6.1
CVE-2026-22202 - wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to tโฆ
6.9
CVE-2026-22201 - wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumveโฆ
6.9
CVE-2026-22199 - wpDiscuz before 7.6.47 - Vote Manipulation via Nonce Oracle and IP Rotation
wpDiscuz before 7.6.47 contains a vote manipulation vulnerability that allows attackers to manipulate comment votes by obtaining fresh nonces and bypassing rate limiting through client-controlled headers. Attackers can vary User-Agent headers to reset rate limits, request nonces from the unauthentiโฆ
9.2
CVE-2026-22193 - wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulatโฆ
6.3
CVE-2026-22192 - wpDiscuz before 7.6.47 - Stored Cross-Site Scripting via Malicious Options Import
wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by importing a crafted options file with unescaped customCss field values. Attackers can supply a malicious JSON import file containing script payloads in tโฆ
6.9
CVE-2026-22191 - wpDiscuz before 7.6.47 - Server-Side Shortcode Injection via Email Notifications
wpDiscuz before 7.6.47 contains a shortcode injection vulnerability that allows attackers to execute arbitrary shortcodes by including them in comment content sent via email notifications. Attackers can inject shortcodes like [contact-form-7] or [user_meta] in comments, which are executed server-siโฆ
5.3
CVE-2026-22183 - wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview
wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directโฆ
8.7
CVE-2026-22182 - wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id paโฆ
6.7
CVE-2026-4105 - Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a โฆ
5.4
CVE-2026-32612 - Statamic: privilege escalation via stored cross-site scripting
Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. Thโฆ