Search Results (43615 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100371 1 Invoiceplane 1 Invoiceplane 2026-09-29 N/A
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password of the primary administrator (user_id=1) through users/change_password/{id}. That remediation, however, protects only the direct password-change operation. It does not protect the identity attribute that password recovery actually trusts: user_email. Users::form() applies no equivalent object-level authorization check when editing the primary administrator's account, and user_email is not included in PROTECTED_FIELDS. A secondary administrator can therefore rewrite the primary administrator's email address, then drive the public password-recovery flow — which resolves the account by user_email — to receive the reset token and take over user_id=1. The result is an alternate attack path that achieves the same impact PR #1638 was intended to prevent: cross-administrator full account takeover of the primary administrator. This issue has been patched via commit 8616fa4.
CVE-2026-73460 1 Arista 1 Eos 2026-09-29 6.1 Medium
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.
CVE-2026-87963 1 Wordpress-extensions 1 Yo 2026-09-29 8.6 High
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
CVE-2026-66618 2 Flippercode, Wordpress-extensions 2 Wp Maps, Wp Maps 2026-09-29 7.6 High
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66619 2 Tribulant, Wordpress-extensions 2 Newsletters, Newsletters 2026-09-29 7.6 High
Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66631 2 Moreconvert, Wordpress-extensions 2 Woocommerce Wishlist, Mc Woocommerce Wishlist 2026-09-29 7.6 High
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-78528 2 Berqier, Wordpress-extensions 2 Berqwp, Berqwp 2026-09-29 5.3 Medium
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
CVE-2026-16750 2 Stylemixthemes, Wordpress-extensions 2 Motors - Car Dealer, Classifieds & Listing, Motors – Car Dealership & Classified Listings 2026-09-29 5.3 Medium
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.
CVE-2026-16582 2 Ameliabooking, Wordpress-extensions 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia 2026-09-29 5.3 Medium
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment
CVE-2026-14311 2 Ameliabooking, Wordpress-extensions 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia 2026-09-29 5.4 Medium
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.
CVE-2026-84904 2 Kingaddons, Wordpress-extensions 2 King Addons For Elementor, King Addons For Elementor 2026-09-29 3.8 Low
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.
CVE-2026-87767 1 Wordpress-extensions 1 Wp Shortcut Link 2026-09-29 8.6 High
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87770 1 Wordpress-extensions 1 Price Drop Alert For Woo Commerce 2026-09-29 8.6 High
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87771 1 Wordpress-extensions 1 Product Question And Answer 2026-09-29 8.6 High
The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them in SQL queries on AJAX actions available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87774 1 Wordpress-extensions 1 Tz Weekly Radio Schedule 2026-09-29 8.6 High
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-87775 1 Wordpress-extensions 1 Tz Weekly Radio Schedule 2026-09-29 8.6 High
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
CVE-2026-82560 1 Perl 1 Pod::text 2026-09-29 7.5 High
Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass. Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted.
CVE-2026-87082 1 Perl 1 Net::idn::punycode 2026-09-29 7.5 High
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set over malformed bytes, as the :utf8 PerlIO layer produces from any malformed input, reaches the encoder unchecked. On perl 5.32 and later the XS backend reports a malformed sequence with a length of `(STRLEN)-1`, so the scan steps back one byte instead of forward and never ends. On earlier perls the XS returns a valid label for a different name. The pure-Perl backend runs a regex over the flagged string. Depending on the bytes, it aborts with SIGBUS on perl 5.28 and later, dies with a panic, or returns a wrong label. The documented conversion functions match the label against Unicode properties first and that match dies on such a string, so only a direct call to encode_punycode reaches the defect. The decoder is not affected. A direct caller encoding attacker-supplied bytes hangs, crashes or gets a label for a name the input never held.
CVE-2026-97227 1 Wordpress-extensions 1 Nextscripts Social Networks Auto-poster 2026-09-29 5.9 Medium
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
CVE-2023-6394 2 Quarkus, Redhat 3 Quarkus, Build Of Quarkus, Quarkus 2026-09-29 7.4 High
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.