Search Results (28619 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-82837 1 Gitlab 1 Gitlab 2026-09-28 5.3 Medium
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
CVE-2026-89008 1 Wordpress-extensions 1 Bookit 2026-09-28 2.7 Low
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.
CVE-2026-16557 1 Wordpress-extensions 1 Nimble Builder 2026-09-28 4.3 Medium
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any authenticated user (Subscriber+) to disclose the page-builder content of arbitrary non-public (draft, pending, private, scheduled) posts and pages.
CVE-2026-92404 1 Wordpress-extensions 1 Mgosync 2026-09-28 7.5 High
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
CVE-2026-92423 1 Wordpress-extensions 1 Meow Gallery 2026-09-28 2.7 Low
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.
CVE-2026-84026 1 Wordpress-extensions 1 Directorist 2026-09-28 5.3 Medium
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details.
CVE-2026-84168 1 Wordpress-extensions 1 Easy Hide Login 2026-09-28 5.3 Medium
The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection.
CVE-2026-84741 1 Wordpress-extensions 1 The Events Calendar 2026-09-28 5.3 Medium
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
CVE-2026-86602 1 Wordpress-extensions 1 Wp Recipe Maker 2026-09-28 4.3 Medium
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
CVE-2026-86603 1 Wordpress-extensions 1 Wp Recipe Maker 2026-09-28 4.3 Medium
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
CVE-2026-86783 1 Wordpress-extensions 1 Postx 2026-09-28 5.3 Medium
The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending, scheduled and password-protected posts.
CVE-2026-88929 1 Wordpress-extensions 1 Sale Booster 2026-09-28 5.3 Medium
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
CVE-2026-89331 1 Wordpress-extensions 1 Fluentboards 2026-09-28 5.3 Medium
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
CVE-2026-90985 1 Wordpress-extensions 1 Wpc Smart Compare For Woocommerce 2026-09-28 5.3 Medium
The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
CVE-2026-93528 1 Wordpress-extensions 1 Np Quote Request For Woocommerce 2026-09-28 3.7 Low
The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
CVE-2026-87071 1 Wordpress-extensions 1 Forminator Forms 2026-09-28 5.3 Medium
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post their submission creates.
CVE-2026-51773 1 Openstack 1 Glance-store 2026-09-28 8.1 High
An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destination host before attaching sensitive authentication headers.
CVE-2026-52622 1 Wellav 1 Wes Emergency Broadcast Terminal 2026-09-28 7.5 High
An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function
CVE-2026-84744 1 Wordpress-extensions 1 Wpforms Lite 2026-09-28 6.5 Medium
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
CVE-2026-101131 1 Deepseek-ai 1 Deepseek-harness 2026-09-28 3.3 Low
A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the file packages/e2b/e2b/src/index.ts of the component dsh. The manipulation of the argument E2B_API_KEY leads to reliance on untrusted inputs in a security decision. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.