🚨 CVE-2026-45199
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
🎖@cveNotify
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
🎖@cveNotify
Imagination
Imagination GPU Driver Vulnerabilities - Imagination
This page contains summary details of security vulnerabilities reported on Imagination Technologies Power VR Graphics driver.
🚨 CVE-2026-45202
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption.
Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.
🎖@cveNotify
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption.
Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.
🎖@cveNotify
Imagination
Imagination GPU Driver Vulnerabilities - Imagination
This page contains summary details of security vulnerabilities reported on Imagination Technologies Power VR Graphics driver.
🚨 CVE-2026-65644
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
🎖@cveNotify
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
🎖@cveNotify
GitHub
fix: special characters not escaped in Omnichannel queue side panel message preview by julio-rocketchat · Pull Request #41595 ·…
Proposed changes (including videos or screenshots)
Issue(s)
https://rocketchat.atlassian.net/browse/VLN-531
Steps to test or reproduce
Further comments
Summary by CodeRabbit
Bug Fixes
Fixe...
Issue(s)
https://rocketchat.atlassian.net/browse/VLN-531
Steps to test or reproduce
Further comments
Summary by CodeRabbit
Bug Fixes
Fixe...
🚨 CVE-2026-65645
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user.
The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
🎖@cveNotify
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user.
The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
🎖@cveNotify
GitHub
fix: imported fixes 08-18-2026 by julio-rocketchat · Pull Request #41814 · RocketChat/Rocket.Chat
Proposed changes (including videos or screenshots)
Approvals have already been added to the private PRs.
Issue(s)
https://github.com/RocketChat/Rocket.Chat-private-security-fork/pull/853
https://gi...
Approvals have already been added to the private PRs.
Issue(s)
https://github.com/RocketChat/Rocket.Chat-private-security-fork/pull/853
https://gi...
🚨 CVE-2025-15671
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
🎖@cveNotify
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in through an attacker-crafted request.
🎖@cveNotify
WPScan
Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter
See details on Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter CVE 2025-15671. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-13736
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
🎖@cveNotify
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
🎖@cveNotify
WPScan
NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
See details on NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API CVE 2026-13736. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14325
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
🎖@cveNotify
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
🎖@cveNotify
WPScan
Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting
See details on Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via drag_n_drop_heading_tag Setting CVE 2026-14325. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-14601
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.
🎖@cveNotify
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.
🎖@cveNotify
WPScan
Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter
See details on Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter CVE 2026-14601. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16575
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.
🎖@cveNotify
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when category-based commission is configured, the per-category and default commission rates.
🎖@cveNotify
WPScan
Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint
See details on Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint CVE 2026-16575. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16576
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
🎖@cveNotify
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Managers to install and activate arbitrary Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 from WordPress.org.
🎖@cveNotify
WPScan
Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
See details on Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API CVE 2026-16576. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16577
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
🎖@cveNotify
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary amount and clear their real commission debt without paying.
🎖@cveNotify
WPScan
Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount
See details on Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount CVE 2026-16577. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16959
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
🎖@cveNotify
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
🎖@cveNotify
WPScan
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
See details on Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector CVE 2026-16959. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16962
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).
🎖@cveNotify
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders store-wide by enumerating ids (triggering downstream stock-release and notification side-effects).
🎖@cveNotify
WPScan
Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation
See details on Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation CVE 2026-16962. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-18781
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
🎖@cveNotify
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
🎖@cveNotify
WPScan
Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass
See details on Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass CVE 2026-18781. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19085
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.
🎖@cveNotify
The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable.
🎖@cveNotify
WPScan
Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure
See details on Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure CVE 2026-19085. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-19435
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
🎖@cveNotify
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content.
🎖@cveNotify
WPScan
Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure
See details on Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure CVE 2026-19435. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-75796
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
🎖@cveNotify
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
🎖@cveNotify
WPScan
AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools
See details on AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools CVE 2026-75796. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16323
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass.
This issue affects ArchitectPanel Web Admin Panel: through 28072026.
🎖@cveNotify
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass.
This issue affects ArchitectPanel Web Admin Panel: through 28072026.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19441
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
This issue affects Rush: through 21082026.
🎖@cveNotify
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
This issue affects Rush: through 21082026.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-73537
Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered.
🎖@cveNotify
Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered.
🎖@cveNotify
jvn.jp
JVN#09266484: Miraikan Assist App vulnerable to cross-site scripting
Japan Vulnerability Notes
🚨 CVE-2026-77264
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
🎖@cveNotify
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.
🎖@cveNotify