5.3

CVSS4.0

CVE-2026-2009 - SourceCodester Gas Agency Management System createUser.php access control

A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been publ…

📅 Published: Feb. 6, 2026, 7:32 a.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.

6.4

CVSS3.1

CVE-2026-1279 - Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_ti…

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for aut…

📅 Published: Feb. 6, 2026, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

5.3

CVSS4.0

CVE-2026-2008 - abhiphile fermat-mcp eqn_chart.py eqn_chart code injection

A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_chart of the file fmcp/mpl_mcp/core/eqn_chart.py. Performing a manipulation of the argument equations results in code injection. It is possible to initiat…

📅 Published: Feb. 6, 2026, 7:02 a.m. 🔄 Last Modified: April 18, 2026, 6:30 p.m.

6.4

CVSS3.1

CVE-2026-1401 - Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scri…

The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Sub…

📅 Published: Feb. 6, 2026, 6:46 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.4

CVSS3.1

CVE-2026-1909 - WaveSurfer-WP <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortco…

The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping on the 'src' attribute. This makes it possible for authenticated attackers, wit…

📅 Published: Feb. 6, 2026, 6:46 a.m. 🔄 Last Modified: April 16, 2026, 7 a.m.

5.3

CVSS3.1

CVE-2025-10753 - OAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing Authorization

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 6.26.14. This is due to missing capability checks and authentication verification on the OAuth redirect functionality accessible via the 'oauthredirect' opti…

📅 Published: Feb. 6, 2026, 6:46 a.m. 🔄 Last Modified: April 22, 2026, 2 p.m.

6.4

CVSS3.1

CVE-2026-1808 - Orange Confort+ accessibility toolbar for WordPress <= 0.7 - Authenticated (Contributor+) Stored Cr…

The Orange Confort+ accessibility toolbar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' parameter of the ocplus_button shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output escaping. This makes it poss…

📅 Published: Feb. 6, 2026, 6:46 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

6.4

CVSS3.1

CVE-2026-1888 - Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The Docus – YouTube Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'docusplaylist' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

📅 Published: Feb. 6, 2026, 6:46 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

5.1

CVSS4.0

CVE-2026-2000 - DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection

A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a manipulation of the argument ip_list results in command injection. The attack is possible to be car…

📅 Published: Feb. 6, 2026, 6:32 a.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.

5.6

CVSS4.0

CVE-2026-0521 - Reflected Cross-Site Scripting in PDF Export Error Message

A reflected cross-site scripting (XSS) vulnerability in the PDF export functionality of the TYDAC AG MAP+ solution allows unauthenticated attackers to craft a malicious URL, that if visited by a victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through…

📅 Published: Feb. 6, 2026, 6:17 a.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.
Total resulsts: 349182
Page 1778 of 34,919
« previous page » next page
Filters