Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-65593

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.

PUBLISHED
Vendor
n8n-io, n8n-io, n8n-io
Product
n8n, n8n, n8n
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65592

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser.

PUBLISHED
Vendor
n8n-io, n8n-io, n8n-io
Product
n8n, n8n, n8n
Provider severity
HIGH
Conflicts
1

CVE-2026-65591

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

PUBLISHED
Vendor
n8n-io, n8n-io, n8n-io
Product
n8n, n8n, n8n
Provider severity
HIGH
Conflicts
1

CVE-2026-65590

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n i

PUBLISHED
Vendor
n8n-io, n8n-io
Product
n8n, n8n
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6559

A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

PUBLISHED
Vendor
Wavlink
Product
WL-WN579A3
Provider severity
MEDIUM
Conflicts
2

CVE-2026-65589

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.

PUBLISHED
Vendor
n8n-io, n8n-io, n8n-io
Product
n8n, n8n, n8n
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65568

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

PUBLISHED
Vendor
Visual Composer
Product
Visual Composer Website Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65567

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

PUBLISHED
Vendor
Nexcess
Product
Event Tickets
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65564

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

PUBLISHED
Vendor
chrisvrichardson
Product
MapPress Maps for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65563

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

PUBLISHED
Vendor
Themeisle
Product
Orbit Fox by ThemeIsle
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65562

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

PUBLISHED
Vendor
WPDeveloper
Product
BetterDocs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65561

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

PUBLISHED
Vendor
miniOrange
Product
WordPress Social Login and Register
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6556

@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed scope can be bypasse

PUBLISHED
Vendor
@fastify/express
Product
@fastify/express
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65558

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

PUBLISHED
Vendor
WPCenter
Product
AffiliateX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65557

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

PUBLISHED
Vendor
Tychesoftwares
Product
Abandoned Cart Lite for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65550

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

PUBLISHED
Vendor
wpshopmart
Product
Tabs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6555

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a ma

PUBLISHED
Vendor
prosolution
Product
ProSolution WP Client
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65540

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

PUBLISHED
Vendor
Metin Saraç
Product
Popup for CF7 with Sweet Alert
Provider severity
HIGH
Conflicts
0

CVE-2026-65539

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

PUBLISHED
Vendor
Bimal Rekhadiya
Product
Kwayy HTML Sitemap
Provider severity
HIGH
Conflicts
0

CVE-2026-65538

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

PUBLISHED
Vendor
Nilo Velez
Product
Machete
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65537

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

PUBLISHED
Vendor
Themeisle
Product
Cyr to Lat reloaded – transliteration of links and file names
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65536

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

PUBLISHED
Vendor
Mahdi Yousefi
Product
افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65535

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

PUBLISHED
Vendor
Takayuki Miyauchi
Product
TinyMCE Templates
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65534

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

PUBLISHED
Vendor
Charlie Etienne
Product
Custom links in Elementor Image Carousel
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65533

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

PUBLISHED
Vendor
wbolt.com
Product
Smart SEO Tool
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65532

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

PUBLISHED
Vendor
PersianScript
Product
Persian Woocommerce SMS
Provider severity
HIGH
Conflicts
0

CVE-2026-65531

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

PUBLISHED
Vendor
Themeum
Product
Qubely
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65530

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

PUBLISHED
Vendor
Templatespare
Product
TemplateSpare
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6553

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
HIGH
Conflicts
0

CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

PUBLISHED
Vendor
Iqonic Design
Product
Graphina
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65528

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

PUBLISHED
Vendor
bannersky
Product
BSK PDF Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65527

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

PUBLISHED
Vendor
lqd
Product
LIQUID SPEECH BALLOON
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65526

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

PUBLISHED
Vendor
Themeisle
Product
Visualizer
Provider severity
HIGH
Conflicts
0

CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

PUBLISHED
Vendor
uxper
Product
Civi Framework
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65524

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

PUBLISHED
Vendor
ThemeFusion
Product
Avada Custom Branding
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65522

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

PUBLISHED
Vendor
pixelacehq
Product
Manual - Documentation, Knowledge Base & Education WordPress Theme
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65521

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

PUBLISHED
Vendor
Mahmudul Hasan Arif
Product
WP Social Ninja
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65519

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

PUBLISHED
Vendor
gt3themes
Product
Photo Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65518

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

PUBLISHED
Vendor
Scott Paterson
Product
Accept Donations with PayPal & Stripe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65516

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

PUBLISHED
Vendor
Pepro Dev. Group
Product
PeproDev Ultimate Invoice
Provider severity
HIGH
Conflicts
0

CVE-2026-65514

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

PUBLISHED
Vendor
codepeople
Product
Appointment Hour Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65512

Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.

PUBLISHED
Vendor
Melapress
Product
WP Activity Log
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65511

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

PUBLISHED
Vendor
pixelacehq
Product
Manual - Documentation, Knowledge Base & Education WordPress Theme
Provider severity
HIGH
Conflicts
0

CVE-2026-65510

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

PUBLISHED
Vendor
Pepro Dev. Group
Product
PeproDev Ultimate Invoice
Provider severity
HIGH
Conflicts
0

CVE-2026-6551

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected p

PUBLISHED
Vendor
techeshta
Product
Timeline Blocks for Gutenberg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

PUBLISHED
Vendor
sonaar
Product
MP3 Audio Player for Music, Radio & Podcast by Sonaar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65505

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

PUBLISHED
Vendor
bdthemes
Product
Ultimate Store Kit Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65503

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

PUBLISHED
Vendor
bdthemes
Product
Ultimate Store Kit Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

PUBLISHED
Vendor
vendidero
Product
Shiptastic for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65500

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

PUBLISHED
Vendor
pixelacehq
Product
Manual - Documentation, Knowledge Base & Education WordPress Theme
Provider severity
HIGH
Conflicts
0