CVE-2026-81273 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. CVSSv3.1 9.8 (CRITICAL)
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. CVSSv3.1 8.5 (HIGH)
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. CVSSv3.1 9.1 (CRITICAL)
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. CVSSv3.1 9.3 (CRITICAL)
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. CVSSv3.1 8.8 (HIGH)
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a different entry, one the plugin's configured scope was meant to keep out of reach. This issue affects Apache APISIX: from 2.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. CVSSv3.1 8.1 (HIGH) · EPSS 41th percentile
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending on server configuration and how the metadata is later rendered or used, may res CVSSv3.1 9.6 (CRITICAL)
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. CVSSv3.1 9.8 (CRITICAL)
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. CVSSv3.1 8.5 (HIGH)
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. CVSSv3.1 8.6 (HIGH)
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin. CVSSv3.1 8.8 (HIGH)
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution. CVSSv3.1 8.8 (HIGH)
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server. CVSSv3.1 9.6 (CRITICAL)
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25 CVSSv3.1 9.4 (CRITICAL)
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE CVSSv3.1 9.8 (CRITICAL) · EPSS 9th percentile
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier CVSSv3.1 9.8 (CRITICAL)
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 CVSSv3.1 9.8 (CRITICAL)
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier CVSSv3.1 9.8 (CRITICAL)
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 CVSSv3.1 8.2 (HIGH)