π¨ CVE-2026-90547
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve sensitive chapter metadata without authentication or password verification.
π@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve sensitive chapter metadata without authentication or password verification.
π@cveNotify
GitHub
Missing authorization: `Bookmark/getBookmarks.json.php` returns chapter names for a password-protected VOD with no `canWatchVideo`β¦
## Summary
`plugin/Bookmark/getBookmarks.json.php` loads `new Video("", "", $_GET['videos_id'])` and then `BookmarkTable::getAllFromVideo` with no `User::canWatchVideo(...
`plugin/Bookmark/getBookmarks.json.php` loads `new Video("", "", $_GET['videos_id'])` and then `BookmarkTable::getAllFromVideo` with no `User::canWatchVideo(...
π¨ CVE-2026-90548
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.
π@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.
π@cveNotify
GitHub
Missing authorization: `ImageGallery/list.json.php` lists gallery files for a password-protected image video with no `canWatchVideo`β¦
## Summary
`plugin/ImageGallery/list.json.php` checks that the plugin is enabled and that the video type is image (`dieIfIsInvalid`). It does not call `User::canWatchVideo()` or require the video ...
`plugin/ImageGallery/list.json.php` checks that the plugin is enabled and that the video type is image (`dieIfIsInvalid`). It does not call `User::canWatchVideo()` or require the video ...
π¨ CVE-2026-90549
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an unauthenticated GET request to the endpoint.
π@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an unauthenticated GET request to the endpoint.
π@cveNotify
GitHub
Missing authorization: `objects/videosAndroid.json.php` lists password-protected VODs with owner email, lastLogin, filename, andβ¦
## Summary
`objects/videos.json.php` returns `total=0` for a guest. `objects/videosAndroid.json.php` calls `Video::getAllVideos(Video::SORT_TYPE_VIEWABLE)` and attaches the joined user row, includ...
`objects/videos.json.php` returns `total=0` for a guest. `objects/videosAndroid.json.php` calls `Video::getAllVideos(Video::SORT_TYPE_VIEWABLE)` and attaches the joined user row, includ...
π¨ CVE-2026-90550
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video ID parameter to retrieve password-protected video titles and owner email addresses without authentication.
π@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video ID parameter to retrieve password-protected video titles and owner email addresses without authentication.
π@cveNotify
GitHub
Missing authorization: `PlayerSkins/mediaSession.json.php` returns password-protected VOD title and owner identification with noβ¦
## Summary
`plugin/PlayerSkins/mediaSession.json.php` calls `getMediaSession()` with no login or `User::canWatchVideo()` check. `getMediaSession()` in `objects/functions.php` takes `$_REQUEST['...
`plugin/PlayerSkins/mediaSession.json.php` calls `getMediaSession()` with no login or `User::canWatchVideo()` check. `getMediaSession()` in `objects/functions.php` takes `$_REQUEST['...
π¨ CVE-2026-90552
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.
π@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.
π@cveNotify
GitHub
Missing authorization: `Playlists_schedules/list.json.php` and `Live/calendar.json.php` return private playlist schedule rows withoutβ¦
## Summary
`plugin/PlayLists/View/Playlists_schedules/add.json.php` requires `PlayLists::canManagePlaylist()` on both an existing row and the target `playlists_id`. `plugin/PlayLists/View/Playlist...
`plugin/PlayLists/View/Playlists_schedules/add.json.php` requires `PlayLists::canManagePlaylist()` on both an existing row and the target `playlists_id`. `plugin/PlayLists/View/Playlist...
π¨ CVE-2026-90553
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.
π@cveNotify
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.
π@cveNotify
GitHub
LlavaOnevision2 processor loader executes attacker model code with `trust_remote_code=False` (inert `trust_remote_code` kwarg toβ¦
### Summary
`LlavaOnevision2`'s processor loader `_load_ov2_processor` loads the model's **remote** processor classes via `transformers.dynamic_module_utils.get_class_from_dynamic_module(....
`LlavaOnevision2`'s processor loader `_load_ov2_processor` loads the model's **remote** processor classes via `transformers.dynamic_module_utils.get_class_from_dynamic_module(....
π¨ CVE-2026-90554
vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(video_bytes)) without the max_duration_s or max_decode_bytes parameters, so neither VLLM_MAX_AUDIO_DECODE_DURATION_S nor VLLM_MAX_AUDIO_DECODE_BYTES is enforced (unlike the direct audio upload path in AudioMediaIO). When a NanoNemotronVL model is served with use_audio_in_video=True, an attacker who supplies a small, highly compressed video as multimodal input can force the server to allocate gigabytes of memory during audio decoding, resulting in a denial of service. Fixed in vLLM 0.28.0.
π@cveNotify
vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(video_bytes)) without the max_duration_s or max_decode_bytes parameters, so neither VLLM_MAX_AUDIO_DECODE_DURATION_S nor VLLM_MAX_AUDIO_DECODE_BYTES is enforced (unlike the direct audio upload path in AudioMediaIO). When a NanoNemotronVL model is served with use_audio_in_video=True, an attacker who supplies a small, highly compressed video as multimodal input can force the server to allocate gigabytes of memory during audio decoding, resulting in a denial of service. Fixed in vLLM 0.28.0.
π@cveNotify
GitHub
Denial of Service NanoNemoTronVL Video Audio Extraction Bomb
### Summary
NanoNemotronVL video audio extraction no decode-size safe guard via `load_audio_pyav`
### Details
Hello I was reviewing https://github.com/vllm-project/vllm/pull/49948 which is a b...
NanoNemotronVL video audio extraction no decode-size safe guard via `load_audio_pyav`
### Details
Hello I was reviewing https://github.com/vllm-project/vllm/pull/49948 which is a b...
π¨ CVE-2026-90555
vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.
π@cveNotify
vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.
π@cveNotify
GitHub
Speech-to-text audio decode duration limit bypass via forged header sample rate
### Summary
The fix for GHSA-6pr9-rp53-2pmc / CVE-2026-54233 (PR #44970, commit `1b1359c33`) added a `max_duration_s` guard to audio decoding that, on the primary `soundfile` code path, computes d...
The fix for GHSA-6pr9-rp53-2pmc / CVE-2026-54233 (PR #44970, commit `1b1359c33`) added a `max_duration_s` guard to audio decoding that, on the primary `soundfile` code path, computes d...
π¨ CVE-2026-78569
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
π@cveNotify
Ibm
Security Bulletin: Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missingβ¦
Langflow uses a code security scanner and component-level execution policies to restrict server-side code execution to authorized users and contexts. The agentic assistant code scanner employs an incomplete denylist omitting process-spawning primitives andβ¦
π¨ CVE-2026-79724
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
π@cveNotify
Ibm
Security Bulletin: Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missingβ¦
Langflow uses a code security scanner and component-level execution policies to restrict server-side code execution to authorized users and contexts. The agentic assistant code scanner employs an incomplete denylist omitting process-spawning primitives andβ¦
π¨ CVE-2026-84889
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
π@cveNotify
Ibm
Security Bulletin: A path traversal vulnerability in file handling components could allow an authenticated attacker to write filesβ¦
A path traversal vulnerability existed in two independent file handling mechanisms used by the product's workflow execution and file management capabilities. The file upload endpoint accepted multipart filenames directly from HTTP request metadata withoutβ¦
π¨ CVE-2026-70341
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
π@cveNotify
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-75800
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
π@cveNotify
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
π@cveNotify
WPScan
Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse
See details on Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse CVE 2026-75800. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77005
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
WPScan
Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
See details on Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal CVE 2026-77005. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77006
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
π@cveNotify
WPScan
WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal
See details on WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal CVE 2026-77006. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77689
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.
π@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.
π@cveNotify
WPScan
Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass
See details on Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass CVE 2026-77689. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77705
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
π@cveNotify
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
π@cveNotify
WPScan
Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover
See details on Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover CVE 2026-77705. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77752
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
π@cveNotify
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.
π@cveNotify
WPScan
Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation
See details on Temporary Login Without Password 1.5 - 1.9.8 - Multisite Subsite Admin+ Network Super Admin Privilege Escalation CVE 2026-77752. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-77753
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
π@cveNotify
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.
π@cveNotify
WPScan
Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords
See details on Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypass via Application Passwords CVE 2026-77753. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-78152
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
π@cveNotify
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
π@cveNotify
WPScan
SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema
See details on SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema CVE 2026-78152. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-80491
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
WPScan
SAMO Forms <= 1.0.0 - Unauthenticated SQLi
See details on SAMO Forms <= 1.0.0 - Unauthenticated SQLi CVE 2026-80491. View the latest Plugin Vulnerabilities on WPScan.