π¨ CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
π@cveNotify
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
π@cveNotify
GitLab
CVE reservation request for GlassFish project report #445: Critical CSRF + SSRF in admingui DownloadServlet leaks admin gfresttokenβ¦
CVE Reservation Request For the
π¨ CVE-2026-64993
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
π@cveNotify
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
π@cveNotify
π¨ CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
π@cveNotify
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
π@cveNotify
π¨ CVE-2026-15246
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.
π@cveNotify
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.
π@cveNotify
WPScan
RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
See details on RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass CVE 2026-15246. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - LeeSinLiang/godot-mcp: A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot gameβ¦
A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot game engine. - LeeSinLiang/godot-mcp
π¨ CVE-2026-19045
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - NocteDefensor/LudusMCP
Contribute to NocteDefensor/LudusMCP development by creating an account on GitHub.
π¨ CVE-2026-25403
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Ultimate Store Kit Elementor Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress Kadence WooCommerce Email Designer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28082
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Ajax Search Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28140
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
π@cveNotify
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress JetFormBuilder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress NextGEN Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28143
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Forminator Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28146
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
π@cveNotify
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
π@cveNotify
Patchstack
Arbitrary File Download in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28172
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Tracking Code Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup Maker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28178
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Powerkit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28179
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
π@cveNotify
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress FiboSearch Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Mercado Pago payments for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28183
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
π@cveNotify
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress PublishPress Capabilities Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.