2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49763 — PHP: Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49763

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49109 — PHP: Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49109

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49106 — PHP: Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <=

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49106

Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49105 — PHP: Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49105

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49104 — PHP: Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49104

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49085 — PHP: Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49085

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-49067 — SQL: Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49067

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-49065 — Broken: Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49065

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-48970 — Broken: Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48970

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 288VNDBrokenTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-48964 — Subscriber: SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48964

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-48889 — Subscriber: Privilege Escalation in Amelia <= 2.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48889

Subscriber Privilege Escalation in Amelia <= 2.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-48886 — SQL: Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48886

Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-48882 — Subscriber: SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48882

Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-48881 — Broken: Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48881

Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDBrokenTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-48874 — Subscriber: SQL Injection in GamiPress <= 7.8.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48874

Subscriber SQL Injection in GamiPress <= 7.8.7 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-48836 — Code: Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48836

Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDCodeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-15
2026-06-15 21:17Z
HIGH

CVE-2026-47825 — Spring: Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47825

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2). CVSSv3.1 8.6 (HIGH)

CWECWE 346VNDSpringTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 21:17Z
CRIT

CVE-2026-45439 — SQL: Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45439

Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-15
2026-06-15 21:16Z
HIGH

CVE-2026-42687 — PHP: Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42687

Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 21:16Z
CRIT

CVE-2026-42665 — SQL: Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42665

Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-15
2026-06-15 21:16Z
HIGH

CVE-2026-42664 — Broken: Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42664

Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1.38.2 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDBrokenTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 21:16Z
HIGH

CVE-2026-42661 — Custom: role Path Traversal in WP Customer Area <= 8.3.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42661

Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 35VNDCustomTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 21:16Z
CRIT

CVE-2026-42639 — SQL: Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42639

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-15
2026-06-15 21:16Z
HIGH

CVE-2026-42411 — Broken: Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42411

Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 288VNDBrokenTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 21:16Z
CRIT

CVE-2026-42386 — SQL: Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42386

Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score