๐จ CVE-2026-73379
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
๐@cveNotify
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
๐@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73380
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Popup by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73381
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Popup by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73382
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Site Reviews Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73383
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
๐@cveNotify
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
๐@cveNotify
Patchstack
Arbitrary File Download in WordPress CTX Feed Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73392
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
๐@cveNotify
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Super Store Finder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73393
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Subscribe2 Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73395
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
๐@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Booking calendar, Appointment Booking System Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73397
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
๐@cveNotify
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
๐@cveNotify
Patchstack
Deserialization of untrusted data in WordPress Youzify Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Piraeus Bank WooCommerce Payment Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73399
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Flutterwave WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73400
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
๐@cveNotify
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
๐@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress MasterStudy LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73426
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
๐@cveNotify
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
๐@cveNotify
GitHub
Fix stored XSS via data-trix-serialized-attributes sanitizer bypass (โฆ ยท basecamp/trix@3229c29
โฆH1 #3581911)
Strip `data-trix-serialized-attributes` in the DOMPurify `uponSanitizeAttribute`
hook before the `data-trix-*` force-keep logic runs.
This attribute is unique among `data-trix-*` at...
Strip `data-trix-serialized-attributes` in the DOMPurify `uponSanitizeAttribute`
hook before the `data-trix-*` force-keep logic runs.
This attribute is unique among `data-trix-*` at...
๐จ CVE-2026-73994
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Charitable Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73995
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
๐@cveNotify
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress User Registration Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73996
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
๐@cveNotify
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Masteriyo - LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73997
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
๐@cveNotify
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
๐@cveNotify
Patchstack
Denial of Service Attack in WordPress Starter Templates by Kadence WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74003
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
๐@cveNotify
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress RomethemeForm For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74004
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
๐@cveNotify
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Gravity Booster โ Styles & Layouts for Gravity Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74006
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
๐@cveNotify
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress WP Table Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.