1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-84795 — Craft: CMS before 5.10.11 fails to validate the admin flag during user registration, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84795

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled email verification are configured. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDCraftTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84770 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84770

Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-84764 — Site: Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84764

Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-81772 — PHP: Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81772

Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-81769 — Incorrect: Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81769

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. CVSSv3.1 8.8 (HIGH)

CWECWE 266TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-81294 — Privilege: Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81294

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 12:17Z
CRIT

CVE-2026-81286 — SQL: Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81286

Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-02 12:17Z
HIGH

CVE-2026-81283 — Subscriber: PHP Object Injection in WP User Frontend <= 4.3.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81283

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 11:17Z
HIGH

CVE-2026-19219 — AJAX: In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19219

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 434CWECWE 345VNDAjaxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-02 08:16Z
HIGH

CVE-2026-14828 — Zohocorp: ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14828

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDZohocorpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-82183 — OAuth: The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82183

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDOauthTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-81807 — Simple: The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81807

The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDSimpleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-81737 — FAQ: The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81737

The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing it and outputting it in an admin area page, and the escaping it does apply is undone by a subsequent decoding step, leading to Stored XSS which will execute in the context of a logged in administrator. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDFaqTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-80467 — Advanced: The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80467

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator. CVSSv3.1 8.1 (HIGH)

CWECWE 269VNDAdvancedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-02 06:17Z
CRIT

CVE-2026-78657 — SigmaForms: The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78657

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The malicious path traversal URL is submitted via form CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDSigmaformsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-19116 — User: The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19116

The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-14357 — DevKit: The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14357

The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary theme ZIP packages containing PHP files that are extracted into the web-accessibl CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDevkitTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 06:17Z
HIGH

CVE-2026-12526 — Advanced: The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12526

The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing administrator (a fixed target, or one mapped to a visitor-submitted field) and map CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDAdvancedTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-02 05:17Z
CRIT

CVE-2026-9055 — Booking: The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9055

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticate CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDBookingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-02 05:17Z
HIGH

CVE-2024-35585 — Oxford: Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2024-35585

Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDOxfordTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-09-02 03:16Z
HIGH

CVE-2026-14982 — File: The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14982

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The two-stage exploit requires a first request to the file.save task to persist CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-02 02:17Z
HIGH

CVE-2026-84715 — FeatherPanel: A subuser with minimal permissions can send a crafted request to grant themselves full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84715

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDFeatherpanelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 01:17Z
HIGH

CVE-2026-84700 — PikiwiDB: (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84700

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates it; the frame dispatcher (DealMessage) does not require a completed or attempted CVSSv3.1 8.6 (HIGH)

CWECWE 306VNDPikiwidbTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2w ago
2026-09-02 01:17Z
CRIT

CVE-2026-84699 — Team: Unauthenticated attackers can reset local account passwords and authenticate as those users to gain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84699

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. CVSSv3.1 9.1 (CRITICAL)

CWECWE 640VNDTeamTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-09-02 01:17Z
HIGH

CVE-2026-84696 — Phison: Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84696

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDPhisonTYPVulnerability
8.2
CVSS v3.1
91
Edit Score