CVE Notify
19.5K subscribers
4 photos
232K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-48847
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

πŸŽ–@cveNotify
🚨 CVE-2026-48848
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

πŸŽ–@cveNotify
🚨 CVE-2026-48849
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

πŸŽ–@cveNotify
🚨 CVE-2026-24545
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects QR Redirector: from n/a through 2.0.3.

πŸŽ–@cveNotify
🚨 CVE-2026-24574
Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery.

This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.

πŸŽ–@cveNotify
🚨 CVE-2026-24597
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery.

This issue affects Organization chart: from n/a through 1.7.5.

πŸŽ–@cveNotify
🚨 CVE-2026-43827
Default configurations of Apache Shiro have a session fixation vulnerability.

This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.

Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue.

In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.

πŸŽ–@cveNotify
🚨 CVE-2026-44598
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.




This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue by encrypting the cookie.

After successful login, Jakarta EE integration module uses shiroSavedRequest cookie to redirect to a particular web page after login.
This cookie was not validated, and can be forged to send a HTTP GET request from the server itself to an arbitrary URL from the cookie.

πŸŽ–@cveNotify
🚨 CVE-2026-48589
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module.
This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

πŸŽ–@cveNotify
🚨 CVE-2026-48850
PuTTY 0.72 before 0.84 has a double free in RSA KEX.

πŸŽ–@cveNotify
🚨 CVE-2026-48851
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

πŸŽ–@cveNotify
🚨 CVE-2026-48852
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

πŸŽ–@cveNotify
🚨 CVE-2025-62745
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.

This issue affects Team Showcase: from n/a through 1.22.28.

πŸŽ–@cveNotify
🚨 CVE-2026-24527
Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.

πŸŽ–@cveNotify
🚨 CVE-2026-24554
Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery.

This issue affects WPSubscription: from n/a through 1.9.1.

πŸŽ–@cveNotify
🚨 CVE-2026-24582
Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects FlexTable: from n/a through 3.24.0.

πŸŽ–@cveNotify
🚨 CVE-2026-24586
Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Newses: from n/a through 2.0.0.77.

πŸŽ–@cveNotify
🚨 CVE-2026-24592
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.

πŸŽ–@cveNotify
🚨 CVE-2026-27346
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects B2BKing: from n/a before 5.2.10.

πŸŽ–@cveNotify
🚨 CVE-2026-27357
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects WP Search Analytics: from n/a before 1.5.0.

πŸŽ–@cveNotify
🚨 CVE-2026-24937
Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection.

This issue affects Broadcast Live Video: from n/a before 7.1.3.

πŸŽ–@cveNotify