๐จ CVE-2026-62079
Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Qi Addons For Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-62080
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Happy Addons for Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-62081
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
๐@cveNotify
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
๐@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Flexible PDF Coupons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-62083
Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.
๐@cveNotify
Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.
๐@cveNotify
Patchstack
Other Vulnerability Type in WordPress Creator LMS Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-74864
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.
This issue was fixed in version 5.8.0~ynh9.
๐@cveNotify
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.
This issue was fixed in version 5.8.0~ynh9.
๐@cveNotify
cert.pl
Vulnerabilities in YunoHost-Apps sogo_yhn software
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-74864 and CVE-2026-74865) found in YunoHost-Apps sogo_yhn software.
๐จ CVE-2026-74865
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.
This issue was fixed in version 5.8.0~ynh9.
๐@cveNotify
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.
This issue was fixed in version 5.8.0~ynh9.
๐@cveNotify
cert.pl
Vulnerabilities in YunoHost-Apps sogo_yhn software
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-74864 and CVE-2026-74865) found in YunoHost-Apps sogo_yhn software.
๐จ CVE-2026-76504
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
๐@cveNotify
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
๐@cveNotify
Cisco
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
This vulnerability is due to improper handlingโฆ
This vulnerability is due to improper handlingโฆ
๐จ CVE-2026-86778
Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting.
This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
๐@cveNotify
Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting.
This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
๐@cveNotify
siberguvenlik.gov.tr
T.C. Siber Gรผvenlik Baลkanlฤฑฤฤฑ
Tรผrkiye Cumhuriyeti Cumhurbaลkanlฤฑฤฤฑ Siber Gรผvenlik Baลkanlฤฑฤฤฑ resmi web sitesi.
๐จ CVE-2026-89238
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
๐@cveNotify
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
๐@cveNotify
๐จ CVE-2026-92121
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.
๐@cveNotify
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.
๐@cveNotify
๐จ CVE-2026-92899
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
๐@cveNotify
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
๐@cveNotify
๐จ CVE-2026-93512
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JW Player for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-93514
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Notification for Telegram Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-93621
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
๐@cveNotify
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress WP Data Access Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-93624
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
๐@cveNotify
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Music Player for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-93651
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
๐@cveNotify
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Minimum and Maximum Quantity for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-93770
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Statistics Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-93771
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
๐@cveNotify
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Cost of Goods for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-94074
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-94076
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
๐@cveNotify
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress SEO Plugin by Squirrly SEO Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-94077
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
๐@cveNotify
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Safe SVG Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.