๐จ CVE-2026-81293
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
๐@cveNotify
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
๐@cveNotify
๐จ CVE-2026-81296
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Fluent Forms Pro Add On Pack Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81297
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
๐@cveNotify
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
๐@cveNotify
Patchstack
Privilege Escalation in WordPress Fluent Forms Pro Add On Pack Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81298
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress LeadConnector Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81756
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
๐@cveNotify
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Smart Marketing SMS and Newsletters Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81758
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
๐@cveNotify
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress OwnerRez API Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81762
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
๐@cveNotify
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Booking and Rental Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81763
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
๐@cveNotify
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Throws SPAM Away Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81764
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Email Essentials Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81765
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Tailored Tools Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81768
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Super Store Finder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81778
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
๐@cveNotify
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Kalles Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-81779
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.
This issue affects Newspapers X: from 1.0.46 through 1.0.48.
๐@cveNotify
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.
This issue affects Newspapers X: from 1.0.46 through 1.0.48.
๐@cveNotify
Patchstack
Backdoor in WordPress Newspapers X Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82221
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress RegistrationMagic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82224
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
๐@cveNotify
๐จ CVE-2026-82225
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress RegistrationMagic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82226
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Tickera Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82228
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
๐@cveNotify
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
๐@cveNotify
Patchstack
Bypass Vulnerability in WordPress SiteGround Security Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82229
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WordPress Social Login and Register Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82852
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
๐@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress MapSVG Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-82906
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
GitHub
Poc/sdcb-chats/chats-poc-2.md at main ยท yaowenxiao721/Poc
Contribute to yaowenxiao721/Poc development by creating an account on GitHub.