🚨 CVE-2026-59559
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65433
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
🎖@cveNotify
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65435
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Thrive Leads Version Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65557
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
🎖@cveNotify
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Abandoned Cart Lite for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65558
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
🎖@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress AffiliateX Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65561
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WordPress Social Login and Register Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65563
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
🎖@cveNotify
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Orbit Fox by ThemeIsle Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65564
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress MapPress Maps for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65567
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
🎖@cveNotify
🚨 CVE-2026-65568
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
🎖@cveNotify
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Visual Composer Website Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66050
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login.
🎖@cveNotify
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login.
🎖@cveNotify
GitHub
GitHub - cduram/NotCVE-2026-0009
Contribute to cduram/NotCVE-2026-0009 development by creating an account on GitHub.
🚨 CVE-2026-66428
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress WP Google Review Slider Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66433
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Location Weather Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66434
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
🎖@cveNotify
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66437
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
🎖@cveNotify
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
🎖@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Feedzy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66438
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Exclusive Addons Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.