CVE tracker
378 subscribers
5.27K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-16065 - Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import

CVE ID :CVE-2026-16065
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16268 - Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler

CVE ID :CVE-2026-16268
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16290 - ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group

CVE ID :CVE-2026-16290
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16537 - Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode

CVE ID :CVE-2026-16537
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16734 - Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation

CVE ID :CVE-2026-16734
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 then updates server-side through the Stripe API with the store's secret key. An ownership check added in 8.5.0 was applied to only one payment-intent handler, leaving the pricing-recalculation and payment-intent-update actions unprotected against amount manipulation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16954 - AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens

CVE ID :CVE-2026-16954
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18050 - Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads

CVE ID :CVE-2026-18050
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18395 - Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes

CVE ID :CVE-2026-18395
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18400 - Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting

CVE ID :CVE-2026-18400
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18510 - TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content

CVE ID :CVE-2026-18510
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18967 - Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow

CVE ID :CVE-2026-18967
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19005 - nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management

CVE ID :CVE-2026-19005
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/create-agent.ts of the component Child-Agent Creation. Performing a manipulation results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19006 - mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization

CVE ID :CVE-2026-19006
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Ggateway Exec Approval Flow. The manipulation results in incorrect authorization. The attack may be performed from remote. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19007 - mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management

CVE ID :CVE-2026-19007
Published : Aug. 6, 2026, 7:16 a.m. | 50 minutes ago
Description :A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulation causes improper privilege management. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19022 - OpenHands send_pull_request.py initialize_repo command injection

CVE ID :CVE-2026-19022
Published : Aug. 6, 2026, 9:16 a.m. | 2 hours, 51 minutes ago
Description :A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue report. It appears that the affected path/file got removed in version 1.7.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64640 - Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation

CVE ID :CVE-2026-64640
Published : Aug. 6, 2026, 9:16 a.m. | 2 hours, 51 minutes ago
Description :Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside that boundary, this could disclose limited information from the object. Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary. This second condition did not itself cause Polaris to read the referenced external locations during registration. The demonstrated impact is limited to confidentiality. No unauthorized data modification or availability impact has been demonstrated. The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog's underlying storage credentials can read. Exploitation requires an authenticated principal with table- or view-registration privileges.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55978 - Improper access control vulnerability in CatchPulse

CVE ID :CVE-2026-55978
Published : Aug. 6, 2026, 10:16 a.m. | 1 hour, 51 minutes ago
Description :An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55979 - Improper access control check in CatchPulse's named pipe communication interface

CVE ID :CVE-2026-55979
Published : Aug. 6, 2026, 10:16 a.m. | 1 hour, 51 minutes ago
Description :An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies.
Severity: 5.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55980 - Denial-of-service vulnerability in CatchPulse

CVE ID :CVE-2026-55980
Published : Aug. 6, 2026, 10:16 a.m. | 1 hour, 51 minutes ago
Description :A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19034 - Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection

CVE ID :CVE-2026-19034
Published : Aug. 6, 2026, 11:16 a.m. | 51 minutes ago
Description :A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54225 - Apache CXF: Denial of Service attack via large attachments

CVE ID :CVE-2026-54225
Published : Aug. 6, 2026, 11:16 a.m. | 51 minutes ago
Description :Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...