2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-40733 — PHP: Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40733

Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39590 — File: Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39590

Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39576 — PHP: Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39576

Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39560 — PHP: Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39560

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39559 — File: Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39559

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39556 — PHP: Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39556

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39523 — File: Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39523

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39445 — PHP: Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39445

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2026-39442 — PHP: Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39442

Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69175 — File: Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69175

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69174 — File: Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69174

Unauthenticated Local File Inclusion in Etude <= 1.6 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69170 — File: Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69170

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69166 — File: Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69166

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69164 — File: Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69164

Unauthenticated Local File Inclusion in Skyward <= 1.10 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69158 — File: Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69158

Unauthenticated Local File Inclusion in Granola <= 1.13 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69157 — File: Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69157

Unauthenticated Local File Inclusion in Gamic <= 1.15 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69144 — File: Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69144

Unauthenticated Local File Inclusion in Preservation <= 1.10 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69130 — Subscriber: PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69130

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69128 — Limitation: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69128

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-69127 — PHP: Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69127

Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69126 — File: Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69126

Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69123 — File: Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69123

Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69120 — File: Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69120

Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69115 — File: Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69115

Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-69111 — PHP: Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69111

Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score