๐จ CVE-2026-63226
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
๐@cveNotify
Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
๐@cveNotify
ใชใณใผใฐใซใผใไผๆฅญใปIRใตใคใ
่ๅผฑๆงใใจใฎๆ
ๅ ฑใชในใ | ใชใณใผใฐใซใผใ ไผๆฅญใปIR | RICOH
2022ๅนด10ๆ1ๆฅไปฅ้ใฏ่ๅผฑๆงๆ
ๅ ฑใๆฌใใผใธใซๆฒ่ผใใพใใใๅฎขๆงใซใจใฃใฆ้่ฆใจๅคๆญใใๅ ดๅใฏใๅพๆฅใจๅๆงใซใ้่ฆใชใ็ฅใใใใซใๆฒ่ผใใใใพใใ
๐จ CVE-2026-12082
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
๐@cveNotify
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
๐@cveNotify
WPScan
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
See details on Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) CVE 2026-12082. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14291
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
๐@cveNotify
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ships only in the premium build.
๐@cveNotify
WPScan
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
See details on Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa CVE 2026-14291. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-59676
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files,
This issue affects policycoreutils through 3.10.
๐@cveNotify
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files,
This issue affects policycoreutils through 3.10.
๐@cveNotify
๐จ CVE-2026-9066
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
๐@cveNotify
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
๐@cveNotify
WPScan
WP Compress < 7.10.04 - Reflected XSS via test_zone
See details on WP Compress < 7.10.04 - Reflected XSS via test_zone CVE 2026-9066. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-9577
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
๐@cveNotify
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.
๐@cveNotify
WPScan
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
See details on Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter CVE 2026-9577. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-59677
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
unconfined context
This issue affects policycoreutils through 3.10.
๐@cveNotify
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
unconfined context
This issue affects policycoreutils through 3.10.
๐@cveNotify
๐จ CVE-2026-59678
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.
This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
๐@cveNotify
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.
This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
๐@cveNotify
๐จ CVE-2026-16745
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
๐@cveNotify
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
๐@cveNotify
๐จ CVE-2026-24639
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
๐@cveNotify
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Photo Block Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27403
Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Hubbub Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57373
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
๐@cveNotify
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Funnel Kit Funnel Builder PRO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57428
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Sprout Clients Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
โค1
๐จ CVE-2026-57626
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0.
๐@cveNotify
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress MailPoet Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57716
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
๐@cveNotify
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
๐@cveNotify
Patchstack
Arbitrary File Deletion in WordPress Broadcast Live Video Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57785
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress ApusListing Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-57809
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AffiliateWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59517
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Easy Form Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59524
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Easy Digital Downloads Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-59541
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
๐@cveNotify
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
๐@cveNotify
Patchstack
Privilege Escalation in WordPress WP BASE Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.