CVE tracker
394 subscribers
5.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-89151 - Forgejo API Token Unauthorized Privilege Escalation

CVE ID :CVE-2026-89151
Published : Sept. 11, 2026, 3:16 a.m. | 30 minutes ago
Description :Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73784 - HPE IceWall products, Remote Bypass of Security Restrictions

CVE ID :CVE-2026-73784
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73785 - HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability

CVE ID :CVE-2026-73785
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-74925 - MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator

CVE ID :CVE-2026-74925
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82305 - YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title

CVE ID :CVE-2026-82305
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-83545 - CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON

CVE ID :CVE-2026-83545
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-83546 - CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute

CVE ID :CVE-2026-83546
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85677 - Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content

CVE ID :CVE-2026-85677
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visitor to the post once the comment is approved.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85678 - AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript

CVE ID :CVE-2026-85678
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86779 - Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart

CVE ID :CVE-2026-86779
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86780 - Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text

CVE ID :CVE-2026-86780
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected post, including higher-privileged users such as Editors and Administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86781 - SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure

CVE ID :CVE-2026-86781
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86782 - Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR

CVE ID :CVE-2026-86782
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86812 - WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API

CVE ID :CVE-2026-86812
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86815 - BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes

CVE ID :CVE-2026-86815
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87908 - multiparty vulnerable to Denial of Service via unbounded part-header accumulation

CVE ID :CVE-2026-87908
Published : Sept. 11, 2026, 7:16 a.m. | 31 minutes ago
Description :multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and exhausting the process memory, which crashes the server. This is a denial of service with no confidentiality or integrity impact. The issue is fixed in multiparty 4.3.1, which caps the size of the accumulated part headers. Users should upgrade to multiparty 4.3.1 or later.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89173 - Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure

CVE ID :CVE-2026-89173
Published : Sept. 11, 2026, 7:27 a.m. | 20 minutes ago
Description :Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89174 - Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection

CVE ID :CVE-2026-89174
Published : Sept. 11, 2026, 7:31 a.m. | 16 minutes ago
Description :Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89175 - Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication

CVE ID :CVE-2026-89175
Published : Sept. 11, 2026, 7:34 a.m. | 13 minutes ago
Description :Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89176 - Howyar|WeenyGenius - Missing Authentication

CVE ID :CVE-2026-89176
Published : Sept. 11, 2026, 7:34 a.m. | 12 minutes ago
Description :WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89177 - Howyar|WeenyGenius - Use of Insecure Protocol

CVE ID :CVE-2026-89177
Published : Sept. 11, 2026, 7:35 a.m. | 12 minutes ago
Description :WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...