2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-49081 — Broken: Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49081

Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49080 — SQL: Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49080

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49079 — SQL: Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49079

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49076 — SQL: Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49076

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49075 — Contributor: PHP Object Injection in JetEngine <= 3.8.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49075

Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDContributorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-49073 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49073

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49058 — Privilege: Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49058

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-48967 — Subscriber: SQL Injection in Geo Mashup <= 1.13.19 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48967

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-48875 — SQL: Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48875

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-48788 — Remark42: Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48788

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an arbitrary remote URL and re-serves the response from Remark42's own origin. During the download phase, the proxy determines whether the resource is an image by inspecting only the Content-Type header adverti CVSSv3.1 8.2 (HIGH)

CWECWE 79CWECWE 436VNDRemark42TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-48781 — Postiz: In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48781

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, CVSSv3.1 9.9 (CRITICAL)

CWECWE 345CWECWE 863CWECWE 302VNDPostizTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-48745 — Traccar: In versions 9.7.19 and below, a single crafted deep link can silently hijack all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48745

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into t CVSSv3.1 9.3 (CRITICAL)

CWECWE 940VNDTraccarTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-48616 — Rocket: Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48616

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all CVSSv3.1 9.3 (CRITICAL)

CWECWE 284VNDRocketTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-48055 — Streambert: The application does not sanitize archive entry filenames during extraction, allowing a malicious archive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48055

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries CVSSv3.1 10.0 (CRITICAL)

CWECWE 22CWECWE 20VNDStreambertTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-42629 — Broken: Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42629

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 288VNDBrokenTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-42380 — PHP: Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42380

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-40783 — Contributor: Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40783

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40761 — PHP: Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40761

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40760 — PHP: Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40760

Unauthenticated PHP Object Injection in Behold <= 1.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40759 — PHP: Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40759

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40758 — PHP: Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40758

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40755 — PHP: Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40755

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40754 — PHP: Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40754

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40753 — PHP: Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40753

Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-40751 — PHP: Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40751

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score