๐จ CVE-2026-16524
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
๐@cveNotify
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
๐@cveNotify
Redhat
CVE-2026-16524 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-16526
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
๐@cveNotify
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
๐@cveNotify
Redhat
CVE-2026-16526 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-16527
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
๐@cveNotify
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
๐@cveNotify
Redhat
CVE-2026-16527 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-16529
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
๐@cveNotify
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
๐@cveNotify
Redhat
CVE-2026-16529 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-14817
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.
๐@cveNotify
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.
๐@cveNotify
WPScan
Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes
See details on Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes CVE 2026-14817. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16042
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
๐@cveNotify
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
๐@cveNotify
WPScan
LWS Optimize < 3.4 - Subscriber+ Cache Deletion
See details on LWS Optimize < 3.4 - Subscriber+ Cache Deletion CVE 2026-16042. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16062
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.
๐@cveNotify
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 itself, but if one is present via another installed Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 or , this could lead to actions such as arbitrary file deletion, sensitive data retrieval, or remote code execution. This is an incomplete fix of the Event Booking Manager for WooCommerce WordPress plugin before 5.3.7's earlier object-injection advisories.
๐@cveNotify
WPScan
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
See details on Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content CVE 2026-16062. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16291
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.
๐@cveNotify
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.
๐@cveNotify
WPScan
ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
See details on ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR CVE 2026-16291. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16292
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.
๐@cveNotify
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.
๐@cveNotify
WPScan
Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
See details on Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF CVE 2026-16292. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2025-15672
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.
๐@cveNotify
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.
๐@cveNotify
WPScan
Chama < 1.0.13 - Unauthenticated PHP Object Injection
See details on Chama < 1.0.13 - Unauthenticated PHP Object Injection CVE 2025-15672. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2025-15673
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
๐@cveNotify
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.
๐@cveNotify
WPScan
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
See details on Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read CVE 2025-15673. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15231
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
๐@cveNotify
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
๐@cveNotify
WPScan
TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
See details on TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR CVE 2026-15231. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16057
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
๐@cveNotify
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
๐@cveNotify
WPScan
Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
See details on Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library CVE 2026-16057. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16250
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
๐@cveNotify
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
๐@cveNotify
WPScan
Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
See details on Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload CVE 2026-16250. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16274
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site โ including drafts, pending, and private posts owned by other users โ regardless of ownership.
๐@cveNotify
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site โ including drafts, pending, and private posts owned by other users โ regardless of ownership.
๐@cveNotify
WPScan
Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
See details on Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts CVE 2026-16274. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-16276
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.
๐@cveNotify
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.
๐@cveNotify
WPScan
Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
See details on Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search CVE 2026-16276. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-18616
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
๐@cveNotify
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
๐@cveNotify
GitHub
iot_vul/GL-iNet/MT3000/4.4.5/wg_set_peer_rce/CVE.md at main ยท StrTzz123/iot_vul
Contribute to StrTzz123/iot_vul development by creating an account on GitHub.
๐จ CVE-2026-67599
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webconfig user, and due to extensive NOPASSWD sudo privileges granted to that user by default, immediately escalate to root.
๐@cveNotify
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webconfig user, and due to extensive NOPASSWD sudo privileges granted to that user by default, immediately escalate to root.
๐@cveNotify
Clearos
ClearOS - Secure Linux Server, Network & Gateway Operating System
Linux-based server and gateway platform with security, virtualization, application marketplace, and business IT management tools.
๐จ CVE-2026-69198
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.
๐@cveNotify
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.
๐@cveNotify
GitHub
Merge commit from fork ยท beaugunderson/ip-address@488fe9b
Every special-use classifier was built on isInSubnet, which short-circuits to
false when the receiver's prefix is shorter than the reference range's. That
prefix comes from the CIDR...
false when the receiver's prefix is shorter than the reference range's. That
prefix comes from the CIDR...
๐จ CVE-2026-18645
A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin Content Endpoint. Performing a manipulation of the argument oldfile results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin Content Endpoint. Performing a manipulation of the argument oldfile results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
GitHub
danpros htmly v3.1.1 /system/admin/admin.php Arbitrary File Move via rename() (CWE-22) ยท Issue #6 ยท orionyan520/cve_report
danpros htmly v3.1.1 /system/admin/admin.php Arbitrary File Move via rename() (CWE-22) NAME OF AFFECTED PRODUCT(S) htmly โ Databaseless Blogging Platform (Flat-File CMS) Vendor Homepage https://www...
๐จ CVE-2026-48113
Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5.
๐@cveNotify
Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5.
๐@cveNotify
GitHub
Enforce auth ACL on tunnel channels ยท jpillora/chisel@44310b6
Previously, authfile ACL restrictions were only checked during the
initial config handshake. This adds ACL enforcement at the tunnel
layer when processing SSH channel requests, ensuring that each
o...
initial config handshake. This adds ACL enforcement at the tunnel
layer when processing SSH channel requests, ensuring that each
o...