CVE ID :CVE-2026-8445 Published : Aug. 23, 2026, 2:16 p.m. | 10 hours, 17 minutes ago Description :justhtml versions are preserved, so untrusted input that is safe in to_html() — including entity-decoded text (e.g….
CVE-2026-7808 – justhtml before 1.16.0 Multiple Security Issues via Sanitization
CVE ID :CVE-2026-7808 Published : Aug. 23, 2026, 2:16 p.m. | 10 hours, 17 minutes ago Description :justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or…
CVE-2026-5388 – justhtml before 1.15.0 Multiple Security Issues
CVE ID :CVE-2026-5388 Published : Aug. 23, 2026, 2:16 p.m. | 10 hours, 17 minutes ago Description :justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True),…
CVE-2026-78155 – Untrusted Search Path in StackGres
CVE ID :CVE-2026-78155 Published : Aug. 23, 2026, 10:16 a.m. | 14 hours, 18 minutes ago Description :privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges…
CVE-2026-10053 – Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) in GitLab
CVE ID :CVE-2026-10053 Published : Aug. 23, 2026, 10:16 a.m. | 14 hours, 18 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before…
CVE-2026-78050 – Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow
CVE ID :CVE-2026-78050 Published : Aug. 23, 2026, 12:16 a.m. | 17 minutes ago Description :A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file…
CVE-2026-16149 – Security Hardener <= 2.4.4 – Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback Overwrite
CVE ID :CVE-2026-16149 Published : Aug. 23, 2026, 12:16 a.m. | 17 minutes ago Description :The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,…
CVE-2026-0551 – PPWP – Password Protect Pages <= 1.9.18 – Authenticated (Contributor+) PHP Object Injection via post_protection_roles
CVE ID :CVE-2026-0551 Published : Aug. 23, 2026, 12:16 a.m. | 17 minutes ago Description :The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions…
CVE-2026-78122 – docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
CVE ID :CVE-2026-78122 Published : Aug. 22, 2026, 11:16 p.m. | 1 hour, 18 minutes ago Description :docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment…
CVE-2026-4703 – WS Form LITE <= 1.10.80 – Unauthenticated PHP Object Injection via Form Submission
CVE ID :CVE-2026-4703 Published : Aug. 22, 2026, 4:16 p.m. | 8 hours, 18 minutes ago Description :The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to…