๐จ CVE-2026-12843
The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.
๐@cveNotify
The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.
๐@cveNotify
Nexcess Documentation
Changelogs
๐จ CVE-2026-15550
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.
๐@cveNotify
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.
๐@cveNotify
Ninja Forms
Save Progress
Let users save WordPress form progress and continue later from any device. Add a save-and-continue button to any form in minutes. Works with Multi Step Forms.
๐จ CVE-2026-86184
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.
๐@cveNotify
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.
๐@cveNotify
GitHub
GitHub - laradashboard/laradashboard: โก Lara Dashboard - CMS by Laravel - All In One solution to start your Laravel Applicationโฆ
โก Lara Dashboard - CMS by Laravel - All In One solution to start your Laravel Application from Basic to Enterprise. Manages Users, Roles, Permissions, Modules, Settings, Translations, Contents, Mon...
๐จ CVE-2026-86185
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
๐@cveNotify
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
๐@cveNotify
Bilibili
ๅๅฉๅๅฉไธ่ฝฝไธญๅฟ
ๅๅฉๅๅฉAPPไธ่ฝฝ,ๅๅฉๅๅฉPCๅฎขๆท็ซฏไธ่ฝฝ
๐จ CVE-2026-42965
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.
๐@cveNotify
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.
๐@cveNotify
๐จ CVE-2026-1784
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
๐@cveNotify
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
๐@cveNotify
๐จ CVE-2026-16242
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
๐@cveNotify
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
๐@cveNotify
๐จ CVE-2026-50236
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
๐@cveNotify
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
๐@cveNotify
๐จ CVE-2026-50237
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
๐@cveNotify
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
๐@cveNotify
๐จ CVE-2026-86186
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.
๐@cveNotify
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.
๐@cveNotify
GitHub
Protection Mechanism Failure: every API rate limit, including login brute-force protection, is disabled by sending a bot User-Agent
### Summary
Every rate limit in the AVideo API is disabled by sending a bot User-Agent. The attacker controls that header, so all eight protected operations including login brute-force protectio...
Every rate limit in the AVideo API is disabled by sending a bot User-Agent. The attacker controls that header, so all eight protected operations including login brute-force protectio...
๐จ CVE-2026-86187
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.
๐@cveNotify
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.
๐@cveNotify
GitHub
Use of a Cryptographically Weak PRNG: accounts created by external-login flows are given a rand() password, recoverable from itsโฆ
### Summary
Every account AVideo creates through an external-login flow is given a local password generated by `rand()`. On PHP 7.1+ that is Mersenne Twister, not a cryptographic generator, and ...
Every account AVideo creates through an external-login flow is given a local password generated by `rand()`. On PHP 7.1+ that is Mersenne Twister, not a cryptographic generator, and ...
๐จ CVE-2026-86188
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script execution in the victim's origin without authentication or user interaction.
๐@cveNotify
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script execution in the victim's origin without authentication or user interaction.
๐@cveNotify
GitHub
Cross-Site Scripting: the websocket layer lets an unauthenticated peer choose which global JavaScript function runs in anotherโฆ
### Summary
When the **YPTSocket** plugin is enabled, an unauthenticated remote attacker can execute arbitrary JavaScript in the browser of any other user currently on the site, including an adm...
When the **YPTSocket** plugin is enabled, an unauthenticated remote attacker can execute arbitrary JavaScript in the browser of any other user currently on the site, including an adm...
๐จ CVE-2026-86189
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.
๐@cveNotify
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.
๐@cveNotify
GitHub
Broken Access Control and Path Traversal: notify.ffmpeg.json.php writes a downloaded file to a caller-chosen path, behind a tokenโฆ
### Summary
`plugin/API/notify.ffmpeg.json.php` accepts a request parameter that decides where a downloaded file is written, and concatenates it onto the application root with no containment che...
`plugin/API/notify.ffmpeg.json.php` accepts a request parameter that decides where a downloaded file is written, and concatenates it onto the application root with no containment che...
๐จ CVE-2026-86190
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.
๐@cveNotify
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.
๐@cveNotify
GitHub
Broken Access Control and Sensitive Data Exposure: the video statistics endpoints return every viewer's password hash, recoveryโฆ
### Summary
`view/videoViewsInfo.json.php`, `.csv.php` and `.php` return the video statistics screen. When called with a `hash` parameter they skip the permission check entirely, and the rows th...
`view/videoViewsInfo.json.php`, `.csv.php` and `.php` return the video statistics screen. When called with a `hash` parameter they skip the permission check entirely, and the rows th...
๐จ CVE-2026-86191
SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.
๐@cveNotify
SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.
๐@cveNotify
GitHub
Reader Can Enumerate Private Attribute-View Key Definitions
### Summary
The `getAttributeViewKeysByID` endpoint allows a publish reader to enumerate an attribute viewโs complete key schema without checking whether its parent database is visible in publis...
The `getAttributeViewKeysByID` endpoint allows a publish reader to enumerate an attribute viewโs complete key schema without checking whether its parent database is visible in publis...
๐จ CVE-2026-86192
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
๐@cveNotify
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.
๐@cveNotify
GitHub
Published Attribute-View Rows Retain Hidden KeyValues
### Summary
A publish reader can retrieve private attribute-view cell values from rows bound to hidden documents. The reader filter removes an attribute-view row only when the rowโs database blo...
A publish reader can retrieve private attribute-view cell values from rows bound to hidden documents. The reader filter removes an attribute-view row only when the rowโs database blo...
๐จ CVE-2026-86193
grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
๐@cveNotify
grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.
๐@cveNotify
GitHub
Target-super guards ignore group-inherited super
### Summary
Every "is the target a super-admin?" guard in Grav's user-management surface decides by reading the target account's own `access` map (`accessGrantsSuper($target->...
Every "is the target a super-admin?" guard in Grav's user-management surface decides by reading the target account's own `access` map (`accessGrantsSuper($target->...
๐จ CVE-2026-86194
Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.
๐@cveNotify
Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.
๐@cveNotify
GitHub
Cross-page form resolution runs a restricted page's form actions for anonymous visitors
### Summary
When a form POST cannot be resolved to a form on the page being posted to, `FormPlugin::getForm()` falls back to `findFormByName()`, which searches every page on the site for a form ...
When a form POST cannot be resolved to a form on the page being posted to, `FormPlugin::getForm()` falls back to `findFormByName()`, which searches every page on the site for a form ...
๐จ CVE-2026-86195
grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can create an invitation with a dot-keyed super flag in the access payload that bypasses the guard and persists to the new account. Attackers can accept the invitation through the public endpoint without real invitee interaction to create a super-admin account and immediately receive a valid JWT for full site control.
๐@cveNotify
grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can create an invitation with a dot-keyed super flag in the access payload that bypasses the guard and persists to the new account. Attackers can accept the invitation through the public endpoint without real invitee interaction to create a super-admin account and immediately receive a valid JWT for full site control.
๐@cveNotify
GitHub
Non-super user manager can mint a super-admin via a dot-keyed super flag in the invitation access payload
### Summary
`InvitationsController::stripSuperFlags()` โ the guard that stops a non-super user manager from minting a super-admin through the invitation flow โ only strips the nested form of the...
`InvitationsController::stripSuperFlags()` โ the guard that stops a non-super user manager from minting a super-admin through the invitation flow โ only strips the nested form of the...
๐จ CVE-2026-86196
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
๐@cveNotify
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
๐@cveNotify
GitHub
Password reset links in the API plugin are built from the request Host header, allowing anonymous account takeover
### Summary
`POST /api/v1/auth/forgot-password` in the Grav **API plugin** builds the password-reset link in the outgoing email from the `Host` header of the incoming request. An unauthenticated...
`POST /api/v1/auth/forgot-password` in the Grav **API plugin** builds the password-reset link in the outgoing email from the `Host` header of the incoming request. An unauthenticated...
๐จ CVE-2026-86197
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.
๐@cveNotify
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.
๐@cveNotify
GitHub
Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating toโฆ
## Summary
Grav 2.0 renders editor-authored Twig in page content by default and relies on the Twig content sandbox to contain it. The shipped sandbox policy allowlists `addcss` and `addjs` on `G...
Grav 2.0 renders editor-authored Twig in page content by default and relies on the Twig content sandbox to contain it. The shipped sandbox policy allowlists `addcss` and `addjs` on `G...