๐จ CVE-2026-56063
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
๐@cveNotify
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress MailChimp Block Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-56066
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
๐@cveNotify
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
๐@cveNotify
Patchstack
Arbitrary File Deletion in WordPress ShortPixel Adaptive Images Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-56067
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
๐@cveNotify
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress JetSmartFilters Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-56069
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
๐@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Toolset Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-56070
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
๐@cveNotify
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Advance Product Search Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-56072
Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WoodMart Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-56773
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords.
๐@cveNotify
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords.
๐@cveNotify
GitHub
[sync] T4883 route CSV table imports through V2 by tea-artist ยท Pull Request #3285 ยท teableio/teable
๐ Automated sync from EE repository.
29 commit(s) synced since last sync.
Authors
Aries X caoxing9@gmail.com
Boris boris2code@outlook.com
Jun Lu hammond@teable.io
SkyHuang sky.huang.fe@gmail.com
U...
29 commit(s) synced since last sync.
Authors
Aries X caoxing9@gmail.com
Boris boris2code@outlook.com
Jun Lu hammond@teable.io
SkyHuang sky.huang.fe@gmail.com
U...
๐จ CVE-2026-57312
Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Everest Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57313
Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.
๐@cveNotify
Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress SureCart Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57314
Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress SureCart Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57315
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
๐@cveNotify
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
๐@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress Blocksy Companion Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57317
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57318
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
๐@cveNotify
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Site Reviews Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57319
Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress FOX Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57323
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Flash & HTML5 Video Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57324
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
๐@cveNotify
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress GIFT4U Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57325
Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress NanoMag Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.