5.3

CVSS4.0

CVE-2026-1440 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker โ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 1:13 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 10:20 a.m.

5.3

CVSS4.0

CVE-2026-1439 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker โ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 1:13 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 10:20 a.m.

5.3

CVSS4.0

CVE-2026-1438 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker โ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 1:13 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 10:20 a.m.

5.3

CVSS4.0

CVE-2026-1437 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker โ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 1:12 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 10:20 a.m.

7.1

CVSS4.0

CVE-2026-1436 - Improper Access Control (IDOR) vulnerability in Graylog Web Interface

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be listed and sensitiveโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 1:09 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 10:20 a.m.

9.3

CVSS4.0

CVE-2026-1435 - Incorrect management of session invalidation vulnerability in Graylog Web Interface

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, whโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 1:08 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 10:20 a.m.

6.5

CVSS3.1

CVE-2026-1317 - WP Import โ€“ Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injecโ€ฆ

The WP Import โ€“ Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is stored in the database during file upload and later used in raw SQL querโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:34 p.m.

3.7

CVSS3.1

CVE-2026-1582 - WP All Export <= 1.4.14 - Unauthenticated Sensitive Information Exposure via PHP Type Juggling

The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security token comparison which uses loose comparison (==) instead of strict โ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:11 p.m.

4.3

CVSS3.1

CVE-2026-2386 - The Plus Addons for Elementor โ€“ Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerโ€ฆ

The The Plus Addons for Elementor โ€“ Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 6.4.7. This is due to the tpae_create_page() AJAX handler authorizing users only with currentโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:52 p.m.

4.9

CVSS3.1

CVE-2025-8781 - Bookster โ€“ WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injecโ€ฆ

The Bookster โ€“ WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the โ€˜rawโ€™ parameter in all versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thisโ€ฆ

๐Ÿ“… Published: Feb. 18, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:41 p.m.
Total resulsts: 343944
Page 1071 of 34,395
ยซ previous page ยป next page
Filters