🚨 CVE-2026-78273
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
🎖@cveNotify
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-78281
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CP Media Player Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-78286
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
🎖@cveNotify
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
🎖@cveNotify
Patchstack
PHP Object Injection in WordPress Geo Controller Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-78288
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
🎖@cveNotify
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Beautiful Taxonomy Filters Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-78289
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CozyStay Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-78293
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP w3all phpBB Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-80433
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
🎖@cveNotify
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
🎖@cveNotify
Patchstack
Sensitive Data Exposure in WordPress SureFeedback Client Site Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81271
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress GeoDirectory Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81273
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
🎖@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
🎖@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress FluentBooking Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81277
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
🎖@cveNotify
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Suggestion Engine for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
🚨 CVE-2026-81279
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
🎖@cveNotify
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
🎖@cveNotify
🚨 CVE-2026-81572
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary
system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted
with System privileges and potentially enable local privilege escalation.
🎖@cveNotify
cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and
file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file
operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary
system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted
with System privileges and potentially enable local privilege escalation.
🎖@cveNotify
🚨 CVE-2026-81573
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.
🎖@cveNotify
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.
🎖@cveNotify