2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-39539 — PHP: Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39539

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-39537 — File: Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39537

Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-39529 — PHP: Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39529

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-39522 — File: Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39522

Unauthenticated Local File Inclusion in Solene <= 3.4 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-39446 — PHP: Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39446

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-39443 — PHP: Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39443

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-39438 — SQL: Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39438

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-34895 — File: Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34895

Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-34894 — File: Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34894

Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-34893 — File: Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34893

Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-32967 — Apache Dolphinscheduler: Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-32966 — Apache Dolphinscheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDApacheVNDDatasourceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-27429 — PHP: Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27429

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-27400 — Arbitrary: Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27400

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 22VNDArbitraryTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-27395 — Privilege: Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27395

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-27041 — Contributor: Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27041

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDContributorTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-25470 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) -

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25470

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-25446 — Subscriber: Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25446

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-25439 — Broken: Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25439

Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 288VNDBrokenTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-24611 — Broken: Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24611

Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDBrokenTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22343 — Broken: Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22343

Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. CVSSv3.1 8.6 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22342 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22342

Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-22340 — SQL: Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22340

Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22338 — File: Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22338

Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22335 — Subscriber: SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22335

Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score