CVE-2026-49763 — PHP: Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. CVSSv3.1 9.8 (CRITICAL)
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. CVSSv3.1 8.2 (HIGH)
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions. CVSSv3.1 8.1 (HIGH)
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. CVSSv3.1 8.5 (HIGH)
Subscriber Privilege Escalation in Amelia <= 2.3 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. CVSSv3.1 9.3 (CRITICAL)
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. CVSSv3.1 9.1 (CRITICAL)
Subscriber SQL Injection in GamiPress <= 7.8.7 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. CVSSv3.1 10.0 (CRITICAL)
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2). CVSSv3.1 8.6 (HIGH)
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. CVSSv3.1 8.2 (HIGH)
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. CVSSv3.1 9.3 (CRITICAL)
Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions. CVSSv3.1 8.1 (HIGH)
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. CVSSv3.1 9.3 (CRITICAL)