π¨ CVE-2026-73352
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
π@cveNotify
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
π@cveNotify
π¨ CVE-2026-73360
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Chaty Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73367
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
π@cveNotify
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
π@cveNotify
Patchstack
Remote File Inclusion in WordPress Easy Google Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73377
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
π@cveNotify
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Ultimate Maps by Supsystic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73379
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
π@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73382
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Site Reviews Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73392
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
π@cveNotify
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Super Store Finder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73396
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
π@cveNotify
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
π@cveNotify
Patchstack
Broken Authentication in WordPress MWB HubSpot for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73398
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
π@cveNotify
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
π@cveNotify
Patchstack
Broken Authentication in WordPress Piraeus Bank WooCommerce Payment Gateway Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73404
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
π@cveNotify
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress MasterStudy LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-73995
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
π@cveNotify
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
π@cveNotify
Patchstack
Broken Authentication in WordPress User Registration Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-74003
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
π@cveNotify
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress RomethemeForm For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-74006
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
π@cveNotify
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress WP Table Builder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-74009
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Razorpay for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-12564
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
π@cveNotify
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.
π@cveNotify
Redhat
CVE-2026-12564 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-49221
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access digital assets linked to another Vendor's products. The admin/controller/product/digital-asset.php and admin/controller/product/digital-assets.php controllers and the admin/sql/sqlite/digital_asset.sql data queries use a caller-controlled digital_asset_id without consistently enforcing the current admin_id ownership boundary. An attacker can list assets, read asset names and file metadata, edit asset metadata, or delete asset records, which can disclose private product metadata, corrupt resource links, and cause data loss. This issue is fixed in version 1.0.8.4.
π@cveNotify
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access digital assets linked to another Vendor's products. The admin/controller/product/digital-asset.php and admin/controller/product/digital-assets.php controllers and the admin/sql/sqlite/digital_asset.sql data queries use a caller-controlled digital_asset_id without consistently enforcing the current admin_id ownership boundary. An attacker can list assets, read asset names and file metadata, edit asset metadata, or delete asset records, which can disclose private product metadata, corrupt resource links, and cause data loss. This issue is fixed in version 1.0.8.4.
π@cveNotify
GitHub
Added edit_other_product capability check for digital assets to allow⦠· givanz/Vvveb@0463ae6
β¦ list, read, edit, or delete, reported by @Mitchell45
π¨ CVE-2026-71574
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
π@cveNotify
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
π@cveNotify
Joomla! Developer Networkβ’
Joomla! Developer Network
The Flexible Platform Empowering Website Creators
π¨ CVE-2026-72532
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
π@cveNotify
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
π@cveNotify
Joomla! Developer Networkβ’
Joomla! Developer Network
The Flexible Platform Empowering Website Creators
π¨ CVE-2026-73337
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
π@cveNotify
Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
π@cveNotify
Joomla! Developer Networkβ’
Joomla! Developer Network
The Flexible Platform Empowering Website Creators