🚨 CVE-2026-61986
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Contest Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66596
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Newsletter Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66613
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
🎖@cveNotify
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
🎖@cveNotify
Patchstack
Remote Code Execution (RCE) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-67363
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.
🎖@cveNotify
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.
🎖@cveNotify
Balbooa
Balbooa — Joomla Extensions for Professionals
Bring up your Joomla website with premium extensions. With Balbooa extensions, Joomla can do more than you think!
🚨 CVE-2026-67364
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.
🎖@cveNotify
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.
🎖@cveNotify
Balbooa
Balbooa — Joomla Extensions for Professionals
Bring up your Joomla website with premium extensions. With Balbooa extensions, Joomla can do more than you think!
🚨 CVE-2026-73185
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
🎖@cveNotify
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress NGG Smart Image Search Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73354
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress SimplyRETS Real Estate IDX Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73363
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Taxi Booking Manager for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73364
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
🎖@cveNotify
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
🎖@cveNotify
🚨 CVE-2026-73384
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Pay with Contact Form 7 Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73385
Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Outranking Plugin Options Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73386
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
🎖@cveNotify
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress Track Geolocation Of Users Using Contact Form 7 Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-73390
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
🎖@cveNotify
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress Total Donations Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.