π¨ CVE-2026-65474
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
π@cveNotify
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65487
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
π@cveNotify
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Photography Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65490
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
π@cveNotify
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Create by Mediavine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65496
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
π@cveNotify
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Complianz Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65499
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
π@cveNotify
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress PeproDev Ultimate Invoice Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65503
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ultimate Store Kit Elementor Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65514
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Appointment Hour Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65519
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
π@cveNotify
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Photo Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65524
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
π@cveNotify
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Avada Custom Branding Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65527
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress LIQUID SPEECH BALLOON Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65530
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
π@cveNotify
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress TemplateSpare Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65533
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Smart SEO Tool Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65539
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Kwayy HTML Sitemap Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-15037
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
π@cveNotify
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
π@cveNotify
π¨ CVE-2026-65906
In JetBrains TeamCity before 2026.1.2, 2025.11.6 Ρode execution via Kotlin DSL sandbox escape was possible
π@cveNotify
In JetBrains TeamCity before 2026.1.2, 2025.11.6 Ρode execution via Kotlin DSL sandbox escape was possible
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65907
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
π@cveNotify
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65908
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
π@cveNotify
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.