🚨 CVE-2026-28169
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress YITH WooCommerce Zoom Magnifier Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup Maker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
🎖@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
🎖@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Mercado Pago payments for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-53975
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
🎖@cveNotify
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
🎖@cveNotify
GitHub
GitHub - openchamber/openchamber: Agentic Development Environment based on OpenCode AI agent
Agentic Development Environment based on OpenCode AI agent - openchamber/openchamber
🚨 CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress EmbedPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61964
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress BOX NOW Delivery Croatia Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65508
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
🎖@cveNotify
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65515
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AffiliateWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65542
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
🎖@cveNotify
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
🎖@cveNotify
Patchstack
Broken Authentication in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65544
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65554
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
🎖@cveNotify
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress AnsPress – Question and answer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65559
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
🎖@cveNotify
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress Order Delivery Date for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-65571
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
🎖@cveNotify
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
🎖@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.