5.3

CVSS3.1

CVE-2026-3335 - Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload

The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file being directly accessible without any authentication, authorization, or nonce checks, and t…

πŸ“… Published: March 21, 2026, 3:26 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.

5.3

CVSS3.1

CVE-2026-3570 - Smarter Analytics <= 2.0 - Missing Authorization to Unauthenticated Plugin Settings Reset via 'rese…

The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for un…

πŸ“… Published: March 21, 2026, 3:26 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.

8.8

CVSS3.1

CVE-2026-3334 - CMS Commander <= 2.288 - Authenticated (Custom+) SQL Injection via 'or_blogname' Parameter

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on …

πŸ“… Published: March 21, 2026, 3:26 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.

7.2

CVSS3.1

CVE-2026-2279 - myLinksDump <= 1.6 - Authenticated (Administrator+) SQL Injection via 'sort_by' and 'sort_order' Pa…

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl…

πŸ“… Published: March 21, 2026, 3:26 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.

7.2

CVSS3.1

CVE-2026-4302 - WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' P…

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that…

πŸ“… Published: March 21, 2026, 1:24 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.

5.3

CVSS4.0

CVE-2026-32899 - OpenClaw < 2026.2.25 - Sender Policy Bypass in Slack Reaction and Pin Event Handlers

OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowlists to inject unauthorized reaction and pin events from res…

πŸ“… Published: March 21, 2026, 12:42 a.m. πŸ”„ Last Modified: March 24, 2026, 9:06 p.m.

5.3

CVSS4.0

CVE-2026-32898 - OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata

OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive approval prompts for read-class operations by spoofing tool m…

πŸ“… Published: March 21, 2026, 12:42 a.m. πŸ”„ Last Modified: March 24, 2026, 9:07 p.m.

6.3

CVSS4.0

CVE-2026-32897 - OpenClaw < 2026.2.22 - Authentication Token Reuse in Owner ID Prompt Hashing Fallback

OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-use of authentication secrets across security domains. Attackers with access to s…

πŸ“… Published: March 21, 2026, 12:42 a.m. πŸ”„ Last Modified: March 24, 2026, 9:07 p.m.

6.3

CVSS4.0

CVE-2026-32896 - OpenClaw < 2026.2.21 - Unauthenticated Webhook Access via Passwordless Fallback in BlueBubbles Plug…

OpenClaw versions prior to 2026.2.21 BlueBubbles webhook handler contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heu…

πŸ“… Published: March 21, 2026, 12:42 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.

5.3

CVSS4.0

CVE-2026-32895 - OpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event Handlers

OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allowlists by sending system events from non-allowlisted senders …

πŸ“… Published: March 21, 2026, 12:42 a.m. πŸ”„ Last Modified: March 25, 2026, 2:42 p.m.
Total resulsts: 340382
Page 125 of 34,039
Β« previous page Β» next page
Filters