0.0

CVE-2026-31924 - Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

📅 Published: April 14, 2026, 8:08 a.m. 🔄 Last Modified: April 14, 2026, 8:08 a.m.

0.0

CVE-2026-31908 - Apache APISIX: forward auth plugin allows header injection

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

📅 Published: April 14, 2026, 8:06 a.m. 🔄 Last Modified: April 14, 2026, 8:06 a.m.

4.3

CVSS3.1

CVE-2026-4109 - Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Autho…

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for …

📅 Published: April 14, 2026, 7:43 a.m. 🔄 Last Modified: April 14, 2026, 7:43 a.m.

6.5

CVSS3.1

CVE-2026-2582 - Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution

The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running …

📅 Published: April 14, 2026, 6:43 a.m. 🔄 Last Modified: April 14, 2026, 6:43 a.m.

7.2

CVSS3.1

CVE-2026-3017 - Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authentica…

The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticat…

📅 Published: April 14, 2026, 5:30 a.m. 🔄 Last Modified: April 14, 2026, 5:30 a.m.

6.4

CVSS3.1

CVE-2026-4059 - ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Sh…

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcode at…

📅 Published: April 14, 2026, 3:37 a.m. 🔄 Last Modified: April 14, 2026, 3:37 a.m.

4.4

CVSS3.1

CVE-2026-4479 - WholeSale Products Dynamic Pricing Management WooCommerce <= 1.2 - Authenticated (Administrator+) S…

The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…

📅 Published: April 14, 2026, 3:37 a.m. 🔄 Last Modified: April 14, 2026, 3:37 a.m.

6.4

CVSS3.1

CVE-2026-1607 - Surbma | Booking.com <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: April 14, 2026, 3:37 a.m. 🔄 Last Modified: April 14, 2026, 3:37 a.m.

9.1

CVSS3.1

CVE-2026-40313 - PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/checkout without setting persist-credentials: false. By default, actions/checkout writes the GITHUB_TOK…

📅 Published: April 14, 2026, 3:10 a.m. 🔄 Last Modified: April 14, 2026, 3:12 a.m.

9.1

CVSS3.1

CVE-2026-40289 - PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension ses…

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws WebSocket end…

📅 Published: April 14, 2026, 3:05 a.m. 🔄 Last Modified: April 14, 2026, 3:05 a.m.
Total resulsts: 344260
Page 2 of 34,426
« previous page » next page
Filters