CVE tracker
393 subscribers
5.67K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-93965 - aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection

CVE ID :CVE-2026-93965
Published : Sept. 20, 2026, 5:45 a.m. | 44 minutes ago
Description :A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84223 - Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload

CVE ID :CVE-2026-84223
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the site's own origin and runs in the session of anyone who opens it.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-85017 - Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection

CVE ID :CVE-2026-85017
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87067 - Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection

CVE ID :CVE-2026-87067
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Forminator Forms WordPress plugin before 1.57.2.1's own settings, so the issue is reachable well below administrator on sites that use that feature.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87068 - Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import

CVE ID :CVE-2026-87068
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87839 - Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion

CVE ID :CVE-2026-87839
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87840 - Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering

CVE ID :CVE-2026-87840
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92410 - Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF

CVE ID :CVE-2026-92410
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92422 - Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route

CVE ID :CVE-2026-92422
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92423 - Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts

CVE ID :CVE-2026-92423
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92540 - Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users

CVE ID :CVE-2026-92540
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92541 - Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer

CVE ID :CVE-2026-92541
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92965 - TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption

CVE ID :CVE-2026-92965
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every request to the site rather than only on the administrator's sign-in.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93966 - aiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injection

CVE ID :CVE-2026-93966
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of the argument command leads to command injection. The attack may be launched remotely. The name of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93967 - aiyiyi121 SxDevOps Command services.py generate_host_task command injection

CVE ID :CVE-2026-93967
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93968 - aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management

CVE ID :CVE-2026-93968
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93969 - aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials

CVE ID :CVE-2026-93969
Published : Sept. 20, 2026, 7:16 a.m. | 3 hours, 12 minutes ago
Description :A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86554 - Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP

CVE ID :CVE-2026-86554
Published : Sept. 20, 2026, 8:16 a.m. | 2 hours, 12 minutes ago
Description :SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93970 - aiyiyi121 SxDevOps Settings settings.py hard-coded credentials

CVE ID :CVE-2026-93970
Published : Sept. 20, 2026, 8:16 a.m. | 2 hours, 12 minutes ago
Description :A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93971 - aiyiyi121 SxDevOps settings.py information disclosure

CVE ID :CVE-2026-93971
Published : Sept. 20, 2026, 8:16 a.m. | 2 hours, 12 minutes ago
Description :A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93972 - SourceCodester Online Reviewer Management System btn_functions.php sql injection

CVE ID :CVE-2026-93972
Published : Sept. 20, 2026, 8:16 a.m. | 2 hours, 12 minutes ago
Description :A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...