Skip to content

Menu
  • Home
Menu

CVE-2026-82901 – Ultra Addons for Contact Form 7 <= 3.5.50 – Unauthenticated Arbitrary File Upload via Signature Form Field

Posted on September 27, 2026

CVE ID :CVE-2026-82901 Published : Sept. 26, 2026, 7:16 p.m. | 5 hours, 3 minutes ago Description :The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due…

CVE-2026-85984 – miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 – Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter

Posted on September 27, 2026

CVE ID :CVE-2026-85984 Published : Sept. 26, 2026, 6:16 p.m. | 6 hours, 3 minutes ago Description :The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via…

CVE-2026-77203 – Groups <= 4.6.0 – Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode

Posted on September 27, 2026

CVE ID :CVE-2026-77203 Published : Sept. 26, 2026, 6:16 p.m. | 6 hours, 3 minutes ago Description :The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all…

CVE-2026-97163 – Joomla Extension – lomart.fr – Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Posted on September 27, 2026

CVE ID :CVE-2026-97163 Published : Sept. 26, 2026, 3:16 p.m. | 9 hours, 3 minutes ago Description :Joomla Extension – lomart.fr – Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 10.0…

CVE-2026-97162 – Joomla Extension – lomart.fr – Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Posted on September 27, 2026

CVE ID :CVE-2026-97162 Published : Sept. 26, 2026, 3:16 p.m. | 9 hours, 3 minutes ago Description :Joomla Extension – lomart.fr – Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 8.3…

CVE-2026-96795 – Horilla: Authenticated RCE in Horilla List-View Export

Posted on September 26, 2026

CVE ID :CVE-2026-96795 Published : Sept. 25, 2026, 11:16 p.m. | 57 minutes ago Description :Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user’s columns…

CVE-2026-71483 – Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View

Posted on September 26, 2026

CVE ID :CVE-2026-71483 Published : Sept. 25, 2026, 10:18 p.m. | 1 hour, 55 minutes ago Description :Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected…

CVE-2026-100501 – Flame through 2.4.0 Brute-Force Attack via Login Endpoint

Posted on September 26, 2026

CVE ID :CVE-2026-100501 Published : Sept. 25, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login…

CVE-2026-100382 – Unauthenticated remote code execution through wikitext in ExternalData

Posted on September 26, 2026

CVE ID :CVE-2026-100382 Published : Sept. 25, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Wikimedia Foundation…

CVE-2026-100391 – MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation

Posted on September 26, 2026

CVE ID :CVE-2026-100391 Published : Sept. 25, 2026, 9:17 p.m. | 2 hours, 56 minutes ago Description :MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing…

Posts pagination

1 2 … 153 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme