9.3

CVSS4.0

CVE-2026-3826 - WellChoose|IFTOP - Local File Inclusion

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

📅 Published: March 11, 2026, 6:38 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

5.1

CVSS4.0

CVE-2026-3825 - WellChoose|IFTOP - Reflected Cross-site Scripting

IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

📅 Published: March 11, 2026, 6:35 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

8.7

CVSS4.0

CVE-2026-31844 - Authenticated SQL Injection in Koha displayby parameter of suggestion.pl

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL que…

📅 Published: March 11, 2026, 6:34 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

5.1

CVSS4.0

CVE-2026-3824 - WellChoose|IFTOP - Open redirect

IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

📅 Published: March 11, 2026, 6:31 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

9.8

CVSS3.1

CVE-2026-2631 - Datalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege Escalation

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perfor…

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

8.1

CVSS3.1

CVE-2026-2626 - Divi Booster < 5.0.2 - Unauthenticated PHP Object Injection

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be furth…

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

7.1

CVSS3.1

CVE-2026-2466 - DukaPress <= 3.2.4 - Reflected XSS

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

5.9

CVSS3.1

CVE-2026-1867 - WP Front User Submit < 5.0.6 - Unauthenticated Sensitive Information Exposure

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posti…

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

6.8

CVSS3.1

CVE-2026-1753 - Gutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options Update

The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors and above role to update arbitrary boolean and array options (such as users_can_register).

📅 Published: March 11, 2026, 6 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.

2.7

CVSS3.1

CVE-2026-3911 - Org.keycloak.services.resources.admin.userresource: keycloak: information disclosure of disabled us…

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized informa…

📅 Published: March 11, 2026, 5:36 a.m. 🔄 Last Modified: March 12, 2026, 10:06 a.m.
Total resulsts: 337543
Page 29 of 33,755
« previous page » next page
Filters