CVE-2026-39539 — PHP: Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated Local File Inclusion in Solene <= 3.4 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. CVSSv3.1 8.1 (HIGH)
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. CVSSv3.1 9.1 (CRITICAL)
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions. CVSSv3.1 8.6 (HIGH)
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. CVSSv3.1 9.8 (CRITICAL)
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. CVSSv3.1 9.9 (CRITICAL)
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47. CVSSv3.1 10.0 (CRITICAL)
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. CVSSv3.1 9.9 (CRITICAL)
Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. CVSSv3.1 9.1 (CRITICAL)
Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. CVSSv3.1 8.6 (HIGH)
Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions. CVSSv3.1 8.1 (HIGH)
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. CVSSv3.1 8.5 (HIGH)