5.1

CVSS4.0

CVE-2026-35496 -

A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should not be accessible.

📅 Published: April 17, 2026, 4:33 a.m. 🔄 Last Modified: April 17, 2026, 4:33 a.m.

5.1

CVSS4.0

CVE-2026-34018 -

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

📅 Published: April 17, 2026, 4:33 a.m. 🔄 Last Modified: April 17, 2026, 4:33 a.m.

8.6

CVSS4.0

CVE-2026-21719 -

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.

📅 Published: April 17, 2026, 4:33 a.m. 🔄 Last Modified: April 17, 2026, 4:33 a.m.

5.3

CVSS3.1

CVE-2026-5502 - Tutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_up…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The function only validates th…

📅 Published: April 17, 2026, 3:36 a.m. 🔄 Last Modified: April 17, 2026, 3:36 a.m.

5.3

CVSS3.1

CVE-2026-5427 - Kubio AI Page Builder <= 2.7.2 - Missing Authorization to Authenticated (Contributor+) Limited File…

The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets() function, which is hooked to the rest_pre_insert_{post_type} filter for posts, pages, templates, an…

📅 Published: April 17, 2026, 3:36 a.m. 🔄 Last Modified: April 17, 2026, 3:36 a.m.

5.3

CVSS3.1

CVE-2026-5234 - LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data E…

The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no authentication required…

📅 Published: April 17, 2026, 3:36 a.m. 🔄 Last Modified: April 17, 2026, 3:36 a.m.

6.5

CVSS3.1

CVE-2026-6080 - Tutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' Parameter

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolation into a SQL fragment before being passed to $wpdb->prepare(). This makes it possible for authentica…

📅 Published: April 17, 2026, 3:36 a.m. 🔄 Last Modified: April 17, 2026, 3:36 a.m.

4.9

CVSS3.1

CVE-2026-3330 - Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Param…

The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslas…

📅 Published: April 17, 2026, 3:36 a.m. 🔄 Last Modified: April 17, 2026, 3:36 a.m.

4.9

CVSS3.1

CVE-2026-4853 - JetBackup <= 3.1.19.8 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traver…

The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insufficient input validation on the fileName parameter in the file upload handler. The plugin sanitizes th…

📅 Published: April 17, 2026, 3:36 a.m. 🔄 Last Modified: April 17, 2026, 3:36 a.m.

7.5

CVSS3.1

CVE-2026-5807 - Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability…

📅 Published: April 17, 2026, 3:22 a.m. 🔄 Last Modified: April 17, 2026, 3:22 a.m.
Total resulsts: 344963
Page 2 of 34,497
« previous page » next page
Filters