Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-12776

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor

PUBLISHED
Vendor
Montodel
Product
House-Rental-Management
Provider severity
MEDIUM
Conflicts
2

CVE-2026-12775

A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was co

PUBLISHED
Vendor
Montodel
Product
House-Rental-Management
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-12774

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

PUBLISHED
Vendor
BerriAI
Product
litellm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, BerriAI
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Exploit Intelligence, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, litellm
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-12772

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure.

PUBLISHED
Vendor
BerriAI
Product
litellm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12771

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

PUBLISHED
Vendor
BerriAI
Product
litellm
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-12770

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 23781. It is recommended to apply a patch to fix this issue. The vendor was contacted early about this disclosure.

PUBLISHED
Vendor
BerriAI
Product
litellm
Provider severity
MEDIUM
Conflicts
2

CVE-2026-1277

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.

PUBLISHED
Vendor
kaizencoders
Product
URL Shortify – Simple and Easy URL Shortener
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12761

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST parameter without verifying that the email belongs to the identity returned by the OAuth provider, combined with send_otp_token() returning the SHA-512(customer_key || otp) transaction has

PUBLISHED
Vendor
cyberlord92
Product
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-12760

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and record

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Tapo C200 v3
Provider severity
HIGH
Conflicts
0

CVE-2026-1276

IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

PUBLISHED
Vendor
IBM
Product
QRadar SIEM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12755

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
LOW
Conflicts
0

CVE-2026-12754

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires the targeted page to render the

PUBLISHED
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12753

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the d

PUBLISHED
Vendor
themehunk
Product
Advance Product Search- Voice & Ajax Search for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-1275

The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' shortcode attribute in all versions up to, and including, 1.4. This is due to insufficient input sanitization and output escaping on the user-supplied 'slides' parameter in the post_slides_shortcode function. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user acce

PUBLISHED
Vendor
gbsdeveloper
Product
Multi Post Carousel by Category
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12746

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this plugin for OAuth 2.0 login is exposed to logi

PUBLISHED
Vendor
BIAFRA
Product
Dancer2::Plugin::Auth::OAuth::Provider
Provider severity
HIGH
Conflicts
0

CVE-2026-12741

The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database

PUBLISHED
Vendor
epsiloncool
Product
WP Fast Total Search – The Power of Indexed Search
Provider severity
HIGH
Conflicts
0

CVE-2026-12740

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-sit

PUBLISHED
Vendor
CORNELIUS
Product
Plack::Middleware::OAuth
Provider severity
HIGH
Conflicts
0

CVE-2026-1274

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

PUBLISHED
Vendor
IBM
Product
Guardium Data Protection
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12738

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'draft', effectively unpublishing arbitrary site content.

PUBLISHED
Vendor
saadiqbal
Product
WP Easy Pay – Payment and Donation form Builder for Square
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12736

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the permission_callback only verifies the manage_woocommerce capability. This makes it possible for authenticated attackers, with Shop Manage

PUBLISHED
Vendor
wpify
Product
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-12734

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wedevs
Product
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

PUBLISHED
Vendor
IBM, IBM, IBM, IBM
Product
DataPower Gateway 11.0.0, DataPower Gateway 10.5.0, DataPower Gateway 10.6.0, DataPower Gateway 10.6CD
Provider severity
HIGH
Conflicts
1

CVE-2026-12732

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization and output escaping in the FilterCourseTemplate::sections() method at line 98, where the attacker-controlled attribute is inserted into an HTML class attribute via sprintf('<form class="%s">', $class_wrapper_form) without esc_attr() escaping. The FilterCourseShortcode::render() han

PUBLISHED
Vendor
thimpress
Product
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12731

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected pa

PUBLISHED
Vendor
wedevs
Product
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1273

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.8 via the `/ultp/v3/starter_dummy_post/` and `/ultp/v3/starter_import_content/` REST API endpoints. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify inform

PUBLISHED
Vendor
wpxpo
Product
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
Provider severity
HIGH
Conflicts
0

CVE-2026-12729

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the wedocs_migrate_betterdocs_to_wedocs AJAX action, which performs no nonce verification via check_ajax_referer() and no capability check via current_user_can() before executing sensitive operations. This makes it possible for authenti

PUBLISHED
Vendor
wedevs
Product
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12726

A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged w

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12725

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12724

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivered to a registered user, which can be used for phishing.

PUBLISHED
Vendor
Unknown
Product
Kirki
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12723

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing comment moderation.

PUBLISHED
Vendor
Unknown
Product
Kirki
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12722

Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.

PUBLISHED
Vendor
FTC Software IT Services
Product
FTC E-Commerce Management Panel
Provider severity
HIGH
Conflicts
0

CVE-2026-12721

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

PUBLISHED
Vendor
Unknown
Product
Kirki
Provider severity
HIGH
Conflicts
1

CVE-2026-12720

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.

PUBLISHED
Vendor
Unknown
Product
Kirki
Provider severity
HIGH
Conflicts
1

CVE-2026-1272

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

PUBLISHED
Vendor
IBM
Product
Guardium Data Protection
Provider severity
LOW
Conflicts
0

CVE-2026-12715

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed.

PUBLISHED
Vendor
Google Cloud
Product
Firebase Studio
Provider severity
HIGH
Conflicts
0

CVE-2026-1271

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the user authorization check in public/partials/crop.php and public/partials/coverimg_crop.php. This makes it possible for authenticated attackers, with Subscriber-level access and above,

PUBLISHED
Vendor
metagauss
Product
ProfileGrid – User Profiles, Groups and Communities
Provider severity
MEDIUM
Conflicts
0

CVE-2026-12707

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the network path. Although quiche implements the protections described in Section 9.3 of RFC 9000 to limit server state commitment, it was discovered that the collection of PathEvent

PUBLISHED
Vendor
Cloudflare
Product
quiche
Provider severity
HIGH
Conflicts
0

CVE-2026-12706

A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker could exploit this by providing a specially crafted AVI file containing a malicious RASC video stream. When a user opens or plays the file, the decoder reads from freed heap memory, which could lead to a denial of service (cr

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12705

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.

PUBLISHED
Vendor
ABB, ABB
Product
KNX Update Tool (ABB), KNX Update Tool (BJE)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-12703

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.

PUBLISHED
Vendor
TeamViewer, TeamViewer, TeamViewer
Product
ONE, Remote, Tensor
Provider severity
HIGH
Conflicts
1

CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

PUBLISHED
Vendor
Octopus Deploy
Product
Octopus Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12701

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-control

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Satellite 6.19 for RHEL 9, Red Hat Satellite 6.18 for RHEL 9, Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9, Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.19 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6, Red Hat Satellite 6.17 for RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.18 for RHEL 9, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Update Infrastructure 5, Red Hat Satellite 6.16 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8
Provider severity
CRITICAL
Conflicts
1

CVE-2026-12697

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.

PUBLISHED
Vendor
Unknown
Product
wpForo Forum
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12696

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile, including a logged-in administrator.

PUBLISHED
Vendor
Unknown
Product
wpForo Forum
Provider severity
MEDIUM
Conflicts
1

CVE-2026-12695

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.

PUBLISHED
Vendor
Unknown
Product
miniOrange 2FA
Provider severity
HIGH
Conflicts
1

CVE-2026-12694

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

PUBLISHED
Vendor
Vimesoft Inc.
Product
Enterprise Video Platform
Provider severity
CRITICAL
Conflicts
0

CVE-2026-12693

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

PUBLISHED
Vendor
Vimesoft Inc.
Product
Enterprise Video Platform
Provider severity
CRITICAL
Conflicts
0

CVE-2026-12692

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

PUBLISHED
Vendor
Vimesoft Inc.
Product
Enterprise Video Platform
Provider severity
CRITICAL
Conflicts
0

CVE-2026-12691

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

PUBLISHED
Vendor
Vimesoft Inc.
Product
Enterprise Video Platform
Provider severity
HIGH
Conflicts
0