๐จ CVE-2026-14221
The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.
๐@cveNotify
The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.
๐@cveNotify
WPScan
Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization
See details on Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization CVE 2026-14221. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14222
The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
๐@cveNotify
The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
๐@cveNotify
WPScan
Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization
See details on Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization CVE 2026-14222. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14223
The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
๐@cveNotify
The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
๐@cveNotify
WPScan
Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR
See details on Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR CVE 2026-14223. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14231
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
๐@cveNotify
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
๐@cveNotify
WPScan
LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
See details on LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts CVE 2026-14231. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14239
The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in administrator into storing JavaScript that then executes in the admin area (stored Cross-Site Scripting via CSRF).
๐@cveNotify
The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in administrator into storing JavaScript that then executes in the admin area (stored Cross-Site Scripting via CSRF).
๐@cveNotify
WPScan
Tourmaster < 5.4.8 - Stored XSS via CSRF
See details on Tourmaster < 5.4.8 - Stored XSS via CSRF CVE 2026-14239. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14318
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
๐@cveNotify
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor.
๐@cveNotify
WPScan
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
See details on GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings CVE 2026-14318. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-14602
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.
๐@cveNotify
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote API WordPress plugin through 0.2.
๐@cveNotify
WPScan
Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter
See details on Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter CVE 2026-14602. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15255
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
๐@cveNotify
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
๐@cveNotify
WPScan
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
See details on RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR CVE 2026-15255. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15257
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.
๐@cveNotify
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.
๐@cveNotify
WPScan
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification
See details on RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification CVE 2026-15257. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15382
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.
๐@cveNotify
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.
๐@cveNotify
WPScan
Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts
See details on Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts CVE 2026-15382. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16524
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
๐@cveNotify
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
๐@cveNotify
๐จ CVE-2026-16531
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
๐@cveNotify
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
๐@cveNotify
๐จ CVE-2026-56847
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
๐@cveNotify
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
๐@cveNotify
nodejs.org
Node.js โ Wednesday, July 29, 2026 Security Releases
Node.jsยฎ is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
๐จ CVE-2026-56850
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.
This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
๐@cveNotify
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.
This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
๐@cveNotify
nodejs.org
Node.js โ Wednesday, July 29, 2026 Security Releases
Node.jsยฎ is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
๐จ CVE-2026-58043
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
๐@cveNotify
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
๐@cveNotify
nodejs.org
Node.js โ Wednesday, July 29, 2026 Security Releases
Node.jsยฎ is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
๐จ CVE-2026-44092
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
๐@cveNotify
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
๐@cveNotify
Certvde
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
๐จ CVE-2026-44097
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
๐@cveNotify
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
๐@cveNotify
Certvde
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
๐จ CVE-2026-44102
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
๐@cveNotify
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
๐@cveNotify
Certvde
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
๐จ CVE-2026-44107
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
๐@cveNotify
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
๐@cveNotify
Certvde
Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers
๐จ CVE-2026-16970
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
๐@cveNotify
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
๐@cveNotify
GitHub
advisories/2026/SBA-ADV-20260128-04_DFIR-IRIS_Insufficient_Logout at public ยท sbaresearch/advisories
Security advisories by SBA Research. Contribute to sbaresearch/advisories development by creating an account on GitHub.
๐จ CVE-2026-17543
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
๐@cveNotify
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
๐@cveNotify
GitHub
SQL injection in ext-pgsql via E'...' backslash breakout
`php_pgsql_convert()` is used to convert and escape user-provided parameters in `pg_insert()`, `pg_update()`, `pg_select()`, and `pg_delete()`. It does so using `PQescapeStringConn()` and then wrap...