7.8
CVE-2026-3779 - Foxit PDF Editor/Reader List Box Calculate Array Use-After-Free Vulnerability
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
5.5
CVE-2026-3777 - Use after free of view cache in Foxit PDF Editor/Reader
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers arβ¦
7.1
CVE-2026-4947 - Insecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSign
Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leadβ¦
5.1
CVE-2026-5249 - gougucms Record Endpoint record.html cross site scripting
A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attaβ¦
4.3
CVE-2026-3831 - Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authentiβ¦
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Conβ¦
7
CVE-2026-4374 - Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Roβ¦
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Service,Observability Collector,Recording Service,Queueing Service,Cloud Discovery Service) allows Serialized Data External Linking, Data Serializat...
4.8
CVE-2026-2394 - Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.
5.3
CVE-2026-5248 - gougucms User Registration Login.php reg_submit dynamically-determined object attributes
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes. The attack may beβ¦
5.1
CVE-2026-35057 - XenForo Stored Cross-Site Scripting via Structured Text Mentions
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
8.6
CVE-2026-35056 - XenForo Remote Code Execution via Authenticated Admin
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.