CVE tracker
312 subscribers
4.41K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-48843 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-48843
Published : May 25, 2026, 7:11 p.m. | 53 minutes ago
Description :Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48844 - Roundcube Webmail LDAP Code Injection Vulnerability

CVE ID :CVE-2026-48844
Published : May 25, 2026, 7:14 p.m. | 49 minutes ago
Description :Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9485 - SourceCodester Student Grades Management System students.php cross site scripting

CVE ID :CVE-2026-9485
Published : May 25, 2026, 7:15 p.m. | 49 minutes ago
Description :A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48845 - Roundcube Webmail Local/Private Image Disclosure Vulnerability

CVE ID :CVE-2026-48845
Published : May 25, 2026, 7:18 p.m. | 46 minutes ago
Description :In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48846 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-48846
Published : May 25, 2026, 7:21 p.m. | 43 minutes ago
Description :In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48847 - Roundcube Webmail Redis/Memcache File Deletion Vulnerability

CVE ID :CVE-2026-48847
Published : May 25, 2026, 7:23 p.m. | 40 minutes ago
Description :Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24546 - WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability

CVE ID :CVE-2026-24546
Published : May 25, 2026, 7:26 p.m. | 37 minutes ago
Description :Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48848 - Roundcube Webmail CSS Injection Vulnerability

CVE ID :CVE-2026-48848
Published : May 25, 2026, 7:27 p.m. | 36 minutes ago
Description :Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9486 - SourceCodester Student Grades Management System cross-site request forgery

CVE ID :CVE-2026-9486
Published : May 25, 2026, 7:30 p.m. | 34 minutes ago
Description :A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24586 - WordPress Newses theme <= 2.0.0.77 - Broken Access Control vulnerability

CVE ID :CVE-2026-24586
Published : May 25, 2026, 9:32 p.m. | 2 hours, 33 minutes ago
Description :Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-62745 - WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2025-62745
Published : May 25, 2026, 9:34 p.m. | 2 hours, 31 minutes ago
Description :Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24527 - WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14.0 - Broken Access Control vulnerability

CVE ID :CVE-2026-24527
Published : May 25, 2026, 9:40 p.m. | 2 hours, 25 minutes ago
Description :Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24554 - WordPress WPSubscription plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-24554
Published : May 25, 2026, 9:41 p.m. | 2 hours, 24 minutes ago
Description :Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This issue affects WPSubscription: from n/a through 1.9.1.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-27346 - WordPress B2BKing plugin < 5.2.10 - Broken Access Control vulnerability

CVE ID :CVE-2026-27346
Published : May 25, 2026, 9:54 p.m. | 2 hours, 11 minutes ago
Description :Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-27398 - WordPress RSVP and Event Management plugin <= 2.7.16 - Broken Access Control vulnerability

CVE ID :CVE-2026-27398
Published : May 25, 2026, 9:56 p.m. | 2 hours, 9 minutes ago
Description :Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-27357 - WordPress WP Search Analytics plugin < 1.5.0 - Broken Access Control vulnerability

CVE ID :CVE-2026-27357
Published : May 25, 2026, 9:59 p.m. | 2 hours, 7 minutes ago
Description :Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9511 - Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection

CVE ID :CVE-2026-9511
Published : May 25, 2026, 10 p.m. | 2 hours, 6 minutes ago
Description :A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48837 - WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vulnerability

CVE ID :CVE-2026-48837
Published : May 25, 2026, 10:05 p.m. | 2 hours, 1 minute ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-24937 - WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) vulnerability

CVE ID :CVE-2026-24937
Published : May 25, 2026, 10:13 p.m. | 1 hour, 53 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a before 7.1.3.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9512 - Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection

CVE ID :CVE-2026-9512
Published : May 25, 2026, 10:15 p.m. | 1 hour, 51 minutes ago
Description :A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39436 - WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-39436
Published : May 25, 2026, 10:15 p.m. | 1 hour, 51 minutes ago
Description :Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...