🚨 CVE-2026-84045
The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price.
🎖@cveNotify
The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary price.
🎖@cveNotify
WPScan
E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart
See details on E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart CVE 2026-84045. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-84428
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent names inside the JSON Schema Draft 7 dependencies keyword. Because Node stores request header names in lowercase, a canonical-case dependency such as requiring an authentication header whenever a privileged-mode header is present never matches, and the presence assertion is silently skipped. An unauthenticated remote client can therefore send the header that activates a privileged branch while omitting the header the dependency was meant to require, bypassing the conditional check. Users should upgrade to fastify 5.12.2 or later.
🎖@cveNotify
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent names inside the JSON Schema Draft 7 dependencies keyword. Because Node stores request header names in lowercase, a canonical-case dependency such as requiring an authentication header whenever a privileged-mode header is present never matches, and the presence assertion is silently skipped. An unauthenticated remote client can therefore send the header that activates a privileged branch while omitting the header the dependency was meant to require, bypassing the conditional check. Users should upgrade to fastify 5.12.2 or later.
🎖@cveNotify
cna.openjsf.org
Security Advisories | OpenJS Foundation CVE Numbering Authority
The OpenJS Foundation's CVE Numbering Authority (CNA)
🚨 CVE-2026-85512
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
GitHub
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_room1.php SQL injection · Issue #7 · justconter/cve
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_room1.php SQL injection NAME OF AFFECTED PRODUCT(S) Class and Exam Timetabling System Vendor Homepage https://www.sourcecode...
🚨 CVE-2026-85534
A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.
🎖@cveNotify
A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.
🎖@cveNotify
Redhat
CVE-2026-85534 - Red Hat Customer Portal
CVE Details App
🚨 CVE-2026-20696
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data.
🎖@cveNotify
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data.
🎖@cveNotify
Apple Support
About the security content of macOS Sequoia 15.7.4 - Apple Support
This document describes the security content of macOS Sequoia 15.7.4.
🚨 CVE-2026-77995
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
🎖@cveNotify
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
🎖@cveNotify
Miniorange
miniOrange Security Software: IAM, PAM, IGA, MDM, DLP, Data Privacy & AI Security
miniOrange offers wide range of security products including IAM, PAM, IGA, MDM, DLP, Data Privacy & AI Security
🚨 CVE-2026-78367
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).
🎖@cveNotify
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).
🎖@cveNotify
Redhat
CVE-2026-78367 - Red Hat Customer Portal
CVE Details App
🚨 CVE-2026-18957
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19043
Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19051
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19080
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-85577
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page.
🎖@cveNotify
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page.
🎖@cveNotify
GitHub
Reflected XSS: userLogin.php echoes addslashes($_GET['error']) inside a script block, and addslashes does not escape </script>…
## Summary
`view/userLogin.php:276` echoes `addslashes($_GET['error'])` inside a `<script>` block. `addslashes()` escapes `'`, `"`, `\`, and NUL but does not escape `</sc...
`view/userLogin.php:276` echoes `addslashes($_GET['error'])` inside a `<script>` block. `addslashes()` escapes `'`, `"`, `\`, and NUL but does not escape `</sc...
🚨 CVE-2026-85578
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
🎖@cveNotify
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
🎖@cveNotify
GitHub
Reader can read files from an explicitly hidden notebook
### Summary
A reader-role authorization bypass in `/api/file/getFile` allows retrieval of normal files below a notebook explicitly configured as `Visible:false` in publish access. The same raw-fil...
A reader-role authorization bypass in `/api/file/getFile` allows retrieval of normal files below a notebook explicitly configured as `Visible:false` in publish access. The same raw-fil...
🚨 CVE-2026-85579
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed.
🎖@cveNotify
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed.
🎖@cveNotify
GitHub
Reader-role undoState discloses private related document root IDs
### Summary
The reader-accessible `POST /api/transactions/undoState` endpoint returns the `peekMutatedRootIDs` list from the global undo-log stack for a caller-supplied root ID. The list is copi...
The reader-accessible `POST /api/transactions/undoState` endpoint returns the `peekMutatedRootIDs` list from the global undo-log stack for a caller-supplied root ID. The list is copi...
🚨 CVE-2026-85580
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.
🎖@cveNotify
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.
🎖@cveNotify
GitHub
Linux MCP publish-access path guard bypass exposes publishAccess.json
### Summary
On Linux, the MCP file-access path guard compares a case-variant path against the protected `publishAccess.json` filename using case-sensitive matching. A read-only MCP request can u...
On Linux, the MCP file-access path guard compares a case-variant path against the protected `publishAccess.json` filename using case-sensitive matching. A read-only MCP request can u...
🚨 CVE-2026-85581
SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.
🎖@cveNotify
SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.
🎖@cveNotify
GitHub
Unauthenticated UI-process registration retains attacker-controlled identifiers without bound
### Summary
The public `/api/system/uiproc` endpoint accepts attacker-controlled UI-process identifiers and retains them in a global registry without a size limit or authentication requirement. ...
The public `/api/system/uiproc` endpoint accepts attacker-controlled UI-process identifiers and retains them in a global registry without a size limit or authentication requirement. ...
🚨 CVE-2026-85582
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing indefinite process memory growth and denial of service.
🎖@cveNotify
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing indefinite process memory growth and denial of service.
🎖@cveNotify
GitHub
Publish-service Basic Auth creates unbounded persistent sessions
### Summary
Successful publish-service Basic Auth requests create persistent session entries keyed by newly issued session cookies. The registry has no effective TTL or size bound for valid sess...
Successful publish-service Basic Auth requests create persistent session entries keyed by newly issued session cookies. The registry has no effective TTL or size bound for valid sess...
🚨 CVE-2026-85583
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace boundary restrictions.
🎖@cveNotify
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace boundary restrictions.
🎖@cveNotify
GitHub
Reader-role file API follows workspace assets symlinks outside the workspace
### Summary
The reader-accessible file-read endpoint performs lexical workspace and publish checks but follows a symlink when opening an authorized asset path. A reader can request a logical ass...
The reader-accessible file-read endpoint performs lexical workspace and publish checks but follows a symlink when opening an authorized asset path. A reader can request a logical ass...
🚨 CVE-2026-85584
SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policies. Unauthenticated attackers can submit repeated authentication requests with unique invalid usernames to exhaust memory and increase synchronization overhead, degrading service availability.
🎖@cveNotify
SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policies. Unauthenticated attackers can submit repeated authentication requests with unique invalid usernames to exhaust memory and increase synchronization overhead, degrading service availability.
🎖@cveNotify
GitHub
Publish-auth throttling retains unique invalid-user keys without a bound
### Summary
The publish-service Basic Auth throttle stores failed-attempt state under a key derived from the remote address and username. Every unique invalid username creates a persistent map e...
The publish-service Basic Auth throttle stores failed-attempt state under a key derived from the remote address and username. Every unique invalid username creates a persistent map e...
🚨 CVE-2026-85585
SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous unique request paths to permanently increase process memory and synchronization overhead, degrading availability.
🎖@cveNotify
SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous unique request paths to permanently increase process memory and synchronization overhead, degrading availability.
🎖@cveNotify
GitHub
Unauthenticated unique request paths grow the global ControlConcurrency map without bound
## Summary
SiYuan’s request-concurrency middleware retains a mutex entry for every non-exempt request path. The path-keyed global map has no eviction or size bound, so an unauthenticated calle...
SiYuan’s request-concurrency middleware retains a mutex entry for every non-exempt request path. The path-keyed global map has no eviction or size bound, so an unauthenticated calle...
🚨 CVE-2026-85586
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
🎖@cveNotify
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
🎖@cveNotify
GitHub
CAPTCHA bypass on anonymous question submission via store=now parameter
> **Authorized research notice:** This vulnerability was discovered during authorized security research in an isolated lab environment against a local instance of phpMyFAQ (main @ 9435f34bd8fcaa...