CVE tracker
393 subscribers
5.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-97031 - Reject malformed ECH outer extension references in crypto/tls

CVE ID :CVE-2026-97031
Published : Oct. 8, 2026, 11:17 p.m. | 3 hours, 6 minutes ago
Description :Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97032 - HTTP/2 server crash due to HPACK encoder race in net/http

CVE ID :CVE-2026-97032
Published : Oct. 8, 2026, 11:17 p.m. | 3 hours, 6 minutes ago
Description :HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107844 - Contao: Path traversal in the images controller

CVE ID :CVE-2026-107844
Published : Oct. 9, 2026, 8:17 p.m. | 2 hours, 10 minutes ago
Description :Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-107845 - Contao: Cross-site scripting in the comments bundle

CVE ID :CVE-2026-107845
Published : Oct. 9, 2026, 8:17 p.m. | 2 hours, 10 minutes ago
Description :Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-78797 - iStoreOS Remote Code Execution Vulnerability

CVE ID :CVE-2026-78797
Published : Oct. 9, 2026, 8:17 p.m. | 2 hours, 10 minutes ago
Description :An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-108267 - Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session

CVE ID :CVE-2026-108267
Published : Oct. 9, 2026, 9:11 p.m. | 1 hour, 15 minutes ago
Description :Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to the certificate public key and client nonce but not to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept a handshake terminated by the attacker as an attested enclave connection. This issue is fixed in privasys-v0.5.1-go1.26.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103755 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2026-103755
Published : Oct. 9, 2026, 11:16 p.m. | 3 hours, 12 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16681 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2026-16681
Published : Oct. 9, 2026, 11:16 p.m. | 3 hours, 12 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18524 - Rejected reason: This CVE ID has been rejected or

CVE ID :CVE-2026-18524
Published : Oct. 9, 2026, 11:16 p.m. | 3 hours, 12 minutes ago
Description :Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-22061 - CVE-2026-22061 Debug Log Information Disclosure Vulnerability in Trident

CVE ID :CVE-2026-22061
Published : Oct. 9, 2026, 11:16 p.m. | 3 hours, 12 minutes ago
Description :Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-108474 - JetBrains Exposed SQL Injection

CVE ID :CVE-2026-108474
Published : Oct. 10, 2026, 12:17 a.m. | 2 hours, 11 minutes ago
Description :In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97643 - GiveWP <= 4.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via givewp_campaign_grid Shortcode Attributes

CVE ID :CVE-2026-97643
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `givewp_campaign_grid` shortcode in versions up to, and including, 4.17.0 This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes (`filter_by`, `layout`, `sort_by`, `order_by`) in the CampaignGridShortcode::parseAttributes() function combined with the render template emitting `json_encode($attributes)` inside a single-quoted HTML attribute without esc_attr() — json_encode() does not escape single quotes by default, so a `'` in an attribute value breaks out of the enclosing attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93775 - Podlove Podcast Publisher <= 4.5.6 - Unauthenticated Stored Cross-Site Scripting via Auphonic Webhook

CVE ID :CVE-2026-93775
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14877 - Data Tables Generator by Supsystic <= 1.12.03 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table 'id' HTML Attribute

CVE ID :CVE-2026-14877
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103482 - Simple Newsletter Plugin <= 4.3.10 - Unauthenticated Stored Cross-Site Scripting via Subscriber Custom Field via Manage Preferences Form + Campaign Preview noptin_key Pivot

CVE ID :CVE-2026-103482
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103912 - JetFormBuilder <= 3.6.6 - Reflected DOM-Based Cross-Site Scripting via 'query_var' Dynamic Preset via data-jfb-macro / JFB_FIELD:: Macro Renderer

CVE ID :CVE-2026-103912
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on pages embedding a form that has a text field configured with a query_var Dynamic Preset and a data-jfb-macro or JFB_FIELD:: macro reference targeting that field, both of which are standard, documented plugin features.
Severity: 4.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14882 - Brizy <= 2.8.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'brizy-compiled-sections' Post Meta

CVE ID :CVE-2026-14882
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17025 - Graphene <= 2.9.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Fields

CVE ID :CVE-2026-17025
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14335 - Easy Digital Downloads <= 3.6.9 - Unauthenticated Stored Cross-Site Scripting via PayPal IPN Parameters

CVE ID :CVE-2026-14335
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12054 - Download Manager <= 3.3.57 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via 'REFERRER' Parameter

CVE ID :CVE-2026-12054
Published : Oct. 10, 2026, 5:31 a.m. | 58 minutes ago
Description :The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104752 - Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import

CVE ID :CVE-2026-104752
Published : Oct. 10, 2026, 6 a.m. | 29 minutes ago
Description :The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...