7.5
CVE-2026-21728 - Tempo query limit results in unbounded memory allocation
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18).
5.3
CVE-2026-3569 - Liaison Site Prober <= 1.2.1 - Missing Authorization to Unauthenticated Information Exposure in '/l…
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for …
6.4
CVE-2026-4078 - ITERAS <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-login, iteras-selfservice) in all versions up to and including 1.8.2. This is due to insufficient input sanitization and output escaping in the combin…
4.3
CVE-2026-3565 - Taqnix <= 1.0.3 - Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJA…
The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to a missing nonce verification in the taqnix_delete_my_account() function, where the check_ajax_referer() call is explicitly commented out on line 883. This makes it…
4.3
CVE-2025-11762 - HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authe…
The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contribu…
9.8
CVE-2026-1951 - No checking of the length of the buffer with the directory name in AS320T
Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.
9.8
CVE-2026-1952 - Denial of service via the undocumented subfunction in AS320T
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.
9.8
CVE-2026-1950 - No checking of the length of the buffer with the file name in AS320T
Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.
9.8
CVE-2026-1949 - Incorrect calculation of buffer size on the stack in AS320T
Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.
6.4
CVE-2026-5428 - Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Im…
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post(…