CVE Notify
19.6K subscribers
4 photos
338K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-6173
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

🎖@cveNotify
🚨 CVE-2026-6806
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

🎖@cveNotify
🚨 CVE-2026-88037
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

🎖@cveNotify
🚨 CVE-2026-92867
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

🎖@cveNotify
🚨 CVE-2026-92868
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.

🎖@cveNotify
🚨 CVE-2026-92869
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.

🎖@cveNotify
🚨 CVE-2026-92870
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

🎖@cveNotify
🚨 CVE-2026-92871
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

🎖@cveNotify
🚨 CVE-2026-92872
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.

🎖@cveNotify
🚨 CVE-2026-92873
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.

🎖@cveNotify
🚨 CVE-2026-93460
Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.

🎖@cveNotify
🚨 CVE-2026-93463
Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.

🎖@cveNotify
🚨 CVE-2026-93464
Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.

🎖@cveNotify
🚨 CVE-2026-97150
When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed.
Arbitrary files on the system may be read or deleted by an administrative user.

🎖@cveNotify
🚨 CVE-2025-14564
The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

🎖@cveNotify
🚨 CVE-2026-102454
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

🎖@cveNotify
🚨 CVE-2026-102455
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

🎖@cveNotify
🚨 CVE-2026-102456
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.

🎖@cveNotify
🚨 CVE-2026-102457
EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.

🎖@cveNotify
🚨 CVE-2026-102458
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.

🎖@cveNotify
🚨 CVE-2026-102459
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.

🎖@cveNotify