🚨 CVE-2026-64897
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
🚨 CVE-2026-64900
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
🚨 CVE-2026-64901
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
🎖@cveNotify
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
🎖@cveNotify
🚨 CVE-2026-64902
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
🚨 CVE-2024-11831
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
🎖@cveNotify
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
🎖@cveNotify
🚨 CVE-2026-12001
A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is
embedded within a password file in the firmware image and may be recovered
through firmware analysis.
Successful
exploitation could result in unauthorized access to privileged functions on
affected devices.
🎖@cveNotify
A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is
embedded within a password file in the firmware image and may be recovered
through firmware analysis.
Successful
exploitation could result in unauthorized access to privileged functions on
affected devices.
🎖@cveNotify
TP-Link
Download for Archer C20 | TP-Link
TP Link - Download Center Detail
🚨 CVE-2026-18649
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.
🎖@cveNotify
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.
🎖@cveNotify
🚨 CVE-2026-17435
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files.
When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target.
An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated).
Note that the touch option is disabled by default.
🎖@cveNotify
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files.
When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target.
An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated).
Note that the touch option is disabled by default.
🎖@cveNotify
🚨 CVE-2026-18037
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
🎖@cveNotify
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
🎖@cveNotify
WPScan
Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
See details on Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication CVE 2026-18037. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-12971
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
🎖@cveNotify
The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.
🎖@cveNotify
WPScan
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
See details on LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature CVE 2026-12971. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13600
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
🎖@cveNotify
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed, an unauthenticated attacker who triggers the due task can receive the administrator's session cookie and gain administrator access without credentials.
🎖@cveNotify
WPScan
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
See details on AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron CVE 2026-13600. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14211
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.
🎖@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.
🎖@cveNotify
WPScan
Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR
See details on Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR CVE 2026-14211. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14860
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
🎖@cveNotify
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
🎖@cveNotify
WPScan
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
See details on Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery CVE 2026-14860. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14941
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
🎖@cveNotify
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin before 5.116.0 options, and disclose store configuration.
🎖@cveNotify
WPScan
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
See details on Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions CVE 2026-14941. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15237
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
🎖@cveNotify
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
🎖@cveNotify
WPScan
Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
See details on Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint CVE 2026-15237. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-15238
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
🎖@cveNotify
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
🎖@cveNotify
WPScan
Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
See details on Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR CVE 2026-15238. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16257
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
🎖@cveNotify
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been configured, allowing them to create arbitrary posts and pages and to disclose author account and taxonomy information.
🎖@cveNotify
WPScan
Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling
See details on Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling CVE 2026-16257. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16298
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
WPScan
FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
See details on FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset CVE 2026-16298. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16299
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
🎖@cveNotify
WPScan
Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
See details on Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset CVE 2026-16299. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16949
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🎖@cveNotify
WPScan
Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
See details on Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup CVE 2026-16949. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16985
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.
🎖@cveNotify
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the uploads directory and achieve remote code execution.
🎖@cveNotify
WPScan
Squeeze < 1.7.12 - Author+ Arbitrary File Upload
See details on Squeeze < 1.7.12 - Author+ Arbitrary File Upload CVE 2026-16985. View the latest Plugin Vulnerabilities on WPScan.