π¨ CVE-2026-84759
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
π@cveNotify
π¨ CVE-2026-84760
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
π@cveNotify
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
π@cveNotify
π¨ CVE-2026-84764
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84770
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Mang Board WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84771
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
π@cveNotify
π¨ CVE-2026-84772
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
π@cveNotify
Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
π@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress Broken Link Checker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84775
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
π@cveNotify
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
π@cveNotify
Patchstack
Denial of Service Attack in WordPress Really Simple SSL Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84780
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
π@cveNotify
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
π@cveNotify
Patchstack
Denial of Service Attack in WordPress WP Go Maps Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84781
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Gallery PhotoBlocks Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84792
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
π@cveNotify
Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after initial authorization checks, bypassing the destination section permission validation.
π@cveNotify
GitHub
Broken access control: a non-admin can move/publish entries into sections they cannot edit
The control panel inline-edit endpoint `element-indexes/save-elements` authorizes the current user against each element with `canSave()` before it applies client-supplied attributes, then mass-assi...
π¨ CVE-2026-84793
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.
π@cveNotify
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.
π@cveNotify
GitHub
Stored XSS in site name rendered without escaping
A stored Cross-Site Scripting (XSS) vulnerability exists in the site name field. The application fails to sanitize input, allowing an attacker to execute arbitrary JavaScript when another user view...
π¨ CVE-2026-84794
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
π@cveNotify
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
π@cveNotify
GitHub
Authorization Bypass in assets/move-asset
Craft CMS lacks an authorization check in `assets/move-asset` when the request includes `force=1`.
An authenticated Control Panel user who can manage their own assets in a volume, but does not h...
An authenticated Control Panel user who can manage their own assets in a volume, but does not h...
π¨ CVE-2026-84795
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
π@cveNotify
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured.
π@cveNotify
GitHub
Public registration inherits admin flag from deactivated admin accounts via missing guard
`User::afterSave()` writes `$record->admin = $this->admin` unconditionally, with no guard β while `active`, `pending`, `locked`, and `suspended` all have change-detection guards that ...
π¨ CVE-2026-84796
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
π@cveNotify
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments.
π@cveNotify
GitHub
GQL entry mutation siteId bypasses schema site scope, enabling cross-site content read/write/delete
Craft CMS GraphQL entry mutation resolvers (`saveEntry`, `deleteEntry`) read `siteId` directly from `$arguments` without passing through `ArgumentManager::prepareArguments()`, which is the function...
π¨ CVE-2026-84797
Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to delete another user's unsaved draft without proper authorization checks, gaining access to the victim's in-progress content.
π@cveNotify
Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to delete another user's unsaved draft without proper authorization checks, gaining access to the victim's in-progress content.
π@cveNotify
GitHub
actionDuplicate with deleteProvisionalDraft side-effect deletes peer drafts
`ElementsController::actionDuplicate()` accepts a `deleteProvisionalDraft` request parameter. After successfully duplicating an element, if the source is a provisional draft and this flag is set, t...
π¨ CVE-2026-84798
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own provisional draft (which only verifies draft ownership), then propagates the deletion to the canonical element without re-checking permissions. As a result, an authenticated user who has viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions but lacks the deleteEntriesForSite permission can hard-delete a canonical entry's site record (and, for single-site entries, the full element and content), which is irrecoverable via Craft's recycle bin.
π@cveNotify
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own provisional draft (which only verifies draft ownership), then propagates the deletion to the canonical element without re-checking permissions. As a result, an authenticated user who has viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and editSite permissions but lacks the deleteEntriesForSite permission can hard-delete a canonical entry's site record (and, for single-site entries, the full element and content), which is irrecoverable via Craft's recycle bin.
π@cveNotify
GitHub
actionDeleteForSite propagates deletion to canonical element without independent authorization check
`ElementsController::actionDeleteForSite()` loads an element with `checkForProvisionalDraft: true`, which returns the userβs provisional draft if one exists. It then calls `canDeleteForSite()` on t...
π¨ CVE-2026-84800
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer's asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.
π@cveNotify
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the permission checks execute, so the replacePeerFiles permission is never enforced. An authenticated low-privilege author with only the replaceFiles permission on a shared folder can overwrite the content of a peer's asset file (located in the same folder) with attacker-controlled bytes. Fixed in 5.10.11.
π@cveNotify
GitHub
Peer asset file overwrite via assets/replace-file late-discovered target skips permission check
`AssetsController::actionReplaceFile` allows a low-privilege author to overwrite the file content of an arbitrary peerβs asset. When the request supplies `sourceAssetId` and `targetFilename` but NO...
π¨ CVE-2026-84801
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover.
π@cveNotify
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover.
π@cveNotify
GitHub
Non-admin with administrateUsers permissions can mint an admin password reset URL
`UsersController::actionGetPasswordResetUrl` lets a non-admin control-panel user who holds the `administrateUsers` permission mint a valid password reset URL for any user, including administrators....
π¨ CVE-2026-84802
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.
π@cveNotify
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they cannot access.
π@cveNotify
GitHub
Missing volume permission in AssetsController::actionMoveInfo leaks cross-volume asset count and total size
`AssetsController::actionMoveInfo` (added in 5.7.0) enforces only `requireCpRequest` + `requirePostRequest`, then computes `count()` + `sum(size)` over the assets table for arbitrary `folderIds`/`a...
π¨ CVE-2026-84803
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.
π@cveNotify
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.
π@cveNotify
GitHub
Incomplete Asset Blocklist Bypasses the GHSA-mjf3-jwmf-r6wf Fix (Stored XSS, API Token Theft)
## Summary
The GHSA-mjf3-jwmf-r6wf fix forces `Content-Disposition: attachment` on script-capable assets using a hardcoded extension blocklist, with a fallback that forces attachment when Go doe...
The GHSA-mjf3-jwmf-r6wf fix forces `Content-Disposition: attachment` on script-capable assets using a hardcoded extension blocklist, with a fallback that forces attachment when Go doe...
π¨ CVE-2026-84804
Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing authorization controls.
π@cveNotify
Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing authorization controls.
π@cveNotify
GitHub
API /api/teams/{id}/activities/{activityId} removes team activity access without requiring permissions_activity
## Summary
Kimai's API exposes team activity access management endpoints under `/api/teams/<team-id>/activities/<activity-id>`. Granting activity access correctly requires both `...
Kimai's API exposes team activity access management endpoints under `/api/teams/<team-id>/activities/<activity-id>`. Granting activity access correctly requires both `...