6.4

CVSS3.1

CVE-2026-5357 - Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeโ€ฆ

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. Tโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:25 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 4:16 p.m.

5.4

CVSS3.1

CVE-2026-4124 - Ziggeo <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'โ€ฆ

The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler only verifies a nonce (check_ajax_referer) but performs no capability checks via current_user_can(). Furthermore, the nonce ('ziggeo_ajax_nonce') is eโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:25 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 2:25 a.m.

4.8

CVSS4.0

CVE-2026-5833 - awwaiid mcp-server-taskwarrior index.ts server.setRequestHandler command injection

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been diโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:15 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 12:59 p.m.

6.9

CVSS4.0

CVE-2026-5832 - atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgerโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:25 a.m.

5.3

CVSS4.0

CVE-2026-5831 - Agions taskflow-ai terminal_execute handlers.ts os command injection

A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading tโ€ฆ

๐Ÿ“… Published: April 9, 2026, 1:45 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 1:45 p.m.

8.7

CVSS4.0

CVE-2026-5830 - Tenda AC15 SysToolChangePwd websGetVar stack-based overflow

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available anโ€ฆ

๐Ÿ“… Published: April 9, 2026, 1:30 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 2:54 p.m.

8.8

CVSS3.1

CVE-2026-4326 - Vertex Addons for Elementor <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitraโ€ฆ

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability checโ€ฆ

๐Ÿ“… Published: April 9, 2026, 1:25 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 1:25 a.m.

6.9

CVSS4.0

CVE-2026-5829 - code-projects Simple IT Discussion Forum content.php sql injection

A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly diโ€ฆ

๐Ÿ“… Published: April 9, 2026, 1:15 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 4:16 p.m.

6.9

CVSS4.0

CVE-2026-5828 - code-projects Simple IT Discussion Forum addcomment.php sql injection

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and cโ€ฆ

๐Ÿ“… Published: April 9, 2026, 1 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 1 a.m.

6.9

CVSS4.0

CVE-2026-5827 - code-projects Simple IT Discussion Forum question-function.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public andโ€ฆ

๐Ÿ“… Published: April 9, 2026, 12:45 a.m. ๐Ÿ”„ Last Modified: April 9, 2026, 12:45 a.m.
Total resulsts: 344055
Page 64 of 34,406
ยซ previous page ยป next page
Filters