CVE ID :CVE-2026-80202 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or…
CVE-2026-80198 – Kimai before 2.56.0 Information Disclosure via config() Twig Function
CVE ID :CVE-2026-80198 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates,…
CVE-2026-80197 – Kimai before 2.57.0 Improper Authorization via Favorite Endpoints
CVE ID :CVE-2026-80197 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that…
CVE-2026-80196 – Kimai before 2.58.0 Authentication Bypass via Password Reset Link
CVE ID :CVE-2026-80196 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes…
CVE-2026-80195 – Kimai before 2.63.0 Team Membership Removal via API
CVE ID :CVE-2026-80195 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint…
CVE-2026-78284 – WordPress MasterStudy LMS plugin <= 3.7.42 – Arbitrary File Deletion vulnerability
CVE ID :CVE-2026-78284 Published : Aug. 24, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Unauthenticated Arbitrary File Deletion in MasterStudy LMS Severity: 8.6 | HIGH Visit the link for more details,…
CVE-2026-78267 – WordPress TranslatePress plugin <= 3.3.2 – Privilege Escalation vulnerability
CVE ID :CVE-2026-78267 Published : Aug. 24, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Unauthenticated Privilege Escalation in TranslatePress Severity: 9.8 | CRITICAL Visit the link for more details, such as…
CVE-2026-78265 – WordPress The Events Calendar plugin <= 6.17.2 – PHP Object Injection vulnerability
CVE ID :CVE-2026-78265 Published : Aug. 24, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Unauthenticated PHP Object Injection in The Events Calendar Severity: 9.8 | CRITICAL Visit the link for more…
CVE-2026-78262 – WordPress WP Project Manager plugin <= 4.0.6 – PHP Object Injection vulnerability
CVE ID :CVE-2026-78262 Published : Aug. 24, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Unauthenticated PHP Object Injection in WP Project Manager Severity: 9.8 | CRITICAL Visit the link for more…
CVE-2026-77337 – CakePHP: Potential Authentication bypass with CookieAuthenticator
CVE ID :CVE-2026-77337 Published : Aug. 24, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications….