| CVE-2026-65605 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as <img> are skipped by that check, a payload like <img src=x onerror=...> is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Because the desktop renderer runs with nodeIntegration enabled, the injected script can reach require and escalate to arbitrary command execution. | critical | 2026-07-23 |
| CVE-2026-65550 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | medium | 2026-07-23 |
| CVE-2026-65540 | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | high | 2026-07-23 |
| CVE-2026-65539 | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | high | 2026-07-23 |
| CVE-2026-65538 | Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | medium | 2026-07-23 |
| CVE-2026-65537 | Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | medium | 2026-07-23 |
| CVE-2026-65536 | Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | medium | 2026-07-23 |
| CVE-2026-65535 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | medium | 2026-07-23 |
| CVE-2026-65534 | Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | medium | 2026-07-23 |
| CVE-2026-65533 | Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | medium | 2026-07-23 |
| CVE-2026-65532 | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | high | 2026-07-23 |
| CVE-2026-65531 | Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | medium | 2026-07-23 |
| CVE-2026-65530 | Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | medium | 2026-07-23 |
| CVE-2026-65529 | Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | medium | 2026-07-23 |
| CVE-2026-65528 | Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | medium | 2026-07-23 |
| CVE-2026-65527 | Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | medium | 2026-07-23 |
| CVE-2026-65526 | Contributor SQL Injection in Visualizer <= 4.0.6 versions. | high | 2026-07-30 |
| CVE-2026-65525 | Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | medium | 2026-07-23 |
| CVE-2026-65524 | Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | medium | 2026-07-23 |
| CVE-2026-65522 | Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | medium | 2026-07-23 |
| CVE-2026-65521 | Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | medium | 2026-07-23 |
| CVE-2026-65519 | Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | medium | 2026-07-23 |
| CVE-2026-65518 | Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | medium | 2026-07-23 |
| CVE-2026-65516 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | high | 2026-07-23 |
| CVE-2026-65514 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | medium | 2026-07-23 |
| CVE-2026-65512 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. | medium | 2026-07-23 |
| CVE-2026-65511 | Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | high | 2026-07-23 |
| CVE-2026-65510 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | high | 2026-07-23 |
| CVE-2026-65506 | Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | medium | 2026-07-23 |
| CVE-2026-65505 | Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | medium | 2026-07-23 |
| CVE-2026-65503 | Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | medium | 2026-07-23 |
| CVE-2026-65501 | Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. | medium | 2026-07-23 |
| CVE-2026-65500 | Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | high | 2026-07-23 |
| CVE-2026-65499 | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | medium | 2026-07-23 |
| CVE-2026-65498 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | medium | 2026-07-23 |
| CVE-2026-65497 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | high | 2026-07-23 |
| CVE-2026-65496 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | medium | 2026-07-23 |
| CVE-2026-65495 | Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. | high | 2026-07-23 |
| CVE-2026-65494 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | high | 2026-07-23 |
| CVE-2026-65493 | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. | high | 2026-07-23 |
| CVE-2026-65492 | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. | high | 2026-07-23 |
| CVE-2026-65491 | Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. | medium | 2026-07-23 |
| CVE-2026-65490 | Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions. | medium | 2026-07-23 |
| CVE-2026-65489 | Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | medium | 2026-07-23 |
| CVE-2026-65488 | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | high | 2026-07-23 |
| CVE-2026-65487 | Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | medium | 2026-07-23 |
| CVE-2026-65486 | Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | medium | 2026-07-23 |
| CVE-2026-65485 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | medium | 2026-07-23 |
| CVE-2026-65484 | Contributor Broken Access Control in Style Kits <= 2.6.5 versions. | medium | 2026-07-23 |
| CVE-2026-65483 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | medium | 2026-07-23 |