7.5

CVSS3.1

CVE-2026-1557 - WP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via src

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 11:45 p.m.

6.1

CVSS3.1

CVE-2026-2506 - EM Cost Calculator <= 2.3.1 - Unauthenticated Stored Cross-Site Scripting via 'customer_name'

The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to the plugin storing attacker-controlled 'customer_name' data and rendering it in the admin customer list without output escaping. This makes it possible foโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 8:15 p.m.

2.7

CVSS4.0

CVE-2026-27942 - fast-xml-parser has stack overflow in XMLBuilder with preserveOrder

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. Asโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:22 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

10

CVSS3.1

CVE-2026-27941 - OpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target`โ€ฆ

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security contexโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:17 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

7.7

CVSS3.1

CVE-2026-27938 - WPGraphQL Repo Vulnerable to Command Injection via Unsanitized GitHub Actions Expression in Releaseโ€ฆ

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:10 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

7.5

CVSS3.1

CVE-2026-27904 - minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:07 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

7.5

CVSS3.1

CVE-2026-27903 - minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segโ€ฆ

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:06 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

5.3

CVSS4.0

CVE-2026-27902 - Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes theโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 12:58 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7:45 p.m.

5.3

CVSS4.0

CVE-2026-27901 - Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial vโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 12:57 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

6.9

CVSS4.0

CVE-2026-27887 - Spin has memory leaks in various WIT interfaces

Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in soโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 12:55 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.
Total resulsts: 347303
Page 1241 of 34,731
ยซ previous page ยป next page
Filters