8.3
CVE-2026-2751 - Blind SQL Injection
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.
8.4
CVE-2026-3223 - Zip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web Designer
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
6.3
CVE-2025-11950 - Reflected XSS in Knowhy's EduAsist
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Advanced Technology Trading Ltd. Co. EduAsist allows Reflected XSS.This issue affects EduAsist: before v2.1.
9.8
CVE-2025-11252 - SQLi in Signum Technologies' windesk.fm
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: before v2.3.4.ย NOTE:ย The vendor patched the vulnerability after the CVE was published.
9.8
CVE-2025-11251 - SQLi in Dayneks Software's E-Commerce Platform
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection.This issue affects E-Commerce Platform: through 27022026. NOTE: The vendor was contacted early about this disclosuโฆ
4.8
CVE-2026-24352 - Session Fixation in PluXml CMS
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this โฆ
5.1
CVE-2026-24351 - Stored XSS in PluXml CMS
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with tโฆ
5.1
CVE-2026-24350 - Stored XSS in PluXml CMS
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the uploaded image. In versionย 5.9.0-rc7 clicking the link associated with thโฆ
4.9
CVE-2026-2831 - MailArchiver <= 4.5.0 - Authenticated (Admininistrator+) SQL Injection via 'logid' Parameter
The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the โlogidโ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticaโฆ
5.1
CVE-2026-1434 - Reflected XSS in Omega-PSIR
Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victimโs browser. This issue was fixed in 4.6.7.