1w ago
2026-09-02 15:17Z
CRIT

CVE-2026-4357 — Embed: The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4357

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDEmbedTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-02 15:17Z
CRIT

CVE-2025-9314 — Developer: The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-9314

The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDDeveloperTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 15:17Z
HIGH

CVE-2025-15485 — Auto: The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-15485

The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDAutoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 14:54Z
INFO

v9.7.0-rc3

BloodHound releases·github.com

BloodHound v9.7.0-rc3 release candidate published with minor updates: npm Browserslist dependency bumped to 4.28.8 for a security vulnerability, and UI color token adjustments for contrast compliance.

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
1w ago
2026-09-02 13:18Z
CRIT

CVE-2026-73475 — Incorrect: Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73475

Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. CVSSv3.1 9.1 (CRITICAL)

CWECWE 863TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-84803 — SiYuan: before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84803

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces. CVSSv3.1 9.0 (CRITICAL)

CWECWE 79VNDSiyuanTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84801 — Craft: CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84801

Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the verification code without checking the caller's session, enabling complete control-panel takeover. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84796 — Craft: CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84796

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across unauthorized sites by passing siteId directly in mutation arguments. CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-84795 — Craft: CMS before 5.10.11 fails to validate the admin flag during user registration, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84795

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDCraftTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84770 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84770

Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84764 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84764

Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-81772 — PHP: Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81772

Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-81769 — Incorrect: Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81769

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-81294 — Privilege: Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81294

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-81286 — SQL: Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81286

Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-81283 — Subscriber: PHP Object Injection in WP User Frontend <= 4.3.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81283

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 11:17Z
HIGH

CVE-2026-19219 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19219

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 434CWECWE 345VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 08:16Z
HIGH

CVE-2026-14828 — Zohocorp: ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14828

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDZohocorpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-82183 — OAuth: The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82183

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDOauthTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-81807 — Simple: The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81807

The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDSimpleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-81737 — FAQ: The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81737

The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDFaqTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-80467 — Advanced: The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80467

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator. CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDAdvancedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 06:17Z
CRIT

CVE-2026-78657 — SigmaForms: The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78657

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The malicious path traversal URL is submitted via form CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDSigmaformsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-19116 — User: The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19116

The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 06:17Z
HIGH

CVE-2026-14357 — DevKit: The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14357

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessibl CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDevkitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score