π¨ CVE-2026-16574
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
π@cveNotify
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.
π@cveNotify
WPScan
Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
See details on Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint CVE 2026-16574. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16589
The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
π@cveNotify
The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
π@cveNotify
WPScan
WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
See details on WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter CVE 2026-16589. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16608
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
π@cveNotify
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
π@cveNotify
WPScan
Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
See details on Download Monitor < 5.2.6 - Unauthenticated Download Log Injection CVE 2026-16608. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16948
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.
π@cveNotify
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.
π@cveNotify
WPScan
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
See details on Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure CVE 2026-16948. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16953
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.
π@cveNotify
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.
π@cveNotify
WPScan
AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
See details on AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie CVE 2026-16953. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16955
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.
π@cveNotify
The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.
π@cveNotify
WPScan
AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
See details on AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription CVE 2026-16955. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16957
The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.
π@cveNotify
The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.
π@cveNotify
WPScan
Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure
See details on Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure CVE 2026-16957. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16965
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
π@cveNotify
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
π@cveNotify
WPScan
Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status
See details on Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status CVE 2026-16965. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-16992
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
π@cveNotify
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
π@cveNotify
WPScan
Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
See details on Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication CVE 2026-16992. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17011
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
π@cveNotify
The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
π@cveNotify
WPScan
Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection
See details on Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection CVE 2026-17011. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17014
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
π@cveNotify
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
π@cveNotify
WPScan
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips
See details on WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips CVE 2026-17014. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17044
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
π@cveNotify
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
π@cveNotify
WPScan
WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
See details on WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid CVE 2026-17044. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-72898
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
π@cveNotify
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
π@cveNotify
GitHub
SQL injection using an unauthenticated endpoint leading to admin access
## Summary
This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access ...
This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access ...
π¨ CVE-2026-18950
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system.
π@cveNotify
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system.
π@cveNotify
π¨ CVE-2026-17061
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
π@cveNotify
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
π@cveNotify
Dassault Systèmes
CVE-2026-17061 - Dassault Systèmes
Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026
π¨ CVE-2026-17535
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images.
Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.
If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
π@cveNotify
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images.
Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.
If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
π@cveNotify
docs.velociraptor.app
Dead Disk Analysis
{{% notice tip %}}
π¨ CVE-2026-18636
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.
π@cveNotify
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.
π@cveNotify
π¨ CVE-2026-18860
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.
π@cveNotify
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.
π@cveNotify
π¨ CVE-2026-11733
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
π@cveNotify
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
π@cveNotify
NETGEAR
RAX41 | Nighthawk AX5 5-Stream AX3600 WiFi Router
Find setup help, user guides, product information, firmware, and troubleshooting for your Nighthawk RAX41 on our official NETGEAR Support site today.
π¨ CVE-2026-11734
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
π@cveNotify
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
π@cveNotify
NETGEAR
MR70 | Nighthawk Mesh WiFi 6 Router
Find setup help, user guides, product information, firmware, and troubleshooting for your Nighthawk MR70 router on our official NETGEAR Support site today.
π¨ CVE-2026-11737
Insufficient input validation vulnerability in the listed
NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality.
π@cveNotify
Insufficient input validation vulnerability in the listed
NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality.
π@cveNotify
NETGEAR
RAX20 | 4-Stream AX1800 WiFi 6 Router
Find setup help, user guides, product information, firmware, and troubleshooting for your RAX20 on our official NETGEAR Support site today.