π¨ CVE-2024-7956
A vulnerability exists in the affected products that allows a threat actor to gain access to userβs projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.
π@cveNotify
A vulnerability exists in the affected products that allows a threat actor to gain access to userβs projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.
π@cveNotify
Rockwell Automation
SD1702 | Security Advisory | Rockwell Automation | US
Sensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosaixβ’ Private Cloud
π¨ CVE-2025-15481
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
π@cveNotify
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
π@cveNotify
WPScan
Notification Bar for WordPress <= 1.1.8 β Unauthenticated Subscriber Data Disclosure
See details on Notification Bar for WordPress <= 1.1.8 β Unauthenticated Subscriber Data Disclosure CVE 2025-15481. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2025-15485
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
π@cveNotify
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
π@cveNotify
WPScan
Auto x LINE <= 1.0.0 β Unauthenticated REST API Endpoints Call
See details on Auto x LINE <= 1.0.0 β Unauthenticated REST API Endpoints Call CVE 2025-15485. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2025-15490
The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
π@cveNotify
The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
π@cveNotify
WPScan
Passster < 4.2.26 - Global Protection Bypass
See details on Passster < 4.2.26 - Global Protection Bypass CVE 2025-15490. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2025-15692
The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.
π@cveNotify
WPScan
Icegram Express < 5.8.6 - Admin+ Stored XSS
See details on Icegram Express < 5.8.6 - Admin+ Stored XSS CVE 2025-15692. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2025-8945
The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.
π@cveNotify
The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.
π@cveNotify
WPScan
Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API
See details on Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API CVE 2025-8945. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2025-9314
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
π@cveNotify
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
π@cveNotify
WPScan
Developer Tools <= 1.1.3 β Unauthenticated Arbitrary File Upload
See details on Developer Tools <= 1.1.3 β Unauthenticated Arbitrary File Upload CVE 2025-9314. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-10821
The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution.
π@cveNotify
The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution.
π@cveNotify
WPScan
Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE
See details on Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE CVE 2026-10821. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-14255
A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.
π@cveNotify
A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.
π@cveNotify
Autodesk
Autodesk Access | Formerly Autodesk Desktop App | Autodesk
Autodesk Access simplifies the update experience. Quickly and easily install updates for your desktop products from the app. Download now for free.
π¨ CVE-2026-14326
The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
π@cveNotify
The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
π@cveNotify
WPScan
Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR
See details on Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR CVE 2026-14326. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-17563
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
π@cveNotify
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to paying subscribers.
π@cveNotify
WPScan
WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form
See details on WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form CVE 2026-17563. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-19698
The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.
π@cveNotify
The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users and to anonymous visitors. JavaScript execution is not possible at that role, so the impact is limited to defacement, interface redressing and forcing external resources to load.
π@cveNotify
WPScan
GutenKit < 2.5.1 - Contributor+ Stored CSS Injection
See details on GutenKit < 2.5.1 - Contributor+ Stored CSS Injection CVE 2026-19698. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-2688
The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
π@cveNotify
The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access protected AJAX endpoints.
π@cveNotify
WPScan
CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass
See details on CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass CVE 2026-2688. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-2811
The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.
π@cveNotify
The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.
π@cveNotify
WPScan
Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection
See details on Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection CVE 2026-2811. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-4357
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
π@cveNotify
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
π@cveNotify
WPScan
Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload
See details on Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload CVE 2026-4357. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77009
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
π@cveNotify
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
π@cveNotify
WPScan
WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console
See details on WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console CVE 2026-77009. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77793
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
π@cveNotify
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
π@cveNotify
WPScan
RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field
See details on RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field CVE 2026-77793. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77794
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
π@cveNotify
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
π@cveNotify
WPScan
RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity
See details on RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity CVE 2026-77794. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-78153
The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.
π@cveNotify
The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.
π@cveNotify
WPScan
Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization
See details on Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization CVE 2026-78153. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-78584
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
π@cveNotify
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
π@cveNotify
Discuss the Elastic Stack
Kibana 9.4.4 Security Update (ESA-2026-161)
Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticatedβ¦
π¨ CVE-2026-78586
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.
π@cveNotify
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.
π@cveNotify
Discuss the Elastic Stack
Kibana 8.19.16, 9.3.5, 9.4.2 Security Update (ESA-2026-163)
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated userβ¦