2026-07-11
2026-07-11 10:16Z
HIGH

CVE-2026-57828 — Phoca Download: The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57828

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 434VNDJoomlaVNDPhocaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 10:16Z
CRIT

CVE-2026-57827 — Rsjoomla Rsfiles\!: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57827

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. CVSSv3.1 9.8 (CRITICAL) · EPSS 21th percentile

CWECWE 434VNDJoomlaVNDRsjoomlaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-11
2026-07-11 09:16Z
HIGH

CVE-2026-1359 — Genolve: The Genolve – AI image AI video generation plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1359

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDGenolveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 07:16Z
HIGH

CVE-2026-15155 — Essential: The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15155

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does n CVSSv3.1 8.8 (HIGH)

CWECWE 640VNDEssentialTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 07:16Z
HIGH

CVE-2025-6784 — Code: The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-6784

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restricting access to the code injecting functionality of the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 77VNDCodeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 06:16Z
HIGH

CVE-2026-7655 — SureCart: The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7655

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart cu CVSSv3.1 8.1 (HIGH)

CWECWE 640VNDSurecartTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-11
2026-07-11 05:16Z
HIGH

CVE-2026-2354 — Swiss: The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2354

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's `wp_check_filetype_and_ext` filter and uses `strpos()` to check if a filename contains a configured extension string, rather than verifying the actual file extension. This makes it possible for authen CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDSwissTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-11
2026-07-11 05:16Z
HIGH

CVE-2026-14262 — Simple: The Simple JWT Login – Allows you to use JWT on REST endpoints.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14262

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` only overwrites JWT payload keys whose names appear in the admin-configured `jwt_payload` list — leaving any attacker-supplied identity claims such as `email`, `id`, or `username` intac CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDSimpleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 04:17Z
HIGH

CVE-2026-13353 — Ultimate: The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML &

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13353

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and StartImport, combined with the plugin nonce being exposed to any authenticated user who can load an admin page, allowing a Subscriber to install the Import WooCo CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDUltimateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 02:16Z
HIGH

CVE-2026-13756 — Grid: The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13756

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator by updating their own `wp_capabilities` user meta with a crafted nested array pay CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDGridTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-11
2026-07-11 00:32Z
HIGH

Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit

Rapid7 Research·rapid7.comCVE-2026-41264CVE-2024-27822

Rapid7 released Metasploit Framework 6.4.143 with three new exploit modules: a prompt-injection RCE for FlowiseAI CSV Agent (CVE-2026-41264) affecting versions 1.3.0–3.0.13, a local privilege escalation for macOS PackageKit via ZSH environment inheritance (CVE-2024-27822), and an Apache .htaccess persistence module. The update also includes framework enhancements for FTP fingerprinting, Kerberos tracing granularity, and bug fixes for AARCH64 Windows payload generation and RBCD module ACE removal.

SRFApplicationTACTA0004TACTA0002SRFWebOSLinuxOSMacosSWMetasploitSWFlowise
72
Edit Score
2026-07-10
2026-07-10 23:16Z
CRIT

CVE-2026-20744 — The charging station websocket endpoint accepts connections without proper authentication, which could lead to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20744

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 23:16Z
CRIT

CVE-2026-15089 — Drupal: vulnerability in Drupal Commerce guest registration allows .

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15089

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. CVSSv3.1 9.1 (CRITICAL) · EPSS 15th percentile

CWECWE 287VNDDrupalTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 23:16Z
CRIT

CVE-2026-14480 — OpenPLC: Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14480

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without validating or restricting the path. Because Python os.path.join() honors attacker‑controlled absolute paths, an authenticated user can write arbitrary files CVSSv3.1 9.9 (CRITICAL)

CWECWE 73VNDOpenplcTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-10
2026-07-10 23:16Z
CRIT

CVE-2026-11913 — Drupal: vulnerability in Drupal Mother May I allows .

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11913

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

CWECWE 79VNDDrupalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-55810 — Improperly: Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55810

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2. CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

CWECWE 915VNDImproperlyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-55809 — Improperly: Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55809

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 915VNDImproperlyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
HIGH

CVE-2026-52747 — ModSecurity: Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52747

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSe CVSSv3.1 8.6 (HIGH)

CWECWE 180VNDModsecurityTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-10
2026-07-10 22:16Z
HIGH

CVE-2026-49213 — TypeBot: Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49213

TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because validateIPAddress blocks local, metadata, and private ranges but does not block :: or its expanded form. A workspace editor or creator can configure a server-side HTTP Request block or guarded script fetch to make the Typebot server connect to local HTTP services through safeKy, includin CVSSv3.1 8.1 (HIGH)

CWECWE 918VNDTypebotTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 22:16Z
HIGH

CVE-2026-44795 — Spinnaker: Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44795

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3. CVSSv3.1 8.8 (HIGH)

CWECWE 502CWECWE 470VNDSpinnakerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 22:16Z
HIGH

CVE-2026-15080 — Site: Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15080

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4. CVSSv3.1 8.8 (HIGH) · EPSS 2th percentile

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 22:16Z
HIGH

CVE-2026-13244 — Improperly: Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13244

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0. CVSSv3.1 8.1 (HIGH) · EPSS 34th percentile

CWECWE 915VNDImproperlyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13243 — Site: Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13243

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. CVSSv3.1 9.8 (CRITICAL) · EPSS 1th percentile

CWECWE 352TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13241 — Authorization: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13241

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 22:16Z
CRIT

CVE-2026-13240 — Authorization: Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13240

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score