4.3

CVSS3.1

CVE-2026-4109 - Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) <= 4.1.8 Missing Autho…

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for …

📅 Published: April 14, 2026, 7:43 a.m. 🔄 Last Modified: April 14, 2026, 7:43 a.m.

6.5

CVSS3.1

CVE-2026-2582 - Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution

The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before running …

📅 Published: April 14, 2026, 6:43 a.m. 🔄 Last Modified: April 14, 2026, 6:43 a.m.

7.2

CVSS3.1

CVE-2026-3017 - Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authentica…

The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticat…

📅 Published: April 14, 2026, 5:30 a.m. 🔄 Last Modified: April 14, 2026, 4:30 p.m.

6.4

CVSS3.1

CVE-2026-4059 - ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Sh…

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcode at…

📅 Published: April 14, 2026, 3:37 a.m. 🔄 Last Modified: April 14, 2026, 3:37 a.m.

4.4

CVSS3.1

CVE-2026-4479 - WholeSale Products Dynamic Pricing Management WooCommerce <= 1.2 - Authenticated (Administrator+) S…

The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…

📅 Published: April 14, 2026, 3:37 a.m. 🔄 Last Modified: April 14, 2026, 3:37 a.m.

6.4

CVSS3.1

CVE-2026-1607 - Surbma | Booking.com <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: April 14, 2026, 3:37 a.m. 🔄 Last Modified: April 14, 2026, 3:37 a.m.

9.1

CVSS3.1

CVE-2026-40313 - PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/checkout without setting persist-credentials: false. By default, actions/checkout writes the GITHUB_TOK…

📅 Published: April 14, 2026, 3:10 a.m. 🔄 Last Modified: April 17, 2026, 3:24 p.m.

9.1

CVSS3.1

CVE-2026-40289 - PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension ses…

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws WebSocket end…

📅 Published: April 14, 2026, 3:05 a.m. 🔄 Last Modified: April 17, 2026, 3:24 p.m.

9.8

CVSS3.1

CVE-2026-40288 - PraisonAI: Critical RCE via `type: job` workflow YAML

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run <file.yaml> loads a YAML file with type: job, the JobWo…

📅 Published: April 14, 2026, 3 a.m. 🔄 Last Modified: April 17, 2026, 3:24 p.m.

8.4

CVSS3.1

CVE-2026-40287 - PraisonAI has RCE via Automatic tools.py Import

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools())…

📅 Published: April 14, 2026, 2:55 a.m. 🔄 Last Modified: April 17, 2026, 3:24 p.m.
Total resulsts: 345187
Page 91 of 34,519
« previous page » next page
Filters