๐จ CVE-2026-66440
Unauthenticated Cross Site Scripting (XSS) in WPIDE โ File Manager & Code Editor <= 3.5.7 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WPIDE โ File Manager & Code Editor <= 3.5.7 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WPIDE โ File Manager & Code Editor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66451
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
๐@cveNotify
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress WP Event SOlution Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66457
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Events Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66470
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
๐@cveNotify
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Frontend Admin by DynamiApps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66663
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Data Access Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66665
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
๐@cveNotify
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Type Hub Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66678
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
๐@cveNotify
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Advanced Custom Fields: Font Awesome Field Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66683
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Custom CSS and JavaScript Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66685
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Featured Video Plus Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66686
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Plugins Garbage Collector (Database Cleanup) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66694
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Thrive Architect Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66695
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
๐@cveNotify
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
๐@cveNotify
Patchstack
Path Traversal in WordPress W3 Total Cache Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66702
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Rank Math SEO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66703
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress MailOptin Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66706
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
๐@cveNotify
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Subscribe to Comments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66708
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Total Upkeep Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66709
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
๐@cveNotify
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
๐@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress CTX Feed Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66711
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
๐@cveNotify
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WooCommerce Multilingual & Multicurrency Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-67261
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
๐@cveNotify
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.
๐@cveNotify
๐จ CVE-2026-70637
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.
๐@cveNotify
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.
๐@cveNotify
GitHub
[SECURITY] LightFTP: concurrent fd close race โ worker_thread_cleanup vs transfer worker thread ยท Issue #75 ยท hfiref0x/LightFTP
Summary The per-connection control thread (ftp_client_thread) and the detached transfer worker thread (stor_thread / retr_thread / list_thread) share ftp_context fields โ specifically context->d...