CVE-2026-66447 — SQL: Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Agora <= 1.9 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. CVSSv3.1 8.1 (HIGH)
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. CVSSv3.1 10.0 (CRITICAL)
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. CVSSv3.1 9.8 (CRITICAL)
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. CVSSv3.1 9.9 (CRITICAL)
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. CVSSv3.1 9.8 (CRITICAL)
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell CVSSv3.1 9.1 (CRITICAL)
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH pri CVSSv3.1 9.1 (CRITICAL)