletters, Sendpress Newsletters 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
CVE-2026-39796 2 Flipper Code, Wordpress-extensions 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
CVE-2026-39798 2 Themetechmount, Wordpress-extensions 2 Truebooker, Truebooker 2026-10-06 6.5 Medium
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVE-2026-41555 2 Weblizar, Wordpress-extensions 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
CVE-2026-41560 2 Wordpress-extensions, Wxdlabs 2 Wxd Backup Lite, Wxd Backup Lite 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-106497 2026-10-06 4.3 Medium
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1.
CVE-2026-106496 2026-10-06 3.1 Low
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.
CVE-2026-95865 2 Beaverbuilder, Wordpress-extensions 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder 2026-10-06 6.5 Medium
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type.
CVE-2026-105306 1 Redhat 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more 2026-10-06 6.5 Medium
A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.
CVE-2026-39763 2 Deepak Anand, Wordpress-extensions 2 Wp Dummy Content Generator, Wp Dummy Content Generator 2026-10-06 4.3 Medium
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
CVE-2026-94669 2 Wordpress-extensions, Wpmanageninja 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack 2026-10-06 5.3 Medium
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
CVE-2026-103684 2 Arraytics, Wordpress-extensions 2 Wp Event Solution, Wp Event Solution 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.