CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-97292 - WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-97292
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97293 - WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability

CVE ID :CVE-2026-97293
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97298 - WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-97298
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97299 - WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-97299
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97301 - WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-97301
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97302 - WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability

CVE ID :CVE-2026-97302
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100507 - WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-100507
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100508 - WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability

CVE ID :CVE-2026-100508
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100513 - WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-100513
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102384 - WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-102384
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102385 - WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-102385
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102386 - WordPress WP Photo Album Plus plugin <= 9.3.02.003 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-102386
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102395 - WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-102395
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102396 - WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-102396
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102398 - WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability

CVE ID :CVE-2026-102398
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102399 - WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID :CVE-2026-102399
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103116 - OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection

CVE ID :CVE-2026-103116
Published : Sept. 30, 2026, 12:45 p.m. | 45 minutes ago
Description :A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86778 - Username Enumeration in Maksisoft Technology's Maksisoft Gym

CVE ID :CVE-2026-86778
Published : Sept. 30, 2026, 12:59 p.m. | 30 minutes ago
Description :Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103117 - OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection

CVE ID :CVE-2026-103117
Published : Sept. 30, 2026, 1 p.m. | 29 minutes ago
Description :A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76504 - Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability

CVE ID :CVE-2026-76504
Published : Sept. 30, 2026, 1:04 p.m. | 25 minutes ago
Description :A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91860 - Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge

CVE ID :CVE-2026-91860
Published : Sept. 30, 2026, 1:13 p.m. | 17 minutes ago
Description :A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.0.0 - 23.6.13 Vaadin 24.0.0 - 24.9.20 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.21 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7 npm packages npm package Vulnerable versions Fixed version @vaadin/charts 23.0.0 - 23.6.4 >=23.6.5 @vaadin/charts 24.0.0 - 24.9.17 >=24.9.18 @vaadin/charts 24.10.0 - 24.10.4 >=24.10.5 @vaadin/charts 25.0.0 - 25.1.11 >=25.1.12 @vaadin/charts 25.2.0 - 25.2.8 >=25.2.9 @vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18 @vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5 @vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12 @vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...