Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confide

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Single Sign-On 7, Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Build of Keycloak
Provider severity
MEDIUM
Conflicts
1

CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Single Sign-On 7, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak
Provider severity
MEDIUM
Conflicts
1

CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Build of Keycloak, Red Hat Single Sign-On 7
Provider severity
MEDIUM
Conflicts
1

CVE-2026-18570

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows t

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat Single Sign-On 7, Red Hat Data Grid 8, Red Hat Build of Keycloak, Red Hat Build of Keycloak
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1857

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.6.1. This is due to insufficient validation of the `endpoint` parameter in the `get_items()` function of the GetResponse REST API handler. The endpoint's permission check only requires `edit_posts` capability (Contributor role) rather than `manage_options` (Administrator). This makes it possible for authenticated attackers, with Contributor-level ac

PUBLISHED
Vendor
stellarwp
Product
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18568

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. verify in lib/XML/Sig.pm counts the `//dsig:Signature` elements into `$numsigs` and iterates over them, but two paths reach `next` before any digest or key check runs: a `SignedInfo/Reference/@URI` that resolves to no element while `$numsigs` is greater than 1, and, when `id_attr` is set, a reference that does not match

PUBLISHED
Vendor
TIMLEGGE
Product
XML::Sig
Provider severity
HIGH
Conflicts
0

CVE-2026-1856

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
creavi
Product
Creavi Appointment Booking Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18556

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

PUBLISHEDCISA KEV
Vendor
N-able
Product
N-central
Provider severity
HIGH
Conflicts
0

CVE-2026-1854

The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
nosoycesaros
Product
Post Flagger
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18536

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string. Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand

PUBLISHED
Vendor
RRWO
Product
Data::Entropy
Provider severity
HIGH
Conflicts
1

CVE-2026-1853

The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
digiblogger
Product
BuddyHolis ListSearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1852

The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages or delete pricing tables via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
woobeewoo
Product
Product Pricing Table by WooBeWoo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1851

The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attribute in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
deckercz
Product
iVysilani Shortcode
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18508

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 6, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Hardened Images
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1850

Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-1849

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-18481

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.

PUBLISHED
Vendor
AWS
Product
AWS Ops Wheel
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-1848

Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH
Conflicts
1

CVE-2026-18477

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalatio

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, Red Hat Hardened Images, Red Hat Hardened Images
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1847

Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the oplog from the primary. This could stall replication inside the replica set leading to server crash.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-18452

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

PUBLISHED
Vendor
Rich Source
Product
DMS+ (Non-Mobile)
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1845

The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has be

PUBLISHED
Vendor
bhubbard
Product
Real Estate Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18446

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applicati

PUBLISHED
Vendor
fast-uri
Product
fast-uri
Provider severity
HIGH
Conflicts
0

CVE-2026-1844

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 12.4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
pixelyoursite
Product
PixelYourSite Pro – Your smart PIXEL (TAG) Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.

PUBLISHED
Vendor
mailerpress
Product
MailerPress – Newsletter, email marketing & AI automation
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback, allowing the restoreRevision() handler to run for unauthenticated requests and overwrite a campaign's content_html with any prior revision. This makes it possible for unauthenticated att

PUBLISHED
Vendor
mailerpress
Product
MailerPress – Newsletter, email marketing & AI automation
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18435

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
stellarwp
Product
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1843

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
optimole
Product
Super Page Cache
Provider severity
HIGH
Conflicts
0

CVE-2026-1842

HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a significantly longer lifetime (default one year), an authenticated client could use a refresh token in place of an access token to maintain long-term access without token rotation. Additionally, old access tokens remained valid after refresh, enabling concurrent or ex

PUBLISHED
Vendor
SoftIron
Product
HyperCloud
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1841

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 11.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2026-27072 is likely a duplicate of thi

PUBLISHED
Vendor
pixelyoursite
Product
PixelYourSite – Your smart PIXEL (TAG) & API Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-1840

The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without restriction. Such unauthorized changes can disrupt normal functionality and, if performed repeatedly, may lead to a loss of communications to the device.

PUBLISHED
Vendor
Hubbell
Product
Aclara Metrum Cellular Web Interface
Provider severity
HIGH
Conflicts
1

CVE-2026-18394

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2.

PUBLISHED
Vendor
AWS
Product
Strands Agents Tools
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-1839

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vul

PUBLISHED
Vendor
huggingface
Product
huggingface/transformers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18382

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.

PUBLISHED
Vendor
Red Hat
Product
Cost Management Metrics Operator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18381

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.

PUBLISHED
Vendor
Red Hat
Product
Cost Management Metrics Operator
Provider severity
HIGH
Conflicts
0

CVE-2026-1838

The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PUBLISHED
Vendor
prasunsen
Product
Hostel
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18378

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.

PUBLISHED
Vendor
Red Hat
Product
Cost Management Metrics Operator
Provider severity
HIGH
Conflicts
0

CVE-2026-1837

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (select

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Google, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, libjxl, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
3

CVE-2026-18369

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Certificate System 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Certificate System 11, Red Hat Enterprise Linux 10, Red Hat Certificate System 10, Red Hat Certificate System 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-18363

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able

PUBLISHED
Vendor
Enhancesoft LLC
Product
osTicket
Provider severity
CRITICAL
Conflicts
0

CVE-2026-18362

The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18361

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
HIGH
Conflicts
0

CVE-2026-18360

The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

PUBLISHED
Vendor
dfir-iris
Product
iris-web
Provider severity
HIGH
Conflicts
0

CVE-2026-1836

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

PUBLISHED
Vendor
Redmine
Product
Redmine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-18358

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions.

PUBLISHED
Vendor
Red Hat, Red Hat, GNOME, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, gnome-remote-desktop, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
1

CVE-2026-18353

PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer allowlist using Python's `urlparse` before performing OIDC discovery with `requests`. Because `urlparse` and `requests`/`urllib3` parse an authority string containing a backslash (e.g. `https://attacker-host\@ci.eclipse.org/`) into *different* hostnames, an attacker can craft an issuer that passes the allowlist check yet drives `requests` — and subsequently `urllib.request.urlop

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse CSI - PIA
Provider severity
HIGH
Conflicts
0

CVE-2026-18352

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is possible because when attachment_url_to_postid() returns 0 for a traversal path, the plugin falls back to the global post set by a valid ?attachment_id parameter supplied by

PUBLISHED
Vendor
gm_alex
Product
User Access Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-1835

A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown part. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.

PUBLISHED
Vendor
lcg0124
Product
BootDo
Provider severity
MEDIUM
Conflicts
2

CVE-2026-18344

The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id'] directly into a double-quoted HTML attribute with no esc_attr() call. The only guard is a loose PHP numeric comparison ($_GET['id']>0) that a string beginning with a numeric prefix t

PUBLISHED
Vendor
nik00726
Product
Responsive Thumbnail Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1834

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
vowelweb
Product
Ibtana – WordPress Website Builder
Provider severity
MEDIUM
Conflicts
0