Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25484

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a Stored XSS via Product Type names. The name is not sanitized when displayed in user permissions settings. The vulnerable input (source) is in Commerce (Product Type settings), but the sink is in CMS user permissions settings. This issue has been patched in versions 4.10.1 and 5.5.2.

PUBLISHED
Vendor
craftcms
Product
commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25483

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Status History Message. The message is rendered using the |md filter, which permits raw HTML, enabling malicious script execution. If a user has database backup utility permissions (which do not require an elevated session), an attacker can exfiltrate the entire database, including all user credentials, customer PII, orde

PUBLISHED
Vendor
craftcms
Product
commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25482

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored DOM XSS vulnerability exists in the "Recent Orders" dashboard widget. The Order Status Name is rendered via JavaScript string concatenation without proper escaping, allowing script execution when any admin visits the dashboard. This issue has been patched in versions 4.10.1 and 5.5.2.

PUBLISHED
Vendor
craftcms
Product
commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25481

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call pandas_eval tool to evaluate the expression. There is a WAF in langroid/utils/pandas_utils.py introduced to block code injection CVE-2025-46724. However it can be bypassed due to _literal_ok() returning False instead of raising UnsafeCommandError on invalid input, combined with unrestricted access to dangerous dunder at

PUBLISHED
Vendor
langroid
Product
langroid
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25480

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileStore is used as response-cache backend, an unauthenticated remote attacker can trigger cache key collisions via crafted paths, causing one URL to serve cached responses of another (cache poisoning/mixup). This vulnerability is fixed in 2.20.0.

PUBLISHED
Vendor
litestar-org
Product
litestar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2548

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
WAYOS
Product
FBM-220G
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25479

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker supplies a host that matches the regex but is not the intended literal hostname. This vulnerability is fixed in 2.20.0.

PUBLISHED
Vendor
litestar-org
Product
litestar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25478

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used with fullmatch() for validation. Because metacharacters are not escaped, a malicious origin can match unexpectedly. The check relies on allowed_origins_regex.fullmatch(origin). This vulnerability is fixed in 2.20.0.

PUBLISHED
Vendor
litestar-org
Product
litestar
Provider severity
HIGH
Conflicts
0

CVE-2026-25477

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0.

PUBLISHED
Vendor
toeverything
Product
AFFiNE
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25476

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1` is sent, the entire block that calls `SessionTracker::isSessionExpired()` and forces logout on timeout is skipped. As a result, any request that includes this parameter (e.g. from auto-refresh pages like the Patient Flow

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-25475

OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel. This issue has been patched in version 2026.1.30.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25474

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployments where the webhook endpoint is reachable by an attacker, this can allow forged Telegram updates (for example spoofing message.from.id). If an attacker can reach the webhook endpoint, they may be able to send forged updates that are processed as if

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH
Conflicts
0

CVE-2026-25473

Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31.

PUBLISHED
Vendor
AA-Team
Product
WZone
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25472

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Stored XSS.This issue affects Fusion Builder: from n/a through <= 3.14.1.

PUBLISHED
Vendor
ThemeFusion
Product
Fusion Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25471

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through <= 1.2.6.

PUBLISHED
Vendor
Themepaste
Product
Admin Safety Guard
Provider severity
HIGH
Conflicts
0

CVE-2026-25470

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.

PUBLISHED
Vendor
ACPT
Product
ACPT (Pro) - Custom Post Types Plugin for WordPress
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2547

A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
LigeroSmart
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-25469

Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ViaBill – WooCommerce: from n/a through <= 1.1.53.

PUBLISHED
Vendor
ViaBill for WooCommerce
Product
ViaBill – WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25468

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8.

PUBLISHED
Vendor
weDevs
Product
Happy Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25466

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

PUBLISHED
Vendor
WPGMaps
Product
WP Go Maps
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25465

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Stored XSS.This issue affects CP Multi View Event Calendar : from n/a through <= 1.4.36.

PUBLISHED
Vendor
codepeople
Product
CP Multi View Event Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25464

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.4.

PUBLISHED
Vendor
TieLabs
Product
Jannah
Provider severity
HIGH
Conflicts
0

CVE-2026-25463

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate Wpresidence Core wpresidence-core allows Stored XSS.This issue affects Wpresidence Core: from n/a through <= 5.4.0.

PUBLISHED
Vendor
WpEstate
Product
Wpresidence Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25462

Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects avalex: from n/a through <= 3.1.3.

PUBLISHED
Vendor
avalex
Product
avalex
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25461

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through <= 2.0.21.

PUBLISHED
Vendor
purethemes
Product
Listeo Core
Provider severity
HIGH
Conflicts
0

CVE-2026-25460

Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ave Core: from n/a through <= 2.9.1.

PUBLISHED
Vendor
LiquidThemes
Product
Ave Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2546

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
LigeroSmart
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-25459

Missing Authorization vulnerability in uixthemes Sober sober allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sober: from n/a through <= 3.5.12.

PUBLISHED
Vendor
uixthemes
Product
Sober
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25458

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Moments moments allows PHP Local File Inclusion.This issue affects Moments: from n/a through <= 2.2.

PUBLISHED
Vendor
Select-Themes
Product
Moments
Provider severity
HIGH
Conflicts
0

CVE-2026-25457

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through <= 2.1.

PUBLISHED
Vendor
Select-Themes
Product
Mixtape
Provider severity
HIGH
Conflicts
0

CVE-2026-25456

Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automated FedEx live/manual rates with shipping labels: from n/a through <= 5.1.9.

PUBLISHED
Vendor
Aarsiv Groups
Product
Automated FedEx live/manual rates with shipping labels
Provider severity
HIGH
Conflicts
0

CVE-2026-25455

Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.61.

PUBLISHED
Vendor
PickPlugins
Product
Product Slider for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25454

Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The League: from n/a through <= 4.4.1.

PUBLISHED
Vendor
MVPThemes
Product
The League
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25453

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10.

PUBLISHED
Vendor
mdempfle
Product
Advanced iFrame
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25452

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDO Remoji remoji allows Stored XSS.This issue affects Remoji: from n/a through <= 2.2.

PUBLISHED
Vendor
WPDO
Product
Remoji
Provider severity
HIGH
Conflicts
0

CVE-2026-25451

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through <= 5.6.9.

PUBLISHED
Vendor
boldthemes
Product
Bold Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2545

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
LigeroSmart
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-25449

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.

PUBLISHED
Vendor
shinetheme
Product
Traveler
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25447

Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9.

PUBLISHED
Vendor
Jonathan Daggerhart
Product
Widget Wrangler
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25446

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

PUBLISHED
Vendor
WishList Products, LLC.
Product
WishList Member X
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25445

Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.

PUBLISHED
Vendor
Membership Software
Product
WishList Member X
Provider severity
HIGH
Conflicts
0

CVE-2026-25444

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

PUBLISHED
Vendor
Magepeople inc.
Product
WpBookingly
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25443

Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fraud Prevention For Woocommerce: from n/a through <= 2.3.3.

PUBLISHED
Vendor
Dotstore
Product
Fraud Prevention For Woocommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-25442

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS.This issue affects Kentha: from n/a through <= 4.7.2.

PUBLISHED
Vendor
QantumThemes
Product
Kentha
Provider severity
HIGH
Conflicts
0

CVE-2026-25441

Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LeadConnector: from n/a through <= 3.0.21.

PUBLISHED
Vendor
varunvairavanlc
Product
LeadConnector
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25440

Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.

PUBLISHED
Vendor
WPDeveloper
Product
Essential Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2544

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
yued-fe
Product
LuLu UI
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-25439

Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.

PUBLISHED
Vendor
fs-code
Product
Booknetic
Provider severity
HIGH
Conflicts
0

CVE-2026-25438

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue affects Gutenberg Blocks: from n/a through <= 1.2.8.

PUBLISHED
Vendor
ThemeHunk
Product
Gutenberg Blocks
Provider severity
HIGH
Conflicts
0

CVE-2026-25437

Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GZSEO: from n/a through <= 2.0.14.

PUBLISHED
Vendor
سید محمدامین هاشمی
Product
GZSEO
Provider severity
MEDIUM
Conflicts
0