CVE-2026-49081 — Broken: Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. CVSSv3.1 9.3 (CRITICAL)
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. CVSSv3.1 9.8 (CRITICAL)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3. CVSSv3.1 8.5 (HIGH)
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. CVSSv3.1 9.8 (CRITICAL)
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. CVSSv3.1 9.3 (CRITICAL)
Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an arbitrary remote URL and re-serves the response from Remark42's own origin. During the download phase, the proxy determines whether the resource is an image by inspecting only the Content-Type header adverti CVSSv3.1 8.2 (HIGH)
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, CVSSv3.1 9.9 (CRITICAL)
Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into t CVSSv3.1 9.3 (CRITICAL)
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all CVSSv3.1 9.3 (CRITICAL)
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries CVSSv3.1 10.0 (CRITICAL)
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. CVSSv3.1 9.8 (CRITICAL)
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. CVSSv3.1 9.9 (CRITICAL)
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Behold <= 1.5 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. CVSSv3.1 8.1 (HIGH)