Export limit exceeded: 14533 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14533 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-27345 | 2 Magepeople, Wordpress | 2 Taxi Booking Manager For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||||
| CVE-2026-66461 | 2 Smepay, Wordpress | 2 Smepay:upi Gateway For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-73353 | 2 Revolut, Wordpress | 2 Revolut Gateway For Woocommerce, Wordpress | 2026-08-14 | 5.3 Medium |
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | ||||
| CVE-2026-72825 | 1 Getgrav | 1 Grav | 2026-08-14 | 7.6 High |
| The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmin() check instead of requireSuper(). Because isSuperAdmin() reads access.api.super directly and never consults api_key_scopes, a least-privilege API key scoped to api.config.write minted on a super account passes the gate, allowing an attacker to append attacker-chosen tokens to the security.twig_sandbox allowlist (persisted to user/config/security.yaml). Widening the allowlist turns any subsequent Twig-in-content render into an SSTI/RCE sink. | ||||
| CVE-2026-72823 | 1 Getgrav | 1 Grav | 2026-08-14 | 5.4 Medium |
| The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes cap (enforced only in requirePermission()) is skipped. As a result, any scoped API key minted on a super account can bypass its scope restrictions when calling the baseline() and reset() operations (e.g. POST /api/v1/demo/reset), allowing it to capture the demo baseline or force a demo reset. Impact is bounded to demo-engine control and is conditional on demo mode being configured with writable resources. | ||||
| CVE-2026-58416 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-14 | 7.1 High |
| Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard) | ||||
| CVE-2026-28159 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28186 | 2 Themefic, Wordpress | 2 Travelfic Toolkit, Wordpress | 2026-08-14 | 8.1 High |
| Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | ||||
| CVE-2026-61978 | 2 Webhosting4ugr, Wordpress | 2 Secure Card Gateway For Epay Paycenter (piraeus Bank), Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. | ||||
| CVE-2026-66431 | 2 Woompaloompa, Wordpress | 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | ||||
| CVE-2026-66455 | 2 Rockiger, Wordpress | 2 Reactpress, Wordpress | 2026-08-14 | 6 Medium |
| Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | ||||
| CVE-2026-66459 | 2 Space Codes, Wordpress | 2 Ai For Seo, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. | ||||
| CVE-2026-66464 | 2 Toast Plugins, Wordpress | 2 Internal Link Optimiser, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | ||||
| CVE-2026-66466 | 2 Wedevs, Wordpress | 2 Storegrowth: Smart Sales Booster For Woocommerce | Bogo, Upsells, Direct Checkout, Quick View, Side Cart, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | ||||
| CVE-2026-66469 | 2 Afonso Matos, Wordpress | 2 Arvow Ai Seo Writer, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | ||||
| CVE-2026-73658 | 1 Triggerdotdev | 1 Trigger.dev | 2026-08-14 | 8.2 High |
| Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while apps/webapp/app/routes/api.v1.packets.$.ts accepts params["*"] without rejecting dot segments and uses findResource: async () => 1 without per-resource ownership validation. WHATWG path normalization collapses .. segments before signing, allowing a caller with a valid environment API key to obtain presigned URLs for another tenant's object-store keys and read or overwrite task payloads. This issue is fixed in version 4.5.0-rc.5. | ||||
| CVE-2026-27999 | 2 Themefic, Wordpress | 2 Tourfic, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. | ||||
| CVE-2026-28188 | 2 Themefic, Wordpress | 2 Hydra Booking, Wordpress | 2026-08-13 | 7.3 High |
| Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. | ||||
| CVE-2026-66689 | 2 Acymailing Newsletter Team, Wordpress | 2 Anti Spam And List Cleaner – Acychecker, Wordpress | 2026-08-13 | 6.3 Medium |
| Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | ||||
| CVE-2026-59714 | 1 Open-webui | 1 Open-webui | 2026-08-13 | 7.1 High |
| Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0. | ||||