π¨ CVE-2026-73208
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known.
π@cveNotify
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known.
π@cveNotify
π¨ CVE-2026-73209
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.
π@cveNotify
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.
π@cveNotify
π¨ CVE-2026-78070
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
π@cveNotify
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
π@cveNotify
Digital Peak
DPCalendar: Joomla calendar and event manager
A responsive Joomla calendar and event management system. Manage your events with powerful repeating patterns and restrict access through native Joomla ACL mana
π¨ CVE-2026-78071
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
π@cveNotify
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
π@cveNotify
Digital Peak
DPCalendar: Joomla calendar and event manager
A responsive Joomla calendar and event management system. Manage your events with powerful repeating patterns and restrict access through native Joomla ACL mana
π¨ CVE-2026-78072
Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
π@cveNotify
Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
π@cveNotify
GitHub
GitHub - Jefferson49/Joomla_extension_sexypolling_reloaded: A Joomla extension for polling with single/multiple voting, addingβ¦
A Joomla extension for polling with single/multiple voting, adding answers by users, start/end dates, voting periods, and extensive template customizing. - Jefferson49/Joomla_extension_sexypolling_...
π¨ CVE-2026-78073
Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors
π@cveNotify
Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors
π@cveNotify
All Video Share
Home - All Video Share
WEBSITES POWERED
π¨ CVE-2026-81732
WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.
π@cveNotify
WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.
π@cveNotify
GitHub
Unauthenticated user-registration statistics disclosure via view/report4.json.php and report4.1.json.php
WWBN/AVideo: `view/report4.json.php` and `view/report4.1.json.php` return daily and cumulative user-registration counts without authentication.
Root cause: both endpoints directly echo `User::getU...
Root cause: both endpoints directly echo `User::getU...
π¨ CVE-2026-81733
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without enforcing a CSRF token or origin check. An attacker who lures a logged-in streamer to a malicious page can silently change the live-channel viewer-redirect settings (persisted in users.externalOptions), causing viewers to be redirected to a phishing site or shown a spoofed message.
π@cveNotify
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without enforcing a CSRF token or origin check. An attacker who lures a logged-in streamer to a malicious page can silently change the live-channel viewer-redirect settings (persisted in users.externalOptions), causing viewers to be redirected to a phishing site or shown a spoofed message.
π@cveNotify
GitHub
CSRF on plugin/Live/myLiveControls.save.json.php allows changing live viewer redirect URL
WWBN/AVideo: `plugin/Live/myLiveControls.save.json.php` changes a logged-in user's live-channel viewer-redirect settings in response to a GET request. No CSRF token or origin check is enforced....
π¨ CVE-2026-81777
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
π@cveNotify
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
π@cveNotify
Patchstack
Bypass Vulnerability in WordPress Essential Addons for Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-82111
A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. Performing a manipulation of the argument image_path results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 1.5.1 is sufficient to fix this issue. The patch is named 7f9a215e03575c650d38c8f87fc6d8d363fed80d. Upgrading the affected component is advised.
π@cveNotify
A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. Performing a manipulation of the argument image_path results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 1.5.1 is sufficient to fix this issue. The patch is named 7f9a215e03575c650d38c8f87fc6d8d363fed80d. Upgrading the affected component is advised.
π@cveNotify
GitHub
GitHub - iswalle/getnote-mcp: GetNote For MCP
GetNote For MCP. Contribute to iswalle/getnote-mcp development by creating an account on GitHub.
π¨ CVE-2026-82222
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
π@cveNotify
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
π@cveNotify
Patchstack
Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP - Patchstack
This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on t
π¨ CVE-2026-82234
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cloud instance metadata and internal services.
π@cveNotify
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cloud instance metadata and internal services.
π@cveNotify
GitHub
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
# Security Advisory β SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of `CheckHostSSRF`)
| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| *...
| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| *...
π¨ CVE-2026-82235
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources.
π@cveNotify
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources.
π@cveNotify
GitHub
fix: fix hanging when reading a named pipe file (closes #1155) Β· filebrowser/filebrowser@586d198
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview and edit your files. - fix: fix hanging when reading a named pipe file (closes #1155) Β· filebrowser/filebrowser@586d198
π¨ CVE-2026-82236
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
π@cveNotify
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
π@cveNotify
GitHub
fix: cross-user unauthorized share-link deletion Β· filebrowser/filebrowser@0231b7e
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview and edit your files. - fix: cross-user unauthorized share-link deletion Β· filebrowser/filebrowser@0231b7e
π¨ CVE-2026-82237
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared path β via re-upload, another user with create permission, or a hook β the stale public share link serves that new file under the original link's password and expiry settings, unexpectedly exposing it.
π@cveNotify
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared path β via re-upload, another user with create permission, or a hook β the stale public share link serves that new file under the original link's password and expiry settings, unexpectedly exposing it.
π@cveNotify
GitHub
Renaming a shared file leaves the public share link behind
## Summary
Share records are keyed by path and are cleaned up when the shared path is deleted, but not when it is
renamed. After a shared file is renamed, its share record survives. The link 404s ...
Share records are keyed by path and are cleaned up when the shared path is deleted, but not when it is
renamed. After a shared file is renamed, its share record survives. The link 404s ...
π¨ CVE-2026-82238
filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads.
π@cveNotify
filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads.
π@cveNotify
GitHub
Concurrent TUS uploads write past the declared Upload-Length
## Summary
The TUS upload handler enforces the declared `Upload-Length` per request only. Nothing serializes
concurrent `PATCH` requests against a single upload, so two or more PATCHes sent at the...
The TUS upload handler enforces the declared `Upload-Length` per request only. Nothing serializes
concurrent `PATCH` requests against a single upload, so two or more PATCHes sent at the...
π¨ CVE-2026-82239
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
π@cveNotify
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
π@cveNotify
GitHub
Missing per-table authorization on POST /api/datasources/query allows low-privilege role to bypass table permission restrictions
### Summary
`POST /api/datasources/query` lets any authenticated user who holds the lowest non-public application role (`BASIC`) read, create, update, or delete rows in any table of any datasour...
`POST /api/datasources/query` lets any authenticated user who holds the lowest non-public application role (`BASIC`) read, create, update, or delete rows in any table of any datasour...
π¨ CVE-2026-82240
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.
π@cveNotify
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate privileges and gain unauthorized builder access to other applications in the same tenant.
π@cveNotify
GitHub
App-scoped builders can grant builder access to unrelated apps through public user update API
# App-scoped builders can grant builder access to unrelated apps through public user update API
## Summary
Budibase 3.39.26 allows an authenticated app-scoped builder for one app to grant bui...
## Summary
Budibase 3.39.26 allows an authenticated app-scoped builder for one app to grant bui...
π¨ CVE-2026-82241
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default blacklist is active (i.e., a self-hosted deployment has not defined BLACKLIST_IPS), an authenticated user with the Builder permission can submit a REST datasource query preview request to POST /api/queries/preview targeting a reachable HTTP(S) service in the 100.64.0.0/10 range, causing the server to send a request to that target and return its response through the preview flow. Per the advisory, no released fix was identified at the time of publication; remediation is to add 100.64.0.0/10 to DEFAULT_BLACKLIST.
π@cveNotify
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default blacklist is active (i.e., a self-hosted deployment has not defined BLACKLIST_IPS), an authenticated user with the Builder permission can submit a REST datasource query preview request to POST /api/queries/preview targeting a reachable HTTP(S) service in the 100.64.0.0/10 range, causing the server to send a request to that target and return its response through the preview flow. Per the advisory, no released fix was identified at the time of publication; remediation is to add 100.64.0.0/10 to DEFAULT_BLACKLIST.
π@cveNotify
GitHub
Budibase backend-core omits shared address space from its default SSRF blacklist
## Affected product
`@budibase/backend-core` as used by Budibase REST datasource query previews through `POST /api/queries/preview`, when the default blacklist is active.
## Summary
`DEFAU...
`@budibase/backend-core` as used by Budibase REST datasource query previews through `POST /api/queries/preview`, when the default blacklist is active.
## Summary
`DEFAU...
π¨ CVE-2026-82242
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject resources by specifying an arbitrary destination workspace ID in the request body, then trigger injected automations with outgoing webhooks to exfiltrate data from victim applications.
π@cveNotify
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject resources by specifying an arbitrary destination workspace ID in the request body, then trigger injected automations with outgoing webhooks to exfiltrate data from victim applications.
π@cveNotify
GitHub
Cross-application resource injection via missing authorization on duplicate endpoint
### Summary
The `POST /api/resources/duplicate` endpoint allows an authenticated application builder to inject tables, automations, queries, and screens from their own application into any other...
The `POST /api/resources/duplicate` endpoint allows an authenticated application builder to inject tables, automations, queries, and screens from their own application into any other...
π¨ CVE-2026-82243
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers, gaining full database access in cloud deployments.
π@cveNotify
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers, gaining full database access in cloud deployments.
π@cveNotify
GitHub
SSRF with Internal CouchDB Credential Leakage via Datasource Verify Endpoint
## Summary
The datasource verify endpoint (`POST /api/datasources/verify`) allows a builder-level user to supply an arbitrary URL as a CouchDB datasource configuration. The CouchDB connector mak...
The datasource verify endpoint (`POST /api/datasources/verify`) allows a builder-level user to supply an arbitrary URL as a CouchDB datasource configuration. The CouchDB connector mak...