๐จ CVE-2026-73393
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Subscribe2 Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73395
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
๐@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Booking calendar, Appointment Booking System Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73397
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
๐@cveNotify
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
๐@cveNotify
Patchstack
Deserialization of untrusted data in WordPress Youzify Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Piraeus Bank WooCommerce Payment Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73399
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Flutterwave WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73400
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
๐@cveNotify
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
๐@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress MasterStudy LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73426
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
๐@cveNotify
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.
๐@cveNotify
GitHub
Fix stored XSS via data-trix-serialized-attributes sanitizer bypass (โฆ ยท basecamp/trix@3229c29
โฆH1 #3581911)
Strip `data-trix-serialized-attributes` in the DOMPurify `uponSanitizeAttribute`
hook before the `data-trix-*` force-keep logic runs.
This attribute is unique among `data-trix-*` at...
Strip `data-trix-serialized-attributes` in the DOMPurify `uponSanitizeAttribute`
hook before the `data-trix-*` force-keep logic runs.
This attribute is unique among `data-trix-*` at...
๐จ CVE-2026-73994
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Charitable Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73995
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
๐@cveNotify
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress User Registration Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73996
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
๐@cveNotify
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Masteriyo - LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73997
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
๐@cveNotify
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
๐@cveNotify
Patchstack
Denial of Service Attack in WordPress Starter Templates by Kadence WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74003
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
๐@cveNotify
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress RomethemeForm For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74004
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
๐@cveNotify
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Gravity Booster โ Styles & Layouts for Gravity Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74006
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
๐@cveNotify
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress WP Table Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74007
Unauthenticated Sensitive Data Exposure in 3D FlipBook โ PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in 3D FlipBook โ PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress 3D FlipBook โ PDF Flipbook Viewer, Flipbook Image Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74008
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.
๐@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Shortcodes and extra features for Phlox theme Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-74009
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
๐@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Razorpay for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-75032
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.
๐@cveNotify
A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.
๐@cveNotify
Redhat
CVE-2026-75032 - Red Hat Customer Portal
CVE Details App