๐จ CVE-2026-73367
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
๐@cveNotify
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
๐@cveNotify
Patchstack
Remote File Inclusion in WordPress Easy Google Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73375
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
๐@cveNotify
๐จ CVE-2026-73376
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Ultimate Maps by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73377
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Ultimate Maps by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73378
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Contact Form by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73379
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
๐@cveNotify
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
๐@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73380
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Popup by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73381
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Popup by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73382
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Site Reviews Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73383
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
๐@cveNotify
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
๐@cveNotify
Patchstack
Arbitrary File Download in WordPress CTX Feed Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73392
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
๐@cveNotify
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Super Store Finder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73393
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Subscribe2 Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73395
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
๐@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Booking calendar, Appointment Booking System Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73397
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
๐@cveNotify
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
๐@cveNotify
Patchstack
Deserialization of untrusted data in WordPress Youzify Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Piraeus Bank WooCommerce Payment Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73399
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Flutterwave WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73400
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
๐@cveNotify
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
๐@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress MasterStudy LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73426
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
๐@cveNotify
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
๐@cveNotify
GitHub
Fix stored XSS via data-trix-serialized-attributes sanitizer bypass (โฆ ยท basecamp/trix@3229c29
โฆH1 #3581911)
Strip `data-trix-serialized-attributes` in the DOMPurify `uponSanitizeAttribute`
hook before the `data-trix-*` force-keep logic runs.
This attribute is unique among `data-trix-*` at...
Strip `data-trix-serialized-attributes` in the DOMPurify `uponSanitizeAttribute`
hook before the `data-trix-*` force-keep logic runs.
This attribute is unique among `data-trix-*` at...
๐จ CVE-2026-73994
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Charitable Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73995
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
๐@cveNotify
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress User Registration Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.