2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-66446 — Subscriber: SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66446

Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89VNDSubscriberTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-66436 — SQL: Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66436

Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 14:17Z
HIGH

CVE-2026-66430 — Subscriber: SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66430

Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-66424 — Privilege: Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66424

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 14:17Z
HIGH

CVE-2026-61979 — Privilege: Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61979

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 266TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-61969 — SQL: Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61969

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-61967 — Privilege: Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61967

Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 640TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-61966 — Subscriber: SQL Injection in WPJAM Basic <= 7.0.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61966

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89VNDSubscriberTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-61962 — Arbitrary: Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDArbitraryTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 14:17Z
HIGH

CVE-2026-28186 — Subscriber: Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28186

Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDSubscriberTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 14:17Z
CRIT

CVE-2026-28185 — Broken: Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28185

Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 345VNDBrokenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 14:17Z
HIGH

CVE-2026-28184 — Subscriber: SQL Injection in Form Maker by 10Web <= 1.15.44 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28184

Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 14:16Z
HIGH

CVE-2026-28176 — PHP: Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28176

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 14:16Z
HIGH

CVE-2026-28168 — Subscriber: SQL Injection in CubeWP <= 1.1.30 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28168

Subscriber SQL Injection in CubeWP <= 1.1.30 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 14:16Z
HIGH

CVE-2026-28161 — Subscriber: Privilege Escalation in Service Finder Booking <= 6.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28161

Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-13
2026-08-13 14:16Z
HIGH

CVE-2026-28156 — Subscriber: SQL Injection in Do Lasso <= 358 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28156

Subscriber SQL Injection in Do Lasso <= 358 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 14:16Z
CRIT

CVE-2026-28149 — PHP: Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28149

Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 14:16Z
CRIT

CVE-2026-28148 — Bypass: Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28148

Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDBypassTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 14:16Z
CRIT

CVE-2026-28142 — SQL: Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28142

Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 14:16Z
CRIT

CVE-2026-28008 — Broken: Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28008

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDBrokenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-13
2026-08-13 14:16Z
HIGH

CVE-2026-28002 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28002

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-13
2026-08-13 14:16Z
CRIT

CVE-2026-28001 — SQL: Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28001

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-13
2026-08-13 14:16Z
CRIT

CVE-2026-27544 — Code: Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27544

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-13
2026-08-13 14:16Z
HIGH

CVE-2026-27543 — Privilege: Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27543

Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 266TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-13
2026-08-13 13:19Z
HIGH

CVE-2026-6464 — Untrusted: data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6464

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attac CVSSv3.1 8.1 (HIGH)

CWECWE 829VNDUntrustedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score