CVE-2026-19035 - Shibby Tomato qoslimit new_qoslimit_start os command injection
CVE ID :CVE-2026-19035
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19035
Published : Aug. 6, 2026, 11:30 a.m. | 38 minutes ago
Description :A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66685 - WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-66685
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66685
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66686 - WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-66686
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66686
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66688 - WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66688
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66688
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66690 - WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66690
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66690
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66692 - WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability
CVE ID :CVE-2026-66692
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66692
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66694 - WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66694
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66694
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66695 - WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
CVE ID :CVE-2026-66695
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66695
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66696 - WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-66696
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66696
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66699 - WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
CVE ID :CVE-2026-66699
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66699
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66701 - WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability
CVE ID :CVE-2026-66701
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66701
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66702 - WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66702
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66702
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66703 - WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66703
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66703
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66705 - WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66705
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66705
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66706 - WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66706
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66706
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66707 - WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66707
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66707
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66708 - WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
CVE ID :CVE-2026-66708
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66708
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66709 - WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-66709
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66709
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66710 - WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability
CVE ID :CVE-2026-66710
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66710
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66711 - WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-66711
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66711
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66712 - WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability
CVE ID :CVE-2026-66712
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-66712
Published : Aug. 6, 2026, 3:17 p.m. | 51 minutes ago
Description :Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...