CVE tracker
383 subscribers
5.38K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-59278 - In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages

CVE ID :CVE-2026-59278
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76549 - UpdraftPlus < 1.26.7 - Backup Restoration via CSRF

CVE ID :CVE-2026-76549
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77016 - Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment

CVE ID :CVE-2026-77016
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77017 - Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via Candidate Profile Mass Assignment

CVE ID :CVE-2026-77017
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77018 - Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment

CVE ID :CVE-2026-77018
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77034 - Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1

CVE ID :CVE-2026-77034
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77035 - Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1

CVE ID :CVE-2026-77035
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77989 - Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1

CVE ID :CVE-2026-77989
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77990 - Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1

CVE ID :CVE-2026-77990
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77991 - Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1

CVE ID :CVE-2026-77991
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78125 - LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure

CVE ID :CVE-2026-78125
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78137 - StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart

CVE ID :CVE-2026-78137
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78138 - Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html

CVE ID :CVE-2026-78138
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78139 - Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR

CVE ID :CVE-2026-78139
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78333 - 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log

CVE ID :CVE-2026-78333
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78276 - WordPress Fluent Boards Pro plugin <= 2.0.11 - PHP Object Injection vulnerability

CVE ID :CVE-2026-78276
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78281 - WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78281
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78283 - WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78283
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78285 - WordPress Like Button Rating plugin <= 2.6.61 - SQL Injection vulnerability

CVE ID :CVE-2026-78285
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78286 - WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability

CVE ID :CVE-2026-78286
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78288 - WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability

CVE ID :CVE-2026-78288
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...