CVE-2026-81799 - WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability
CVE ID :CVE-2026-81799
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81799
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81800 - WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability
CVE ID :CVE-2026-81800
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81800
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81801 - WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
CVE ID :CVE-2026-81801
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81801
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81803 - WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-81803
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81803
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81804 - WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-81804
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81804
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81805 - WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
CVE ID :CVE-2026-81805
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-81805
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84816 - WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-84816
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84816
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84819 - WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-84819
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84819
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84821 - WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability
CVE ID :CVE-2026-84821
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84821
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85310 - WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability
CVE ID :CVE-2026-85310
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-85310
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88004 - Traefik entrypoint header-name sanitization bypassed via request trailers
CVE ID :CVE-2026-88004
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer. When the retry or buffering middleware reads the body before the reverse proxy clones the request, the attacker-controlled trailer value reaches a backend that merges trailers into the header namespace, bypassing the documented delete or reject behavior and potentially spoofing identity or forwarded routing data. This issue is fixed in 3.7.13.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88004
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer. When the retry or buffering middleware reads the body before the reverse proxy clones the request, the attacker-controlled trailer value reaches a backend that merges trailers into the header namespace, bypassing the documented delete or reject behavior and potentially spoofing identity or forwarded routing data. This issue is fixed in 3.7.13.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88005 - Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
CVE ID :CVE-2026-88005
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88005
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88006 - Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
CVE ID :CVE-2026-88006
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88006
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88007 - Traefik HTTP/3 Backend NTLM Connection Reuse
CVE ID :CVE-2026-88007
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88007
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88008 - Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
CVE ID :CVE-2026-88008
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88008
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88897 - Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
CVE ID :CVE-2026-88897
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88897
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88898 - AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint
CVE ID :CVE-2026-88898
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88898
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88924 - Gvfs: gvfs-admin socket ownership race permits local root
CVE ID :CVE-2026-88924
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88924
Published : Sept. 10, 2026, 3:17 p.m. | 26 minutes ago
Description :A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89045 - zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length
CVE ID :CVE-2026-89045
Published : Sept. 10, 2026, 6:18 p.m. | 1 hour, 26 minutes ago
Description :zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-89045
Published : Sept. 10, 2026, 6:18 p.m. | 1 hour, 26 minutes ago
Description :zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89046 - zstd-jni 1.5.5-6 through 1.5.7-13 Out-of-Bounds Read via Negative Offset
CVE ID :CVE-2026-89046
Published : Sept. 10, 2026, 6:18 p.m. | 1 hour, 26 minutes ago
Description :zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-89046
Published : Sept. 10, 2026, 6:18 p.m. | 1 hour, 26 minutes ago
Description :zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88061 - career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution
CVE ID :CVE-2026-88061
Published : Sept. 10, 2026, 7:08 p.m. | 36 minutes ago
Description :career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or restricting clients to loopback addresses. A malicious page in another browser tab could send cross-origin localhost requests while the dashboard was running, and a dashboard bound beyond loopback could receive direct requests from the local network. Both paths allowed unauthenticated command execution as the dashboard user, but npm installations were unaffected because web/ is excluded from the published package. This issue is fixed in version 0.8.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-88061
Published : Sept. 10, 2026, 7:08 p.m. | 36 minutes ago
Description :career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or restricting clients to loopback addresses. A malicious page in another browser tab could send cross-origin localhost requests while the dashboard was running, and a dashboard bound beyond loopback could receive direct requests from the local network. Both paths allowed unauthenticated command execution as the dashboard user, but npm installations were unaffected because web/ is excluded from the published package. This issue is fixed in version 0.8.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...