🚨 CVE-2022-50960
WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.
🎖@cveNotify
WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.
🎖@cveNotify
WordPress.org
International Sms For Contact Form 7 Integration
Works with the Contact Form 7 plugin to send SMS notifications when somebody submits your contact form, using the API Configured By Site Admin
🚨 CVE-2022-50961
WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page.
🎖@cveNotify
WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when administrators or other authenticated users visit the plugin settings page.
🎖@cveNotify
WordPress.org
IP2Location Country Blocker
Blocks unwanted visitors from accessing your frontend (blog pages) or backend (admin area) by countries or proxy servers.
🚨 CVE-2022-50962
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
aiwithphp.org
Artificial intelligence and Machine Learning with PHP - Free Online Books
Artificial intelligence and Machine Learning with PHP - Free Online Books. These books explain the basics of AI and ML in a way that’s easy to understand.
🚨 CVE-2022-50963
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
aiwithphp.org
Artificial intelligence and Machine Learning with PHP - Free Online Books
Artificial intelligence and Machine Learning with PHP - Free Online Books. These books explain the basics of AI and ML in a way that’s easy to understand.
🚨 CVE-2022-50964
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
aiwithphp.org
Artificial intelligence and Machine Learning with PHP - Free Online Books
Artificial intelligence and Machine Learning with PHP - Free Online Books. These books explain the basics of AI and ML in a way that’s easy to understand.
🚨 CVE-2022-50965
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
🎖@cveNotify
aiwithphp.org
Artificial intelligence and Machine Learning with PHP - Free Online Books
Artificial intelligence and Machine Learning with PHP - Free Online Books. These books explain the basics of AI and ML in a way that’s easy to understand.
🚨 CVE-2026-4137
In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with group-writable permissions (0o770). These insecure permissions allow local attackers to tamper with model artifacts, such as cloudpickle-serialized Python objects, and achieve arbitrary code execution when the tampered artifacts are deserialized via `cloudpickle.load()`. This vulnerability is particularly critical in environments with shared NFS mounts, such as Databricks, where NFS is enabled by default. The issue is a continuation of the vulnerability class addressed in CVE-2025-10279, which was only partially fixed.
🎖@cveNotify
In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with group-writable permissions (0o770). These insecure permissions allow local attackers to tamper with model artifacts, such as cloudpickle-serialized Python objects, and achieve arbitrary code execution when the tampered artifacts are deserialized via `cloudpickle.load()`. This vulnerability is particularly critical in environments with shared NFS mounts, such as Databricks, where NFS is enabled by default. The issue is a continuation of the vulnerability class addressed in CVE-2025-10279, which was only partially fixed.
🎖@cveNotify
GitHub
Update directory permissions for Spark UDF accessibility (#20960) · mlflow/mlflow@1dcbb0c
Signed-off-by: Tomu Hirata <tomu.hirata@gmail.com>
🚨 CVE-2026-28733
in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
🎖@cveNotify
in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
🎖@cveNotify
Gitcode
security/zh/security-disclosure/2026/2026-05.md-代码预览-security:基于 OpenHarmony 生态的安全问题响应与处理项目 - AtomGit
security/zh/security-disclosure/2026/2026-05.md-代码预览-用户可通过此项目上报、跟踪和处理OpenHarmony安全问题,获取安全公告及漏洞奖励。项目核心功能包括漏洞感知、修复协助、安全问题处理、代码审核及漏洞奖励评审,保障社区安全响应效率。
🚨 CVE-2026-47307
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions.
This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.
🎖@cveNotify
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembly module containing deeply nested instructions.
This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.
🎖@cveNotify
GitHub
Improve error throwing by zherczeg · Pull Request #409 · Samsung/walrus
WebAssembly Lightweight RUntime. Contribute to Samsung/walrus development by creating an account on GitHub.
🚨 CVE-2026-32994
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply providing the target message ID. The endpoint fetches the message via Messages.findOneById(messageId) with no room access check (canAccessRoomIdAsync is never called), returning the complete IMessage object including message text, sender info, room ID, timestamps, and markdown content.
🎖@cveNotify
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply providing the target message ID. The endpoint fetches the message via Messages.findOneById(messageId) with no room access check (canAccessRoomIdAsync is never called), returning the complete IMessage object including message text, sender info, room ID, timestamps, and markdown content.
🎖@cveNotify
HackerOne
Rocket.Chat disclosed on HackerOne: IDOR:...
The `/api/v1/autotranslate.translateMessage` endpoint allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply...
🚨 CVE-2026-47308
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation.
This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.
🎖@cveNotify
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation.
This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.
🎖@cveNotify
GitHub
Improve error throwing by zherczeg · Pull Request #409 · Samsung/walrus
WebAssembly Lightweight RUntime. Contribute to Samsung/walrus development by creating an account on GitHub.
🚨 CVE-2025-15609
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.
🎖@cveNotify
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.
🎖@cveNotify
WPScan
Fortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure
See details on Fortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure CVE 2025-15609. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-47309
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
🚨 CVE-2026-47310
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
🚨 CVE-2026-47311
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
🚨 CVE-2026-47313
Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
🚨 CVE-2026-47314
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
🚨 CVE-2026-47315
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
🚨 CVE-2026-47316
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
🎖@cveNotify
GitHub
Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 · Pull Request #1565 · Samsung/escargot