CVE tracker
370 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-14922 - WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment

CVE ID :CVE-2026-14922
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `&lt;img src=... onload=...&gt;`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14927 - FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes

CVE ID :CVE-2026-14927
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14928 - JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject

CVE ID :CVE-2026-14928
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14929 - JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR

CVE ID :CVE-2026-14929
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14930 - JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload

CVE ID :CVE-2026-14930
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14931 - JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure

CVE ID :CVE-2026-14931
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15048 - GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History

CVE ID :CVE-2026-15048
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15209 - JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR

CVE ID :CVE-2026-15209
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15258 - Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter

CVE ID :CVE-2026-15258
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15381 - WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter

CVE ID :CVE-2026-15381
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16236 - Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload

CVE ID :CVE-2026-16236
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18452 - Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials

CVE ID :CVE-2026-18452
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8155 - BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR

CVE ID :CVE-2026-8155
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65309 - Storage of passwords in a reversible format

CVE ID :CVE-2026-65309
Published : July 31, 2026, 7:17 a.m. | 35 minutes ago
Description :ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16105 - Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints

CVE ID :CVE-2026-16105
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18203 - Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes

CVE ID :CVE-2026-18203
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18206 - Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass

CVE ID :CVE-2026-18206
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18208 - Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim

CVE ID :CVE-2026-18208
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18209 - Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check

CVE ID :CVE-2026-18209
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18211 - Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains

CVE ID :CVE-2026-18211
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18214 - Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction

CVE ID :CVE-2026-18214
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...