CVE tracker
394 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-88845 - MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import

CVE ID :CVE-2026-88845
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88846 - MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disabled

CVE ID :CVE-2026-88846
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88847 - MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation

CVE ID :CVE-2026-88847
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89002 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview

CVE ID :CVE-2026-89002
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89004 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR

CVE ID :CVE-2026-89004
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-89005 - WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category

CVE ID :CVE-2026-89005
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93661 - Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR

CVE ID :CVE-2026-93661
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93662 - Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' Parameter

CVE ID :CVE-2026-93662
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97168 - Rejected reason: suggestion

CVE ID :CVE-2026-97168
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :Rejected reason: suggestion
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97176 - Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator

CVE ID :CVE-2026-97176
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97177 - Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission

CVE ID :CVE-2026-97177
Published : Sept. 24, 2026, 6:17 a.m. | 1 hour, 2 minutes ago
Description :A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81645 - Graphics Module Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-81645
Published : Sept. 24, 2026, 6:18 a.m. | 1 hour, 1 minute ago
Description :Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82077 - PaperCut NG/MF: Remote Code Execution via Scan2Fax

CVE ID :CVE-2026-82077
Published : Sept. 24, 2026, 6:43 a.m. | 35 minutes ago
Description :An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87739 - PaperCut MF/NG: User permissions are not evaluated on report generation

CVE ID :CVE-2026-87739
Published : Sept. 24, 2026, 6:46 a.m. | 32 minutes ago
Description :An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11744 - PaperCut Hive Embedded App for Ricoh: Javascript injection

CVE ID :CVE-2026-11744
Published : Sept. 24, 2026, 6:51 a.m. | 28 minutes ago
Description :An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a specially crafted NFC card or emulator could exploit this flaw to execute arbitrary code within the context of the application's user interface. This could result in unauthorized actions or information disclosure.
Severity: 3.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97181 - ezGlobal|GPM LIGHT - Sensitive Data Exposure

CVE ID :CVE-2026-97181
Published : Sept. 24, 2026, 8:17 a.m. | 3 hours, 3 minutes ago
Description :GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77193 - eesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query Parameter

CVE ID :CVE-2026-77193
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78308 - Authentication Bypass in DIAEnergie

CVE ID :CVE-2026-78308
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78309 - SQL Injection in DIAEnergie

CVE ID :CVE-2026-78309
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78310 - Authorization Bypass Through User-Controlled Key in DIAEnergie

CVE ID :CVE-2026-78310
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78311 - SQL Injection in DIAEnergie

CVE ID :CVE-2026-78311
Published : Sept. 24, 2026, 9:17 a.m. | 2 hours, 2 minutes ago
Description :SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...