CVE Notify
19.7K subscribers
4 photos
285K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-81289
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.

🎖@cveNotify
🚨 CVE-2026-81294
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

🎖@cveNotify
🚨 CVE-2026-81769
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.

This issue affects Booking Hub: from n/a through 1.3.1.

🎖@cveNotify
🚨 CVE-2026-83562
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.

🎖@cveNotify
🚨 CVE-2026-84217
Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Classified Listing: from n/a through 6.1.1.

🎖@cveNotify
🚨 CVE-2026-84759
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.

🎖@cveNotify
🚨 CVE-2026-84760
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.

🎖@cveNotify
🚨 CVE-2026-84771
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.

🎖@cveNotify
🚨 CVE-2026-84792
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.

🎖@cveNotify