CVE tracker
362 subscribers
4.91K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-7534 - SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter

CVE ID :CVE-2026-7534
Published : July 23, 2026, 6:16 a.m. | 1 hour, 59 minutes ago
Description :The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the custom `rs_earning_read` capability to all users — including unauthenticated visitors — combined with missing sanitization of the `reason` parameter in the `create_items()` function and missing output escaping in the `column_default()` method of `SRP_Master_Log`. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the reward points log that will execute whenever an administrator accesses the Master Log or User Reward Points admin pages.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59677 - Process Kill Attack Vector in killall() in seunshare

CVE ID :CVE-2026-59677
Published : July 23, 2026, 6:43 a.m. | 1 hour, 32 minutes ago
Description :A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59678 - portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager

CVE ID :CVE-2026-59678
Published : July 23, 2026, 6:48 a.m. | 1 hour, 27 minutes ago
Description :An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12421 - ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values

CVE ID :CVE-2026-12421
Published : July 23, 2026, 6:52 a.m. | 1 hour, 24 minutes ago
Description :The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9729 - Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter

CVE ID :CVE-2026-9729
Published : July 23, 2026, 6:52 a.m. | 1 hour, 24 minutes ago
Description :The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the save_send_notification_flag() function and missing output escaping in the wpp_notification_box() function, which concatenates raw post meta values directly into HTML attribute and textarea contexts. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9635 - WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute

CVE ID :CVE-2026-9635
Published : July 23, 2026, 6:52 a.m. | 1 hour, 24 minutes ago
Description :The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode attribute directly into the HTML output between anchor tags without applying any escaping functions. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9713 - Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload

CVE ID :CVE-2026-9713
Published : July 23, 2026, 6:52 a.m. | 1 hour, 24 minutes ago
Description :The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping on the user-supplied parameters before they are appended directly to a raw SQL query in the find_resource() function — the 'id' field is interpolated without quotes into a WHERE clause (numeric context) and 'table' is interpolated into the FROM clause, neither of which is protected by wp_magic_quotes or passed through $wpdb->prepare(). This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12082 - Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)

CVE ID :CVE-2026-12082
Published : July 23, 2026, 7:16 a.m. | 1 hour ago
Description :The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14291 - Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa

CVE ID :CVE-2026-14291
Published : July 23, 2026, 7:16 a.m. | 1 hour ago
Description :The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59676 - Local File Deletion Attack Vector in rm_rf() in seunshare

CVE ID :CVE-2026-59676
Published : July 23, 2026, 7:16 a.m. | 1 hour ago
Description :A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9066 - WP Compress < 7.10.04 - Reflected XSS via test_zone

CVE ID :CVE-2026-9066
Published : July 23, 2026, 7:16 a.m. | 1 hour ago
Description :The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-9577 - Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter

CVE ID :CVE-2026-9577
Published : July 23, 2026, 7:16 a.m. | 1 hour ago
Description :The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64800 - JetBrains GoLand Sensitive Configuration Data Exposure

CVE ID :CVE-2026-64800
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64802 - JetBrains GoLand Arbitrary Code Execution

CVE ID :CVE-2026-64802
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64803 - JetBrains GoLand Arbitrary Code Execution

CVE ID :CVE-2026-64803
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64804 - JetBrains WebStorm Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-64804
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64805 - JetBrains WebStorm Arbitrary Code Execution

CVE ID :CVE-2026-64805
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64806 - JetBrains WebStorm Arbitrary Code Execution

CVE ID :CVE-2026-64806
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64807 - JetBrains WebStorm Arbitrary Code Execution

CVE ID :CVE-2026-64807
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64808 - JetBrains PhpStorm Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-64808
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64809 - JetBrains PhpStorm Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-64809
Published : July 23, 2026, 11:36 a.m. | 39 minutes ago
Description :In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...