8.1

CVSS3.1

CVE-2026-4021 - Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registrโ€ฆ

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email strinโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:25 p.m. ๐Ÿ”„ Last Modified: March 24, 2026, 6:43 p.m.

5.4

CVSS3.1

CVE-2026-4056 - User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Conโ€ฆ

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts`โ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:25 p.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:29 a.m.

8.8

CVSS3.1

CVE-2026-3533 - JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload โ€ฆ

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authenโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:25 p.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:29 a.m.

9.8

CVSS3.1

CVE-2026-4001 - Woocommerce Custom Product Addons Pro <= 5.4.1 - Unauthenticated Remote Code Execution via Custom Pโ€ฆ

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitizatioโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:25 p.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:29 a.m.

6.6

CVSS4.0

CVE-2026-33174 - Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the entire requested byte range into memory before sending it. A request wiโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:24 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

5.3

CVSS4.0

CVE-2026-33173 - Rails Active Storage has possible content type bypass via metadata in direct uploads

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like `identified` and `analyzed` are stored inโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:21 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

5.3

CVSS4.0

CVE-2026-33170 - Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a `SafeBuffer` is mutated in place (e.g. via `gsubโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:09 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

6.9

CVSS4.0

CVE-2026-33169 - Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, the interaction between โ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:07 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

6.9

CVSS4.0

CVE-2026-4613 - SourceCodester E-Commerce Site products.php sql injection

A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

๐Ÿ“… Published: March 23, 2026, 11:04 p.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:30 a.m.

2.3

CVSS4.0

CVE-2026-33168 - Rails has a possible XSS vulnerability in its Action View tag helpers

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully โ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:01 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.
Total resulsts: 340969
Page 141 of 34,097
ยซ previous page ยป next page
Filters