๐จ CVE-2026-66633
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Fluent Forms Pro Add On Pack Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66634
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
๐@cveNotify
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Modal Survey Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66635
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
๐@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
๐@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Slider by 10Web Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66636
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Wise Chat Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66637
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Featured Video Plus Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66638
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Frontend Admin by DynamiApps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66639
Contributor Cross Site Scripting (XSS) in WPZOOM Forms โ Contact Form Plugin for Gutenberg <= 2.0.4 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in WPZOOM Forms โ Contact Form Plugin for Gutenberg <= 2.0.4 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WPZOOM Forms โ Contact Form Plugin for Gutenberg Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66640
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Login With Ajax Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66641
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Video Conferencing with Zoom Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66643
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Wufoo Shortcode Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66644
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Typing Effect Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66645
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Table Of Contents Block Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66646
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Tab Widget Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66651
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
๐@cveNotify
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress MultiVendorX Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66667
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Templately Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66679
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Appointment Hour Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-66793
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.
๐@cveNotify
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.
๐@cveNotify
Redhat
CVE-2026-66793 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-68565
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress GeoDirectory Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-68568
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Patchstack
Privilege Escalation in WordPress MasterStudy LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-68939
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.
๐@cveNotify
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.
๐@cveNotify
GitHub
Merge commit from fork ยท pyenv/pyenv@95df7db
Simple Python version management. Contribute to pyenv/pyenv development by creating an account on GitHub.
๐จ CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
๐@cveNotify
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
๐@cveNotify
GitHub
fix(backend): enforce ownership on user history and private User fielโฆ ยท hoppscotch/hoppscotch@9cc980b
โฆds (#6409)
* fix(backend): enforce ownership on user history and private User fields
* test: fix unit test cases
* fix(backend): gate private User field resolvers to their owner
* fix(backend)...
* fix(backend): enforce ownership on user history and private User fields
* test: fix unit test cases
* fix(backend): gate private User field resolvers to their owner
* fix(backend)...