CVE tracker
380 subscribers
5.35K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-78059 - SourceCodester Stock Management System printOrder.php cross site scripting

CVE ID :CVE-2026-78059
Published : Aug. 23, 2026, 4:16 a.m. | 2 hours, 35 minutes ago
Description :A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78060 - SourceCodester Stock Management System getOrderReport.php cross site scripting

CVE ID :CVE-2026-78060
Published : Aug. 23, 2026, 4:17 a.m. | 2 hours, 34 minutes ago
Description :A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78061 - vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery

CVE ID :CVE-2026-78061
Published : Aug. 23, 2026, 4:17 a.m. | 2 hours, 34 minutes ago
Description :A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78062 - vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials

CVE ID :CVE-2026-78062
Published : Aug. 23, 2026, 5:16 a.m. | 1 hour, 35 minutes ago
Description :A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78063 - Tenda CH22 editFileName formeditFileName command injection

CVE ID :CVE-2026-78063
Published : Aug. 23, 2026, 5:16 a.m. | 1 hour, 35 minutes ago
Description :A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13598 - RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator

CVE ID :CVE-2026-13598
Published : Aug. 23, 2026, 6:16 a.m. | 35 minutes ago
Description :The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14853 - WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization

CVE ID :CVE-2026-14853
Published : Aug. 23, 2026, 6:17 a.m. | 34 minutes ago
Description :The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77003 - Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_mask

CVE ID :CVE-2026-77003
Published : Aug. 23, 2026, 6:17 a.m. | 34 minutes ago
Description :The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77115 - Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters

CVE ID :CVE-2026-77115
Published : Aug. 23, 2026, 6:17 a.m. | 34 minutes ago
Description :Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77116 - Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview

CVE ID :CVE-2026-77116
Published : Aug. 23, 2026, 6:17 a.m. | 34 minutes ago
Description :Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10053 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

CVE ID :CVE-2026-10053
Published : Aug. 23, 2026, 10:16 a.m. | 35 minutes ago
Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78112 - itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection

CVE ID :CVE-2026-78112
Published : Aug. 23, 2026, 10:16 a.m. | 35 minutes ago
Description :A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78115 - SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization

CVE ID :CVE-2026-78115
Published : Aug. 23, 2026, 10:16 a.m. | 35 minutes ago
Description :A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78155 - Untrusted Search Path in StackGres

CVE ID :CVE-2026-78155
Published : Aug. 23, 2026, 10:16 a.m. | 35 minutes ago
Description :privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-4671 - justhtml before 1.18.0 Denial of Service via CSS Selector

CVE ID :CVE-2026-4671
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM trees from untrusted structure, or enable linkification over attacker-controlled text may consume disproportionate CPU or memory. Triggers include oversized selectors, large selector lists, oversized compound selectors, long combinator chains, deeply nested functional pseudo-classes, repeated token/positional matching, cyclic DOM graphs causing non-terminating traversal, and punctuation-heavy or trailing-bracket linkification input. These are availability-only concerns and do not by themselves allow script execution, data disclosure, or sanitizer bypass. Default JustHTML(sanitize=True) usage is not expected to be exposed, since selectors are normally supplied by application code.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-5388 - justhtml before 1.15.0 Multiple Security Issues

CVE ID :CVE-2026-5388
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject active HTML and JavaScript — for example via encoded javascript: URLs, backslash-based relative URLs resolved as remote hosts, markup-breaking programmatic element/attribute names or HTML comments, raw reintroduction through Markdown passthrough, or preserved
CVE-2026-5389 - justhtml before 1.13.0 XSS via code fence breakout

CVE ID :CVE-2026-5389
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to break out of fixed-length code fences, allowing raw HTML to execute when the generated Markdown is rendered by CommonMark or GFM-style renderers.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-5751 - justhtml before 1.14.0 Mutation XSS via custom sanitization policies

CVE ID :CVE-2026-5751
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespaces=False with allowlisted SVG/MathML elements or raw-text containers such as
CVE-2026-6827 - justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities

CVE ID :CVE-2026-6827
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG , MathML ) and mutation-XSS parser-differential payloads could survive sanitization and become active HTML after reparse; SVG filter="url(...)" and preserved
CVE-2026-74793 - justhtml before 3.11.0 XSS via selectedcontent projection

CVE ID :CVE-2026-74793
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elements with event handlers that are cloned and reinserted into output without sanitization, enabling stored or reflected XSS attacks.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77088 - justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span

CVE ID :CVE-2026-77088
Published : Aug. 23, 2026, 2:16 p.m. | 35 minutes ago
Description :justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code or pre element text to break the inline span, causing sanitized HTML to be emitted unescaped and re-parsed as live Markdown by compliant renderers.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...