๐จ CVE-2026-15049
The Depicter โ Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
๐@cveNotify
The Depicter โ Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
๐@cveNotify
WPScan
Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
See details on Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import CVE 2026-15049. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-17153
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access โ including Contributors โ making the absent upload_files check the sole barrier to exploitation.
๐@cveNotify
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to upload images to the WordPress media library, bypassing the upload_files capability restriction that Contributors are normally subject to, as authenticated attackers with Contributor-level access or above can satisfy the endpoint's nonce and permission checks. The sg_ai_studio_gutenberg_nonce required by the endpoint is emitted to any user with block editor access โ including Contributors โ making the absent upload_files check the sole barrier to exploitation.
๐@cveNotify
๐จ CVE-2026-19615
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
๐@cveNotify
The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users with a role the site owner granted upload access to store a file containing JavaScript which then executes in the browser of anyone who opens it.
๐@cveNotify
WPScan
Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC
See details on Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC CVE 2026-19615. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19697
The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
๐@cveNotify
The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file upload capability, such as Author, to upload a malicious SVG and perform Stored Cross-Site Scripting attacks against any user opening it, including administrators.
๐@cveNotify
WPScan
GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload
See details on GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload CVE 2026-19697. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19699
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
๐@cveNotify
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.
๐@cveNotify
WPScan
GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
See details on GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure CVE 2026-19699. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-73542
Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
๐@cveNotify
Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
๐@cveNotify
jvn.jp
JVNVU#91609598: Multiple SEIKO EPSON printers and scanners keep already revoked root certificates
Japan Vulnerability Notes
๐จ CVE-2026-74992
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.
๐@cveNotify
The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not remove all unwanted files after extracting them, allowing such users to upload arbitrary files to a web accessible directory, leading to Stored XSS as well as RCE on some server configurations.
๐@cveNotify
WPScan
Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload
See details on Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload CVE 2026-74992. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-75860
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
๐@cveNotify
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
๐@cveNotify
WPScan
JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update
See details on JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update CVE 2026-75860. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-75963
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
๐@cveNotify
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
๐@cveNotify
๐ฅ1
๐จ CVE-2025-14602
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
๐@cveNotify
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
๐@cveNotify
GitHub
Advisories/KLSA-00294-Weak-File-Name-Generation-in-vsDesk.md at master ยท klsecservices/Advisories
Contribute to klsecservices/Advisories development by creating an account on GitHub.
๐จ CVE-2026-14163
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.
๐@cveNotify
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.
๐@cveNotify
Octopus
Security Advisory Sa2026-07
2026-07 - Sensitive Variables exposed in Deployment Variable Snapshot JSON
๐จ CVE-2026-71368
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
๐@cveNotify
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
๐@cveNotify
f-revocrm.jp
F-RevoCRMใใผใธใงใณ7็ณปไปฅ้ใฎ่ๅผฑๆงใจๅฏพๅฟใซใคใใฆ | F-RevoCRM[ใจใใฌใCRM]๏ผใชใผใใณใฝใผในใฎ้กงๅฎข็ฎก็ใทในใใ
ๅนณ็ด ใใF-RevoCRMใใๅฉ็จใใใ ใ่ช ใซใใใใจใใใใใพใใ ใใฎๅบฆใF-RevoCRMใใผใธใงใณ7็ณปไปฅ้๏ผ7็ณปใป8็ณป๏ผใซใใใฆ่ๅผฑๆงใ็บ่ฆใใใพใใใใใใซไผดใๆฌๆฅใชใชใผในใฎF-RevoCRM 8.0.4&n
๐จ CVE-2026-18963
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
๐@cveNotify
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.
๐@cveNotify
๐จ CVE-2025-14601
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
๐@cveNotify
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
๐@cveNotify
๐จ CVE-2026-75948
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
๐@cveNotify
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
๐@cveNotify
Icagenda
iCagenda - Events Management for Joomla!
iCagenda is a multi-lingual extension designed to create, manage and share events on a Joomla!โข based website.
๐จ CVE-2026-76564
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
๐@cveNotify
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
๐@cveNotify
Phoca
Phoca Cart - Joomla eCommerce and Shopping Cart Extension
๐จ CVE-2026-76565
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
๐@cveNotify
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
๐@cveNotify
Phoca
Phoca Cart - Joomla eCommerce and Shopping Cart Extension
๐จ CVE-2026-76569
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
๐@cveNotify
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
๐@cveNotify
Phoca
Phoca Cart - Joomla eCommerce and Shopping Cart Extension
๐จ CVE-2026-14946
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
๐@cveNotify
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
๐@cveNotify
๐จ CVE-2026-14947
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
๐@cveNotify
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
๐@cveNotify
๐จ CVE-2026-14948
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
๐@cveNotify
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
๐@cveNotify