CVE tracker
383 subscribers
5.38K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-78276 - WordPress Fluent Boards Pro plugin <= 2.0.11 - PHP Object Injection vulnerability

CVE ID :CVE-2026-78276
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78281 - WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78281
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78283 - WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78283
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78285 - WordPress Like Button Rating plugin <= 2.6.61 - SQL Injection vulnerability

CVE ID :CVE-2026-78285
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78286 - WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability

CVE ID :CVE-2026-78286
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78288 - WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability

CVE ID :CVE-2026-78288
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78289 - WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78289
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78292 - WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability

CVE ID :CVE-2026-78292
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78293 - WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-78293
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80433 - WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-80433
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81271 - WordPress GeoDirectory plugin <= 2.8.176 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-81271
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81272 - WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability

CVE ID :CVE-2026-81272
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81273 - WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-81273
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81274 - WordPress Ditty plugin <= 3.1.67 - Broken Access Control vulnerability

CVE ID :CVE-2026-81274
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81276 - WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability

CVE ID :CVE-2026-81276
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81277 - WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection vulnerability

CVE ID :CVE-2026-81277
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81279 - WordPress Push Notification for Post and BuddyPress plugin <= 3.20 - Broken Access Control vulnerability

CVE ID :CVE-2026-81279
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81572 - Local Privilege Escalation in CodeMeter Runtime on Windows

CVE ID :CVE-2026-81572
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81573 - Improper Access Control in Local-Only Configuration Commands

CVE ID :CVE-2026-81573
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81574 - Format String Vulnerability in Logger

CVE ID :CVE-2026-81574
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this vulnerability.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81575 - Missing Sanity Checks for Buffer Lengths

CVE ID :CVE-2026-81575
Published : Aug. 27, 2026, 10:16 a.m. | 1 hour, 26 minutes ago
Description :If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds reads, causing a segmentation fault that ultimately crashes the CodeMeter Runtime.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...