CVE-2026-87803 - Countly Server DBViewer Authorization Bypass
CVE ID :CVE-2026-87803
Published : Sept. 10, 2026, 10:17 a.m. | 1 hour, 26 minutes ago
Description :An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87803
Published : Sept. 10, 2026, 10:17 a.m. | 1 hour, 26 minutes ago
Description :An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by checking if every element contains a key present in a hardcoded KNOWN_STAGE_OPERATORS set. If any element contains an unrecognized stage key, such as the undocumented MongoDB-internal $_internalInhibitOptimization, the sanitizer misclassifies the entire branch as a generic array and skips stage-level stripping for all sibling stages. This allows a non-admin user with DBViewer read permission to inject forbidden operators like $lookup inside $facet sub-pipelines, performing cross-collection joins into restricted collections. This leads to unauthorized read access to sensitive data including password-reset tokens (prid), enabling account takeover.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78085 - Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4
CVE ID :CVE-2026-78085
Published : Sept. 10, 2026, 11:17 a.m. | 26 minutes ago
Description :Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-78085
Published : Sept. 10, 2026, 11:17 a.m. | 26 minutes ago
Description :Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87961 - ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header
CVE ID :CVE-2026-87961
Published : Sept. 10, 2026, 11:17 a.m. | 26 minutes ago
Description :ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-based out-of-bounds read vulnerability in the read_ID3_Header function due to a shadowed length parameter in ID3 synchronized-lyrics processing. Attackers can craft malicious MP3 files or HTTP audio streams with oversized frame size declarations to read past allocated buffer boundaries, causing device crashes or exposing adjacent heap memory.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87961
Published : Sept. 10, 2026, 11:17 a.m. | 26 minutes ago
Description :ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-based out-of-bounds read vulnerability in the read_ID3_Header function due to a shadowed length parameter in ID3 synchronized-lyrics processing. Attackers can craft malicious MP3 files or HTTP audio streams with oversized frame size declarations to read past allocated buffer boundaries, causing device crashes or exposing adjacent heap memory.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87962 - t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in MergingDigest.fromBytes
CVE ID :CVE-2026-87962
Published : Sept. 10, 2026, 11:17 a.m. | 26 minutes ago
Description :t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatched header fields to trigger ArrayIndexOutOfBoundsException or NegativeArraySizeException, aborting the parsing thread.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87962
Published : Sept. 10, 2026, 11:17 a.m. | 26 minutes ago
Description :t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatched header fields to trigger ArrayIndexOutOfBoundsException or NegativeArraySizeException, aborting the parsing thread.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84828 - Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
CVE ID :CVE-2026-84828
Published : Sept. 10, 2026, 11:20 a.m. | 22 minutes ago
Description :A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84828
Published : Sept. 10, 2026, 11:20 a.m. | 22 minutes ago
Description :A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88859 - Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction
CVE ID :CVE-2026-88859
Published : Sept. 10, 2026, 11:24 a.m. | 18 minutes ago
Description :A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88859
Published : Sept. 10, 2026, 11:24 a.m. | 18 minutes ago
Description :A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81788 - WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability
CVE ID :CVE-2026-81788
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81788
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81789 - WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability
CVE ID :CVE-2026-81789
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81789
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81791 - WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81791
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81791
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81793 - WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability
CVE ID :CVE-2026-81793
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81793
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81794 - WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability
CVE ID :CVE-2026-81794
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81794
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81795 - WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-81795
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81795
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81796 - WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability
CVE ID :CVE-2026-81796
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81796
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81799 - WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability
CVE ID :CVE-2026-81799
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81799
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81800 - WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability
CVE ID :CVE-2026-81800
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81800
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81801 - WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
CVE ID :CVE-2026-81801
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81801
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81803 - WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-81803
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81803
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81804 - WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-81804
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81804
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81805 - WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
CVE ID :CVE-2026-81805
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81805
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84816 - WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-84816
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84816
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84819 - WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-84819
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84819
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...