CVE ID :CVE-2026-23588
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23589
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23590
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23591
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 2, 2026, 7:52 a.m. | 19 minutes ago
Description :None
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82958 - Eclipse Ditto ImplicitThingCreationMessageMapper JSON Injection Vulnerability
CVE ID :CVE-2026-82958
Published : Sept. 2, 2026, 11:17 a.m. | 54 minutes ago
Description :In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing" template as raw, un-escaped strings, and then parses the resulting string as JSON. Because the placeholder engine performs no JSON escaping and is unaware of the surrounding JSON string context, a resolved value containing a double-quote character can break out of its string and inject additional JSON structure. When a connection is configured to use this mapper with a template that reflects a header whose value a publishing device can control (for example an MQTT 5 user property, an AMQP 1.0 application property, or a Kafka record header), an attacker able to publish on that connection can inject an inline _policy object. The inline policy overrides the administrator-configured policyId, letting the attacker assign an arbitrary access-control policy to the newly created digital twin — gaining full read/write access to it and potentially revoking the legitimate owner's access, with no administrator interaction. Exploitation requires all of the following: the connection uses the (non-default) ImplicitThingCreation mapper; its template reflects an attacker-controllable header; and, for the policy-override impact, the connection's authorization subjects are permitted to create policies (the default). Deployments that restrict the connection's subjects to thing creation only via the entity-creation configuration are not affected by the policy-override impact.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82958
Published : Sept. 2, 2026, 11:17 a.m. | 54 minutes ago
Description :In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing" template as raw, un-escaped strings, and then parses the resulting string as JSON. Because the placeholder engine performs no JSON escaping and is unaware of the surrounding JSON string context, a resolved value containing a double-quote character can break out of its string and inject additional JSON structure. When a connection is configured to use this mapper with a template that reflects a header whose value a publishing device can control (for example an MQTT 5 user property, an AMQP 1.0 application property, or a Kafka record header), an attacker able to publish on that connection can inject an inline _policy object. The inline policy overrides the administrator-configured policyId, letting the attacker assign an arbitrary access-control policy to the newly created digital twin — gaining full read/write access to it and potentially revoking the legitimate owner's access, with no administrator interaction. Exploitation requires all of the following: the connection uses the (non-default) ImplicitThingCreation mapper; its template reflects an attacker-controllable header; and, for the policy-override impact, the connection's authorization subjects are permitted to create policies (the default). Deployments that restrict the connection's subjects to thing creation only via the entity-creation configuration are not affected by the policy-override impact.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84781 - WordPress Gallery PhotoBlocks plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-84781
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84781
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81283 - WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability
CVE ID :CVE-2026-81283
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81283
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81286 - WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability
CVE ID :CVE-2026-81286
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81286
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81288 - WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81288
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81288
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81289 - WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.13.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81289
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81289
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81294 - WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability
CVE ID :CVE-2026-81294
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81294
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81769 - WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability
CVE ID :CVE-2026-81769
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Subscriber Privilege Escalation in Booking Hub <= 1.3.1 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81769
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Subscriber Privilege Escalation in Booking Hub <= 1.3.1 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81770 - WordPress Interactive Geo Maps plugin <= 1.6.30 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81770
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81770
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81771 - WordPress TrustedSite plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81771
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81771
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81772 - WordPress Ninja Forms - Layout & Styles plugin <= 3.0.31 - PHP Object Injection vulnerability
CVE ID :CVE-2026-81772
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81772
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81774 - WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-81774
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81774
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81775 - WordPress Estatik plugin <= 4.3.4 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81775
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81775
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82223 - WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerability
CVE ID :CVE-2026-82223
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82223
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-83562 - WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-83562
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-83562
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84759 - WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-84759
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84759
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84760 - WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access Control vulnerability
CVE ID :CVE-2026-84760
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84760
Published : Sept. 2, 2026, 11:37 a.m. | 34 minutes ago
Description :Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...