๐จ CVE-2026-86181
A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used.
๐@cveNotify
A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used.
๐@cveNotify
๐จ CVE-2026-86182
A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
GitHub
GitHub - diem-project/diem: Diem CMF CMS for symfony 1.4
Diem CMF CMS for symfony 1.4. Contribute to diem-project/diem development by creating an account on GitHub.
๐จ CVE-2026-86183
A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
GitHub
GitHub - diem-project/diem: Diem CMF CMS for symfony 1.4
Diem CMF CMS for symfony 1.4. Contribute to diem-project/diem development by creating an account on GitHub.
๐จ CVE-2026-19859
The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.
๐@cveNotify
The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.
๐@cveNotify
WPScan
JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter
See details on JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Parameter CVE 2026-19859. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19862
The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.
๐@cveNotify
The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.
๐@cveNotify
WPScan
JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action
See details on JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action CVE 2026-19862. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-80437
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
๐@cveNotify
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
๐@cveNotify
WPScan
Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags
See details on Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags CVE 2026-80437. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-80439
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.
๐@cveNotify
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.
๐@cveNotify
WPScan
Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags
See details on Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags CVE 2026-80439. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-86208
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
๐@cveNotify
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
๐@cveNotify
GitHub
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_schoolyr.php SQL injection ยท Issue #10 ยท justconter/cve
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_schoolyr.php SQL injection NAME OF AFFECTED PRODUCT(S) Class and Exam Timetabling System Vendor Homepage https://www.sourcec...
๐จ CVE-2026-86209
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
๐@cveNotify
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
๐@cveNotify
GitHub
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_rooma.php SQL injection ยท Issue #9 ยท justconter/cve
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_rooma.php SQL injection NAME OF AFFECTED PRODUCT(S) Class and Exam Timetabling System Vendor Homepage https://www.sourcecode...
๐จ CVE-2026-86210
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
๐@cveNotify
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
๐@cveNotify
GitHub
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_room2.php SQL injection ยท Issue #8 ยท justconter/cve
sourcecodester Class and Exam Timetabling System Project V1.0 /modal_add_room2.php SQL injection NAME OF AFFECTED PRODUCT(S) Class and Exam Timetabling System Vendor Homepage https://www.sourcecode...
๐จ CVE-2025-15693
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.
๐@cveNotify
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.
๐@cveNotify
WPScan
JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal
See details on JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal CVE 2025-15693. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2025-15694
The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.
๐@cveNotify
The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.
๐@cveNotify
WPScan
Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS
See details on Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS CVE 2025-15694. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-15247
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
๐@cveNotify
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
๐@cveNotify
WPScan
Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion
See details on Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion CVE 2026-15247. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19858
The JetFormBuilder โ Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder โ Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.
๐@cveNotify
The JetFormBuilder โ Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder โ Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.
๐@cveNotify
WPScan
JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset
See details on JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset CVE 2026-19858. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-19861
The JetFormBuilder โ Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.
๐@cveNotify
The JetFormBuilder โ Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.
๐@cveNotify
WPScan
JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails
See details on JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails CVE 2026-19861. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-77826
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.
๐@cveNotify
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.
๐@cveNotify
WPScan
RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation
See details on RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation CVE 2026-77826. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-78149
The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.
๐@cveNotify
The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.
๐@cveNotify
WPScan
Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id
See details on Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id CVE 2026-78149. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-78150
The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.
๐@cveNotify
The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.
๐@cveNotify
WPScan
Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR
See details on Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR CVE 2026-78150. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-78362
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.
๐@cveNotify
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.
๐@cveNotify
WPScan
SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication
See details on SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication CVE 2026-78362. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-81348
The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.
๐@cveNotify
The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.
๐@cveNotify
WPScan
My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap
See details on My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap CVE 2026-81348. View the latest Plugin Vulnerabilities on WPScan.
๐จ CVE-2026-81404
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
๐@cveNotify
The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.
๐@cveNotify
WPScan
IPGP Visitors Origin < 1.6 - Reflected XSS
See details on IPGP Visitors Origin < 1.6 - Reflected XSS CVE 2026-81404. View the latest Plugin Vulnerabilities on WPScan.