π¨ CVE-2026-81773
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ninja Forms File Uploads Extension Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81776
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
π@cveNotify
π¨ CVE-2026-84215
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
π@cveNotify
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Timetics Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84238
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
π@cveNotify
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress YITH Request a Quote for WooCommerce Premium Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84736
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification.
As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens.
The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.
π@cveNotify
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification.
As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens.
The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.
π@cveNotify
GitHub
fix(security): set TLS_CERTIFICATE_VALIDATION true by default Β· eclipse-aerios/federator@9c63b60
The aeriOS Federator serves as a management service responsible for controlling the establishment and maintenance of federation mechanisms among the multiple aeriOS domains that form the Cloud-Edge-IoT continuum - fix(security): set TLS_CERTIFICATE_VALIDATIONβ¦
π¨ CVE-2026-84754
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
π@cveNotify
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress WPFunnels Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84755
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
π@cveNotify
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Mail Mint Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84756
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
π@cveNotify
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress WCFM Membership Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84757
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
π@cveNotify
Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
π@cveNotify
Patchstack
Settings Change in WordPress WP Compress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84758
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
π@cveNotify
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
π@cveNotify
π¨ CVE-2026-84761
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
π@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
π@cveNotify
π¨ CVE-2026-84762
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
π@cveNotify
Patchstack
Bypass Vulnerability in WordPress WP EasyPay Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84763
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress RTMKit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84765
Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Breadcrumb NavXT Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84766
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
π@cveNotify
π¨ CVE-2026-84767
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
π@cveNotify
Patchstack
Bypass Vulnerability in WordPress BookIt Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84768
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
π@cveNotify
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
π@cveNotify
π¨ CVE-2026-84769
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Business Directory Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84773
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress EWWW Image Optimizer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-84774
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
π@cveNotify