CVE-2026-105051 - Denuvo Anti-Tamper Hypervisor Detection Bypass
CVE ID :CVE-2026-105051
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
Severity: 1.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105051
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
Severity: 1.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84411 - MikroTik RouterOS Integer Underflow
CVE ID :CVE-2026-84411
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-84411
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73802 - Gitea act_runner Container Sandbox Escape Vulnerability
CVE ID :CVE-2026-73802
Published : Oct. 2, 2026, 11:18 p.m. | 2 hours, 32 minutes ago
Description :### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces and execute commands on the runner host as root. ### Details Source-to-sink path in act_runner: - `ContainerSpec.Options` accepts workflow YAML `container.options` - `RunContext.options()` appends workflow options to runner-level container options - Job container is created with `Privileged: rc.Config.Privileged` but also with `Options: rc.options(ctx)` - `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig - When privileged mode is disabled, only `copts.privileged` is forced false - `sanitizeConfig()` only filters `Binds` and `Mounts` - Preserved dangerous HostConfig fields: ```text Privileged=false PidMode=host IpcMode=host CapAdd=["ALL"] SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] ``` Attacker workflow YAML: ```yaml jobs: breakout: runs-on: ubuntu-latest container: image: ubuntu:22.04 options: >- --pid=host --ipc=host --cap-add=ALL --security-opt seccomp=unconfined --security-opt apparmor=unconfined steps: - name: host namespace marker run: | nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker" ``` ### Impact An attacker who can submit a workflow to a repository using a shared Docker-backed act_runner can: - Enter host PID, IPC, and mount namespaces - Execute arbitrary commands as root on the runner host - Access runner host secrets, deployment credentials, and environment variables - Pivot to adjacent jobs running on the same runner - Access internal build infrastructure reachable from the runner host Critical severity for shared runners where untrusted users can trigger workflows. High severity for single-tenant runners with privileged mode explicitly disabled as a security control. ### Fix Direction Treat `container.options` as untrusted input. Reject or strip when privileged mode is disabled: - Host namespaces: `--pid=host`, `--ipc=host`, `--uts=host`, `--network=host` - Capability expansion: `--cap-add ALL`, `--cap-add SYS_ADMIN` - Security overrides: `--security-opt seccomp=unconfined`, `--security-opt apparmor=unconfined` - Device access: `--device`, `--device-cgroup-rule` - Volume inheritance: `--volumes-from` - Runtime controls: `--runtime`, `--cgroup-parent`
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-73802
Published : Oct. 2, 2026, 11:18 p.m. | 2 hours, 32 minutes ago
Description :### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces and execute commands on the runner host as root. ### Details Source-to-sink path in act_runner: - `ContainerSpec.Options` accepts workflow YAML `container.options` - `RunContext.options()` appends workflow options to runner-level container options - Job container is created with `Privileged: rc.Config.Privileged` but also with `Options: rc.options(ctx)` - `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig - When privileged mode is disabled, only `copts.privileged` is forced false - `sanitizeConfig()` only filters `Binds` and `Mounts` - Preserved dangerous HostConfig fields: ```text Privileged=false PidMode=host IpcMode=host CapAdd=["ALL"] SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] ``` Attacker workflow YAML: ```yaml jobs: breakout: runs-on: ubuntu-latest container: image: ubuntu:22.04 options: >- --pid=host --ipc=host --cap-add=ALL --security-opt seccomp=unconfined --security-opt apparmor=unconfined steps: - name: host namespace marker run: | nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker" ``` ### Impact An attacker who can submit a workflow to a repository using a shared Docker-backed act_runner can: - Enter host PID, IPC, and mount namespaces - Execute arbitrary commands as root on the runner host - Access runner host secrets, deployment credentials, and environment variables - Pivot to adjacent jobs running on the same runner - Access internal build infrastructure reachable from the runner host Critical severity for shared runners where untrusted users can trigger workflows. High severity for single-tenant runners with privileged mode explicitly disabled as a security control. ### Fix Direction Treat `container.options` as untrusted input. Reject or strip when privileged mode is disabled: - Host namespaces: `--pid=host`, `--ipc=host`, `--uts=host`, `--network=host` - Capability expansion: `--cap-add ALL`, `--cap-add SYS_ADMIN` - Security overrides: `--security-opt seccomp=unconfined`, `--security-opt apparmor=unconfined` - Device access: `--device`, `--device-cgroup-rule` - Volume inheritance: `--volumes-from` - Runtime controls: `--runtime`, `--cgroup-parent`
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104433 - Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString
CVE ID :CVE-2026-104433
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104433
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104474 - OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
CVE ID :CVE-2026-104474
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104474
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104475 - IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload
CVE ID :CVE-2026-104475
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104475
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104476 - Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive
CVE ID :CVE-2026-104476
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104476
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104477 - Showdown through 2.1.0 XSS via unescaped quote in href and src attributes
CVE ID :CVE-2026-104477
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104477
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104478 - Formwork before 2.3.13 Path Traversal via BackupController Download and Delete
CVE ID :CVE-2026-104478
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104478
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104479 - Shopclass before 6.2.0 Stored XSS via Listing Description Field
CVE ID :CVE-2026-104479
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-104479
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105029 - UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
CVE ID :CVE-2026-105029
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105029
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105030 - Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
CVE ID :CVE-2026-105030
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105030
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105083 - ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE
CVE ID :CVE-2026-105083
Published : Oct. 3, 2026, 1:11 a.m. | 39 minutes ago
Description :ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
Severity: 3.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105083
Published : Oct. 3, 2026, 1:11 a.m. | 39 minutes ago
Description :ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
Severity: 3.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105080 - ConvertX Arbitrary Code Execution
CVE ID :CVE-2026-105080
Published : Oct. 3, 2026, 1:17 a.m. | 33 minutes ago
Description :In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105080
Published : Oct. 3, 2026, 1:17 a.m. | 33 minutes ago
Description :In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79113 - OpenAPV Heap-Based Buffer Overflow
CVE ID :CVE-2026-79113
Published : Oct. 3, 2026, 1:17 a.m. | 32 minutes ago
Description :OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-79113
Published : Oct. 3, 2026, 1:17 a.m. | 32 minutes ago
Description :OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92551 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter
CVE ID :CVE-2026-92551
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92551
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92727 - EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute
CVE ID :CVE-2026-92727
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The slidesShow block attribute is interpolated into an unquoted data-carousel-options HTML attribute, allowing a payload containing spaces to break out of the attribute and inject additional DOM attributes such as onfocus event handlers onto the wrapper element.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92727
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The slidesShow block attribute is interpolated into an unquoted data-carousel-options HTML attribute, allowing a payload containing spaces to break out of the attribute and inject additional DOM attributes such as onfocus event handlers onto the wrapper element.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92826 - EWWW Image Optimizer <= 8.7.7 - Reflected Cross-Site Scripting via REQUEST_URI Parameter Key
CVE ID :CVE-2026-92826
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires that the enable_help option is active, as the vulnerable HelpScout Beacon script block is only emitted when that setting is enabled.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92826
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires that the enable_help option is active, as the vulnerable HelpScout Beacon script block is only emitted when that setting is enabled.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92977 - Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via Comment
CVE ID :CVE-2026-92977
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress's comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin's page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92977
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress's comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin's page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97644 - Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test
CVE ID :CVE-2026-97644
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97644
Published : Oct. 3, 2026, 4:18 a.m. | 1 hour, 32 minutes ago
Description :The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — including the security-bearing `user_id` column — into the upsert path of `Contacts_DB::add()`, which bypasses the ownership guard that `Contacts_DB::update()` enforces, allowing an attacker to rebind any existing contact record to an arbitrary WordPress user ID. This makes it possible for authenticated attackers with Sales Representative-level access and above to upsert their own contact row to point to an Administrator's user ID, then invoke the v4 email-test endpoint (`POST /gh/v4/emails/test`) — also accessible to the Sales Representative role via the `send_emails` capability — to generate an `{auto_login_url}` one-time permissions key bound to the rebound contact, and consume that link to call `wp_set_auth_cookie()` and gain a fully authenticated session as the WordPress Administrator.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11399 - Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter
CVE ID :CVE-2026-11399
Published : Oct. 3, 2026, 5:29 a.m. | 21 minutes ago
Description :The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11399
Published : Oct. 3, 2026, 5:29 a.m. | 21 minutes ago
Description :The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...