Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39586

Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through <= 4.1132.

PUBLISHED
Vendor
Ateeq Rafeeq
Product
RepairBuddy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39585

Missing Authorization vulnerability in Arraytics Booktics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booktics: from n/a through 1.0.16.

PUBLISHED
Vendor
Arraytics
Product
Booktics
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39584

Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

PUBLISHED
Vendor
Webful Creations
Product
RepairBuddy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39583

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

PUBLISHED
Vendor
Datalogics
Product
Datalogics Ecommerce Delivery
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39582

Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.

PUBLISHED
Vendor
xtemos
Product
Hitek
Provider severity
HIGH
Conflicts
0

CVE-2026-39581

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

PUBLISHED
Vendor
activity-log.com
Product
WP Sessions Time Monitoring Full Automatic
Provider severity
HIGH
Conflicts
0

CVE-2026-39580

Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.

PUBLISHED
Vendor
Select-Themes
Product
Micdrop
Provider severity
HIGH
Conflicts
0

CVE-2026-3958

A vulnerability has been found in Woahai321 ListSync up to 0.6.6. This issue affects the function requests.post of the file list-sync-main/api_server.py of the component JSON Handler. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
Woahai321
Product
ListSync
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39579

Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.

PUBLISHED
Vendor
bPlugins
Product
B Blocks
Provider severity
HIGH
Conflicts
0

CVE-2026-39578

Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Valiance
Provider severity
HIGH
Conflicts
0

CVE-2026-39577

Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Playroom
Provider severity
HIGH
Conflicts
0

CVE-2026-39576

Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

PUBLISHED
Vendor
Elated-Themes
Product
SingleMalt
Provider severity
HIGH
Conflicts
0

CVE-2026-39575

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query Blocks: from n/a through <= 5.5.0.

PUBLISHED
Vendor
Ronald Huereca
Product
Custom Query Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39574

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

PUBLISHED
Vendor
RealMag777
Product
InPost Gallery
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39573

Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.

PUBLISHED
Vendor
Select-Themes
Product
Mildhill
Provider severity
HIGH
Conflicts
0

CVE-2026-39572

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Retrieve Embedded Sensitive Data.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through < 5.6.5.

PUBLISHED
Vendor
magepeopleteam
Product
Bus Ticket Booking with Seat Reservation
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39571

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through <= 3.3.30.

PUBLISHED
Vendor
Themefic
Product
Instantio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39570

Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.

PUBLISHED
Vendor
AA Web Servant
Product
12 Step Meeting List
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3957

A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This vulnerability affects the function getLikeMovieList of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/HomeController.java of the component Endpoint. Executing a manipulation of the argument cat can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which

PUBLISHED
Vendor
xierongwkhd
Product
weimai-wetapp
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39569

Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.

PUBLISHED
Vendor
AA Web Servant
Product
12 Step Meeting List
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39568

Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Mr. SEO
Provider severity
HIGH
Conflicts
0

CVE-2026-39567

Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.

PUBLISHED
Vendor
Select-Themes
Product
Santé
Provider severity
HIGH
Conflicts
0

CVE-2026-39566

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26.

PUBLISHED
Vendor
Designinvento
Product
DirectoryPress
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39565

Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7.

PUBLISHED
Vendor
magepeopleteam
Product
WpTravelly
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39564

Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo Cart: from n/a through < 3.6.2.

PUBLISHED
Vendor
sunshinephotocart
Product
Sunshine Photo Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39563

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.

PUBLISHED
Vendor
ILLID
Product
Share This Image
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39562

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.10.

PUBLISHED
Vendor
BoldGrid
Product
Client Invoicing by Sprout Invoices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39561

Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.7.

PUBLISHED
Vendor
WP Chill
Product
Revive.so
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39560

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

PUBLISHED
Vendor
Select-Themes
Product
Hiroshi
Provider severity
HIGH
Conflicts
0

CVE-2026-3956

A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects the function getAdmins of the file source-code/src/main/java/com/moke/wp/wx_weimai/controller/admin/Admin_AdminUserController.java. Performing a manipulation of the argument keyword results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version

PUBLISHED
Vendor
xierongwkhd
Product
weimai-wetapp
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39559

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

PUBLISHED
Vendor
codesupplyco
Product
Uppercase
Provider severity
HIGH
Conflicts
0

CVE-2026-39558

Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Malmö
Provider severity
HIGH
Conflicts
0

CVE-2026-39557

Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.

PUBLISHED
Vendor
Elated-Themes
Product
NeoBeat
Provider severity
HIGH
Conflicts
0

CVE-2026-39556

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Konsept
Provider severity
HIGH
Conflicts
0

CVE-2026-39555

Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.

PUBLISHED
Vendor
Elated-Themes
Product
Askka
Provider severity
HIGH
Conflicts
0

CVE-2026-39554

Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Fidalgo
Provider severity
HIGH
Conflicts
0

CVE-2026-39553

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4.

PUBLISHED
Vendor
Select-Themes
Product
WaveRide
Provider severity
HIGH
Conflicts
0

CVE-2026-39552

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5.

PUBLISHED
Vendor
Code Supply Co.
Product
Blueprint
Provider severity
HIGH
Conflicts
0

CVE-2026-39551

Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.

PUBLISHED
Vendor
Elated-Themes
Product
Töbel
Provider severity
HIGH
Conflicts
0

CVE-2026-39550

Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.

PUBLISHED
Vendor
Elated-Themes
Product
Aperitif
Provider severity
HIGH
Conflicts
0

CVE-2026-3955

A security vulnerability has been detected in elecV2P up to 3.8.3. Affected by this issue is the function runJSFile of the file source-code/elecV2P-master/webser/wbjs.js of the component jsfile Endpoint. Such manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
elecV2P
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39549

Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Aperitif
Provider severity
HIGH
Conflicts
0

CVE-2026-39548

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

PUBLISHED
Vendor
Sneeit
Product
MagOne
Provider severity
HIGH
Conflicts
0

CVE-2026-39547

Unauthenticated Local File Inclusion in Getaway < 1.8 versions.

PUBLISHED
Vendor
Select-Themes
Product
Getaway
Provider severity
HIGH
Conflicts
0

CVE-2026-39546

Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.

PUBLISHED
Vendor
Techspawn
Product
MultiLoca
Provider severity
HIGH
Conflicts
0

CVE-2026-39545

Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.

PUBLISHED
Vendor
Select-Themes
Product
Zermatt
Provider severity
HIGH
Conflicts
0

CVE-2026-39544

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechco allows PHP Local File Inclusion.This issue affects LabtechCO: from n/a through <= 8.3.

PUBLISHED
Vendor
themeStek
Product
LabtechCO
Provider severity
HIGH
Conflicts
0

CVE-2026-39543

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.21.4.

PUBLISHED
Vendor
Themefic
Product
Tourfic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39542

Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13.

PUBLISHED
Vendor
Doofinder
Product
Doofinder for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39541

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.38.

PUBLISHED
Vendor
Themefic
Product
Hydra Booking
Provider severity
MEDIUM
Conflicts
0