π¨ CVE-2026-66688
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ultimate Addons for Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66690
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress GiveWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66692
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : MΓ©thodes de livraison pour WooCommerce <= 2.10.0 versions.
π@cveNotify
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : MΓ©thodes de livraison pour WooCommerce <= 2.10.0 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Colissimo Officiel : MΓ©thodes de livraison pour WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66694
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Thrive Architect Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66695
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
π@cveNotify
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
π@cveNotify
Patchstack
Path Traversal in WordPress W3 Total Cache Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66696
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
π@cveNotify
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Gutenberg Blocks by Kadence Blocks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66702
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Rank Math SEO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66703
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress MailOptin Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66705
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Facebook for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66706
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
π@cveNotify
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Subscribe to Comments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66707
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Facebook for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66708
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
π@cveNotify
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Total Upkeep Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66709
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
π@cveNotify
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
π@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress CTX Feed Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66711
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
π@cveNotify
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WooCommerce Multilingual & Multicurrency Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-66712
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
π@cveNotify
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Simple Membership Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-67261
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
π@cveNotify
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
π@cveNotify
π¨ CVE-2026-70637
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.
π@cveNotify
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.
π@cveNotify
GitHub
[SECURITY] LightFTP: concurrent fd close race β worker_thread_cleanup vs transfer worker thread Β· Issue #75 Β· hfiref0x/LightFTP
Summary The per-connection control thread (ftp_client_thread) and the detached transfer worker thread (stor_thread / retr_thread / list_thread) share ftp_context fields β specifically context->d...
π¨ CVE-2026-70646
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing.
π@cveNotify
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing.
π@cveNotify
GitHub
fix: validate HMAC before parsing update body Β· vovchic17/aiosend@db20f0a
synchronous & asynchronous Crypto Pay API client. Contribute to vovchic17/aiosend development by creating an account on GitHub.
π¨ CVE-2026-57585
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.
π@cveNotify
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.
π@cveNotify
GitHub
Merge commit from fork Β· msgpack/msgpack-python@2c56ddb
* fix Unpacker crash after unpack failure.
* fixup
* fixup