CVE IDSeverityCVSSDescriptionDate
CVE-2026-84800HIGH7.1Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsControlle…2026-09-02
CVE-2026-84801HIGH8.8Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, all…2026-09-02
CVE-2026-84802MEDIUM4.3Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsControll…2026-09-02
CVE-2026-84803CRITICAL9.0SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplet…2026-09-02
CVE-2026-84804MEDIUM5.4Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, …2026-09-02
CVE-2026-84805MEDIUM4.3Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privileg…2026-09-02
CVE-2026-84806MEDIUM5.4Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows auth…2026-09-02
CVE-2026-84807MEDIUM5.4Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the def…2026-09-02
CVE-2026-84808MEDIUM4.3Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collectio…2026-09-02
CVE-2026-84835MEDIUM5.3Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Con…2026-09-02
CVE-2026-16647NAN/AAuthentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Fun…2026-09-02
CVE-2026-18986MEDIUM4.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal E…2026-09-02
CVE-2026-73474NAN/AServer-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forg…2026-09-02
CVE-2026-73475NAN/AIncorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects C…2026-09-02
CVE-2026-73476NAN/AImproper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalat…2026-09-02
CVE-2026-73477NAN/AIncorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick …2026-09-02
CVE-2026-73478NAN/AIncorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff version…2026-09-02
CVE-2026-76755NAN/AVulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.…2026-09-02
CVE-2026-76756NAN/AVulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.…2026-09-02
CVE-2026-76757NAN/AVulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.…2026-09-02
CVE-2026-76758NAN/AVulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.…2026-09-02
CVE-2026-76759NAN/AVulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.…2026-09-02
CVE-2026-76782NAN/AVulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.…2026-09-02
CVE-2026-81158NAN/AIncorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity…2026-09-02
CVE-2026-81159NAN/AObservable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affe…2026-09-02
CVE-2026-81160NAN/AImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal S…2026-09-02
CVE-2026-81161NAN/APrivilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privileg…2026-09-02
CVE-2026-81162NAN/AInsertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) …2026-09-02
CVE-2026-81164NAN/AMissing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity P…2026-09-02
CVE-2026-81165NAN/AIncorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versi…2026-09-02
CVE-2026-81166NAN/AMissing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue a…2026-09-02
CVE-2026-81167MEDIUM4.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal A…2026-09-02
CVE-2026-81168NAN/AAuthentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows…2026-09-02
CVE-2026-81201NAN/AImproper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal M…2026-09-02
CVE-2026-81205NAN/AImproper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal L…2026-09-02
CVE-2026-81269NAN/AMissing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data fie…2026-09-02
CVE-2023-3360LOW3.3The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could …2026-09-02
CVE-2024-3773MEDIUM5.9The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode at…2026-09-02
CVE-2024-7956NAN/AA vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. …2026-09-02
CVE-2025-13398NAN/ARejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned …2026-09-02
CVE-2025-15481MEDIUM5.3The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that disc…2026-09-02
CVE-2025-15485HIGH8.2The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoint…2026-09-02
CVE-2025-15489MEDIUM5.3The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthe…2026-09-02
CVE-2025-15490MEDIUM5.3The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticat…2026-09-02
CVE-2025-15692LOW3.5The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before o…2026-09-02
CVE-2025-8945MEDIUM5.3The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protecti…2026-09-02
CVE-2025-9314CRITICAL9.8The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerabi…2026-09-02
CVE-2026-10821MEDIUM6.6The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origin…2026-09-02
CVE-2026-14255MEDIUM5.5A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Rec…2026-09-02
CVE-2026-14326LOW3.8The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments …2026-09-02
4 / 7715