5.6

CVSS3.1

CVE-2026-22687 - WeKnora vulnerable to SQL Injection

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass tech…

📅 Published: Jan. 10, 2026, 3:41 a.m. 🔄 Last Modified: April 16, 2026, 6:30 p.m.

8.5

CVSS4.0

CVE-2026-22610 - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulne…

📅 Published: Jan. 10, 2026, 3:35 a.m. 🔄 Last Modified: April 18, 2026, 7:30 p.m.

7.5

CVSS3.1

CVE-2025-13457 - WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Informa…

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Sq…

📅 Published: Jan. 10, 2026, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2026-22589 - Spree API has Unauthenticated IDOR - Guest Address

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supply…

📅 Published: Jan. 10, 2026, 3:17 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

6.1

CVSS3.1

CVE-2025-61674 - October CMS Vulnerable to Stored XSS via Editor and Branding Styles

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permission could inject malicious HTML/JS into the stylesh…

📅 Published: Jan. 10, 2026, 3:14 a.m. 🔄 Last Modified: Jan. 20, 2026, 4:06 p.m.

6.1

CVSS3.1

CVE-2025-61676 - October CMS Vulnerable to Stored XSS via Branding Styles

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the sty…

📅 Published: Jan. 10, 2026, 3:14 a.m. 🔄 Last Modified: Jan. 20, 2026, 4:05 p.m.

10

CVSS3.1

CVE-2025-65091 - XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been pat…

📅 Published: Jan. 10, 2026, 3:06 a.m. 🔄 Last Modified: Jan. 29, 2026, 5:27 p.m.

5.3

CVSS3.1

CVE-2025-65090 - XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has b…

📅 Published: Jan. 10, 2026, 3:05 a.m. 🔄 Last Modified: Jan. 29, 2026, 5:27 p.m.

5.1

CVSS4.0

CVE-2026-22597 - Ghost has SSRF via External Media Inliner

Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. T…

📅 Published: Jan. 10, 2026, 2:57 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.

6.7

CVSS3.1

CVE-2026-22596 - Ghost has SQL Injection in Members Activity Feed

Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in vers…

📅 Published: Jan. 10, 2026, 2:57 a.m. 🔄 Last Modified: April 18, 2026, 7:15 a.m.
Total resulsts: 349182
Page 2203 of 34,919
« previous page » next page
Filters