CVE Notify
19.7K subscribers
4 photos
285K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-81294
Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

🎖@cveNotify
🚨 CVE-2026-81769
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.

This issue affects Booking Hub: from n/a through 1.3.1.

🎖@cveNotify
🚨 CVE-2026-83562
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.

🎖@cveNotify
🚨 CVE-2026-84217
Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Classified Listing: from n/a through 6.1.1.

🎖@cveNotify
🚨 CVE-2026-84759
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.

🎖@cveNotify
🚨 CVE-2026-84760
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.

🎖@cveNotify
🚨 CVE-2026-84771
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.

🎖@cveNotify
🚨 CVE-2026-84792
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.

🎖@cveNotify
🚨 CVE-2026-84793
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.

🎖@cveNotify
🚨 CVE-2026-84794
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.

🎖@cveNotify