๐จ CVE-2025-62314
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2025-62315
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2025-62318
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2026-19716
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
๐@cveNotify
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
๐@cveNotify
GitHub
fix: patch username XSS and multipart DoS CVEs (v1.1.1) ยท ccyl13/Pentestify@714e05e
Username field was reflected into an inline onclick handler. escapeHTML()
protects HTML text context, but the browser HTML-decodes attribute values
before the JS engine runs them, so '...
protects HTML text context, but the browser HTML-decodes attribute values
before the JS engine runs them, so '...
๐จ CVE-2026-21832
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2026-27345
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Taxi Booking Manager for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27535
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
๐@cveNotify
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Solace Extra Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27536
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress MailChimp Subscribe Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27537
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27538
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
๐@cveNotify
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress WP Directory Kit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27539
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Welcart e-Commerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27543
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
๐@cveNotify
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
๐@cveNotify
Patchstack
Privilege Escalation in WordPress MStore API Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27544
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
๐@cveNotify
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
๐@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress QA Analytics Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28001
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
๐@cveNotify
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress WP Directory Kit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28002
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection.
This issue affects Booktics: from n/a through 1.0.22.
๐@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection.
This issue affects Booktics: from n/a through 1.0.22.
๐@cveNotify
Patchstack
SQL Injection in WordPress Booktics Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28003
Unauthenticated Cross Site Scripting (XSS) in Maspik โ Spam blacklist <= 2.9.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Maspik โ Spam blacklist <= 2.9.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Maspik โ Spam blacklist Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28004
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Business Directory Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28008
Unauthenticated Broken Authentication in OAuth Single Sign On โ SSO (OAuth Client) <= 7.0.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in OAuth Single Sign On โ SSO (OAuth Client) <= 7.0.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress OAuth Single Sign On โ SSO (OAuth Client) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28142
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
๐@cveNotify
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Web Directory Free Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28148
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
๐@cveNotify
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
๐@cveNotify
Patchstack
Bypass Vulnerability in WordPress Headless Single Sign On Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.