4.8

CVSS4.0

CVE-2026-6003 - code-projects Simple IT Discussion Forum user.php cross site scripting

A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been di…

📅 Published: April 10, 2026, 2:15 a.m. 🔄 Last Modified: April 10, 2026, 2:15 a.m.

5.3

CVSS4.0

CVE-2026-6000 - code-projects Online Library Management System SQL Database Backup File library.sql information dis…

A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exp…

📅 Published: April 10, 2026, 2 a.m. 🔄 Last Modified: April 10, 2026, 2 a.m.

5.3

CVSS4.0

CVE-2026-5999 - JeecgBoot SysAnnouncementController improper authorization

A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor conf…

📅 Published: April 10, 2026, 1:45 a.m. 🔄 Last Modified: April 10, 2026, 1:45 a.m.

6.9

CVSS4.0

CVE-2026-5998 - zhayujie chatgpt-on-wechat CowAgent API Memory Content Endpoint service.py dispatch path traversal

A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The …

📅 Published: April 10, 2026, 1:30 a.m. 🔄 Last Modified: April 10, 2026, 1:30 a.m.

6.1

CVSS3.1

CVE-2026-4305 - Royal WordPress Backup & Restore Plugin <= 1.0.16 - Reflected Cross-Site Scripting via 'wpr_pending…

The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject…

📅 Published: April 10, 2026, 1:25 a.m. 🔄 Last Modified: April 10, 2026, 1:25 a.m.

4.3

CVSS3.1

CVE-2026-4977 - UsersWP <= 1.2.58 - Authenticated (Subscriber+) Restricted Usermeta Modification via 'htmlvar' Para…

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation in the upload_file_remove() AJAX handler w…

📅 Published: April 10, 2026, 1:25 a.m. 🔄 Last Modified: April 10, 2026, 1:25 a.m.

4.3

CVSS3.1

CVE-2026-1924 - Aruba HiSpeed Cache <= 3.0.4 - Cross-Site Request Forgery to Plugin Settings Reset

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the `ahsc_ajax_reset_options()` function. This makes it possible for unauthenticated attackers to reset all plugin setti…

📅 Published: April 10, 2026, 1:24 a.m. 🔄 Last Modified: April 10, 2026, 1:24 a.m.

8.1

CVSS3.1

CVE-2026-4351 - Perfmatters <= 2.5.9 - Authenticated (Subscriber+) Arbitrary File Overwrite via 'snippets' Parameter

The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` handlers without any authorization check or nonce veri…

📅 Published: April 10, 2026, 1:24 a.m. 🔄 Last Modified: April 10, 2026, 1:24 a.m.

6.4

CVSS3.1

CVE-2026-1263 - Webling <= 3.9.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'title' Parameter

The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.0 due to insufficient input sanitization, insufficient output escaping, and missing capabilities checks in the 'webling_admin_save_form' and 'webling_admin_save_memberlist' functi…

📅 Published: April 10, 2026, 1:24 a.m. 🔄 Last Modified: April 10, 2026, 1:24 a.m.

4.3

CVSS3.1

CVE-2026-4057 - Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Prote…

The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capa…

📅 Published: April 10, 2026, 1:24 a.m. 🔄 Last Modified: April 10, 2026, 1:24 a.m.
Total resulsts: 343746
Page 6 of 34,375
« previous page » next page
Filters