π¨ CVE-2026-48396
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
π@cveNotify
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
π@cveNotify
Adobe
Adobe Security Bulletin
Security Updates Available for Adobe Bridge | APSB26-89
π¨ CVE-2026-7769
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
π@cveNotify
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
π@cveNotify
Ibm
Security Bulletin: SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway (CVE-2026β¦
IBM Sterling B2B Integrator and IBM Sterling File Gateway have addressed vulnerability due to SQL injection.
π¨ CVE-2026-18072
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick β¦ plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function β registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request β reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account.
π@cveNotify
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick β¦ plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function β registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request β reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account.
π@cveNotify
π¨ CVE-2026-44747
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
π@cveNotify
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
π@cveNotify
π¨ CVE-2026-17501
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
π@cveNotify
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
π@cveNotify
GitHub
GitHub - ggml-org/llama.cpp: LLM inference in C/C++
LLM inference in C/C++. Contribute to ggml-org/llama.cpp development by creating an account on GitHub.
π¨ CVE-2026-11351
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.
π@cveNotify
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.
π@cveNotify
WPScan
ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure
See details on ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure CVE 2026-11351. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-11974
The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.
π@cveNotify
The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.
π@cveNotify
WPScan
Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Download
See details on Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Download CVE 2026-11974. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13423
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
π@cveNotify
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
π@cveNotify
WPScan
Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
See details on Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call CVE 2026-13423. View the latest Theme Vulnerabilities on WPScan.
π¨ CVE-2026-13605
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
π@cveNotify
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
π@cveNotify
WPScan
Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
See details on Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute CVE 2026-13605. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13690
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
π@cveNotify
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
π@cveNotify
WPScan
UsersWP < 1.2.67 - Two-Factor Authentication Bypass
See details on UsersWP < 1.2.67 - Two-Factor Authentication Bypass CVE 2026-13690. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-13692
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
π@cveNotify
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
π@cveNotify
WPScan
PayU CommercePro <= 3.8.9 - Unauthenticated Order Tampering
See details on PayU CommercePro <= 3.8.9 - Unauthenticated Order Tampering CVE 2026-13692. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14224
The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.
π@cveNotify
The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an appointment of their own can therefore reuse that nonce to overwrite the customer metadata (email, name, phone, description) of another user's appointment. Because the Easy Appointments WordPress plugin through 3.12.26 then treats that metadata as the appointment's contact data, a subsequent administrator status change with customer notifications enabled delivers the victim's appointment notification to the attacker-controlled email address.
π@cveNotify
WPScan
Easy Appointments <= 3.12.26 - Subscriber+ Cross-User Appointment Data Modification via IDOR
See details on Easy Appointments <= 3.12.26 - Subscriber+ Cross-User Appointment Data Modification via IDOR CVE 2026-14224. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14234
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting.
π@cveNotify
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting.
π@cveNotify
WPScan
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
See details on WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF CVE 2026-14234. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14300
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
π@cveNotify
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.
π@cveNotify
WPScan
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
See details on miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover CVE 2026-14300. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-63227
An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upload a SCORM package containing a PHP
webshell to a publicly accessible directory and execute arbitrary code on the
server.
π@cveNotify
An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upload a SCORM package containing a PHP
webshell to a publicly accessible directory and execute arbitrary code on the
server.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦
π¨ CVE-2026-63228
An unrestricted image upload vulnerability in
Koollab LMS allowed
an authenticated attacker to upload malicious content disguised as an image
file via the feedback mail registration endpoint, potentially enabling further
attacks on the server.
π@cveNotify
An unrestricted image upload vulnerability in
Koollab LMS allowed
an authenticated attacker to upload malicious content disguised as an image
file via the feedback mail registration endpoint, potentially enabling further
attacks on the server.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦
π¨ CVE-2026-63229
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable account takeover.
π@cveNotify
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable account takeover.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦
π¨ CVE-2026-63230
A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including personally identifiable information, credentials, and valid
JWT tokens that may enable account takeover, via the SCORM report endpoint.
π@cveNotify
A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including personally identifiable information, credentials, and valid
JWT tokens that may enable account takeover, via the SCORM report endpoint.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦
π¨ CVE-2026-63231
A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-face runs update endpoint to read the entire application database
and obtain valid JWT tokens for account takeover.
π@cveNotify
A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-face runs update endpoint to read the entire application database
and obtain valid JWT tokens for account takeover.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦
π¨ CVE-2026-63232
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
reinforcement endpoint, control data passed to unserialize(), write a webshell
to a publicly accessible location, and execute arbitrary code on the server.
π@cveNotify
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
reinforcement endpoint, control data passed to unserialize(), write a webshell
to a publicly accessible location, and execute arbitrary code on the server.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦
π¨ CVE-2026-63233
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall answer endpoint, control data passed to unserialize(), write a webshell
to a publicly accessible location, and execute arbitrary code on the server.
π@cveNotify
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall answer endpoint, control data passed to unserialize(), write a webshell
to a publicly accessible location, and execute arbitrary code on the server.
π@cveNotify
Cyber Security Agency of Singapore
Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass
Multiple vulnerabilities have been discovered in Koollab's Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the informerβ¦