CVE tracker
388 subscribers
5.5K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-15980 - MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token

CVE ID :CVE-2026-15980
Published : Aug. 30, 2026, 5:16 a.m. | 2 hours, 41 minutes ago
Description :The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie for that account, including administrators. Successful exploitation requires the MyHome theme to be configured in legacy/WPBakery mode with frontend registration and confirmation email enabled, and the target account must not already have the myhome_agent_confirmed user meta set.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82478 - NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow

CVE ID :CVE-2026-82478
Published : Aug. 30, 2026, 5:16 a.m. | 2 hours, 41 minutes ago
Description :A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82479 - NASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflow

CVE ID :CVE-2026-82479
Published : Aug. 30, 2026, 6:16 a.m. | 1 hour, 41 minutes ago
Description :A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82480 - NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow

CVE ID :CVE-2026-82480
Published : Aug. 30, 2026, 6:16 a.m. | 1 hour, 41 minutes ago
Description :A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14307 - Geotargeting WP < 3.5.6.2 - Reflected XSS

CVE ID :CVE-2026-14307
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14835 - SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox

CVE ID :CVE-2026-14835
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any administrator who reviews the post and of any visitor once the post is published.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19722 - WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore

CVE ID :CVE-2026-19722
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76585 - Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter

CVE ID :CVE-2026-76585
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78364 - MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List

CVE ID :CVE-2026-78364
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81660 - Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field

CVE ID :CVE-2026-81660
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81766 - Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin

CVE ID :CVE-2026-81766
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the network-shared Really Simple Security WordPress plugin before 9.8.0 directory, which WordPress otherwise reserves to the network administrator. Exploitation requires the network administrator to have enabled the Really Simple Security WordPress plugin before 9.8.0 administration menu for subsites, which is not the default.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82482 - coppermine-gallery Coppermine Photo Gallery edit_profile Endpoint profile.php cross site scripting

CVE ID :CVE-2026-82482
Published : Aug. 30, 2026, 7:17 a.m. | 41 minutes ago
Description :A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.6.29 mitigates this issue. Upgrading the affected component is recommended.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82483 - coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting

CVE ID :CVE-2026-82483
Published : Aug. 30, 2026, 8:16 a.m. | 3 hours, 42 minutes ago
Description :A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.6.29 will fix this issue. It is recommended to upgrade the affected component.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82484 - itsourcecode Sales and Inventory System emp_searchfrm.php sql injection

CVE ID :CVE-2026-82484
Published : Aug. 30, 2026, 9:16 a.m. | 2 hours, 42 minutes ago
Description :A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82485 - itsourcecode Sales and Inventory System pro_edit.php sql injection

CVE ID :CVE-2026-82485
Published : Aug. 30, 2026, 9:16 a.m. | 2 hours, 42 minutes ago
Description :A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82486 - SiteServer SSCMS Agent Installation Workflow access control

CVE ID :CVE-2026-82486
Published : Aug. 30, 2026, 10:17 a.m. | 1 hour, 41 minutes ago
Description :A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82487 - Beetel 450TC3 password recovery

CVE ID :CVE-2026-82487
Published : Aug. 30, 2026, 10:17 a.m. | 1 hour, 41 minutes ago
Description :A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82540 - itsourcecode Sales and Inventory System cust_searchfrm.php sql injection

CVE ID :CVE-2026-82540
Published : Aug. 30, 2026, 11:15 a.m. | 44 minutes ago
Description :A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82488 - Beetel 450TC3 User Management cross site scripting

CVE ID :CVE-2026-82488
Published : Aug. 30, 2026, 11:17 a.m. | 41 minutes ago
Description :A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82539 - TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption

CVE ID :CVE-2026-82539
Published : Aug. 30, 2026, 11:17 a.m. | 41 minutes ago
Description :A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82639 - NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure

CVE ID :CVE-2026-82639
Published : Aug. 30, 2026, 2:17 p.m. | 1 hour, 42 minutes ago
Description :NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...