π¨ CVE-2026-102910
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
GitHub
sourcecodester Online Reviewer Management System using PHP/MySQL V1.0 /reviewer_0/admins/assessments/examproper/exam-delete.phpβ¦
sourcecodester Online Reviewer Management System using PHP/MySQL V1.0 /reviewer_0/admins/assessments/examproper/exam-delete.php SQL injection NAME OF AFFECTED PRODUCT(S) Online Reviewer Management ...
π¨ CVE-2026-102911
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.
π@cveNotify
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.
π@cveNotify
GitHub
GitHub - zosmaai/pi-llm-wiki: Self-maintaining, Obsidian-compatible knowledge base for pi β turn raw sources into an interlinkedβ¦
Self-maintaining, Obsidian-compatible knowledge base for pi β turn raw sources into an interlinked wiki that compounds. Native Open Knowledge Format (OKF) v0.2. - zosmaai/pi-llm-wiki
π¨ CVE-2026-102912
A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
π@cveNotify
A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
π@cveNotify
GitHub
SourceCodester Online Leave Management System V1.0 index.php admin-page-reports GET date_end SQL Injection Β· Issue #1 Β· zhongzhicong1998/CVE
VulDB Submission Title (Title) SourceCodester Online Leave Management System V1.0 index.php admin-page-reports GET date_end SQL Injection Affected Product and Version Product Name: Online Leave Man...
π¨ CVE-2026-103110
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
π@cveNotify
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
π@cveNotify
π¨ CVE-2026-86134
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
π@cveNotify
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
π@cveNotify
π¨ CVE-2026-102913
A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
π@cveNotify
GitHub
SourceCodester Car Driving School Management System in PHP OOP Master.php save_enrollment Dynamic POST Field Name SQL Injectionβ¦
SourceCodester Car Driving School Management System in PHP OOP Master.php save_enrollment Dynamic POST Field Name SQL Injection NAME OF AFFECTED PRODUCT(S) Car Driving School Management System Vend...
π¨ CVE-2026-103111
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
π@cveNotify
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
π@cveNotify
GitHub
PCRE2: out-of-bounds write in JIT matching with large stack allocations
## PCRE2 maintainer report
### Summary
A regular expression can cause JIT-compiled matching to write outside the maximum memory area of a growable JIT stack. A sufficiently large single stack...
### Summary
A regular expression can cause JIT-compiled matching to write outside the maximum memory area of a growable JIT stack. A sufficiently large single stack...
π¨ CVE-2026-54812
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
π@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
π@cveNotify
Patchstack
SQL Injection in WordPress Motors Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-100143
The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.
π@cveNotify
The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.
π@cveNotify
WPScan
FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
See details on FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email CVE 2026-100143. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-75823
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.
This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.
π@cveNotify
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.
This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.
π@cveNotify
WPScan
WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
See details on WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption CVE 2026-75823. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-75824
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.
The created account receives the site's default role.
π@cveNotify
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.
The created account receives the site's default role.
π@cveNotify
WPScan
WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
See details on WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled CVE 2026-75824. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-75873
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
π@cveNotify
The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
π@cveNotify
WPScan
Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
See details on Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload CVE 2026-75873. View the latest Theme Vulnerabilities on WPScan.
π¨ CVE-2026-80333
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
π@cveNotify
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
π@cveNotify
WPScan
Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
See details on Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes CVE 2026-80333. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-82127
The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.
π@cveNotify
The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.
π@cveNotify
WPScan
Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
See details on Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields CVE 2026-82127. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-83560
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
π@cveNotify
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
π@cveNotify
WPScan
New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
See details on New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass CVE 2026-83560. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85001
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
π@cveNotify
WPScan
EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute
See details on EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute CVE 2026-85001. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85415
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
π@cveNotify
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
π@cveNotify
WPScan
Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
See details on Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL CVE 2026-85415. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85573
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
π@cveNotify
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.
π@cveNotify
WPScan
All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
See details on All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload CVE 2026-85573. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-85576
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
π@cveNotify
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
π@cveNotify
WPScan
All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
See details on All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update CVE 2026-85576. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-86789
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.
The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.
π@cveNotify
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.
The Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.
π@cveNotify
WPScan
Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
See details on Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes CVE 2026-86789. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-87777
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
π@cveNotify
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
π@cveNotify
WPScan
Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
See details on Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute CVE 2026-87777. View the latest Plugin Vulnerabilities on WPScan.