| CVE-2026-80355 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | medium | 2026-09-18 |
| CVE-2026-80218 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject/2 parses the JWT sub claim (for example user?id=1) with URI.parse/1 and keeps only its query string, discarding the path segment that names the subject the token was issued for. Nothing else restores that binding: AshAuthentication.Jwt.verify/3 checks the signature, exp, nbf, jti and the library-version claims, the purpose check only requires sign_in, and the remaining comparison is over primary-key field names, which are identical across resources. The WebAuthn sign-in and remember-me preparations carry copies of the same helper and drop the path in the same way. The magic link sign-in path pins the subject name against the resource and is not affected. This issue affects ash_authentication: from 3.10.5 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14. | high | 2026-09-18 |
| CVE-2026-78528 | Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | medium | 2026-09-19 |
| CVE-2026-78295 | Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. | high | 2026-09-17 |
| CVE-2026-78294 | Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | medium | 2026-09-19 |
| CVE-2026-78223 | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it with AshAuthentication.Jwt.peek/1, which delegates to Joken.peek_claims/1 and performs no signature check, unlike Jwt.verify/4. The jti, exp and sub claims it returns are written straight onto the revocation record, guarded only by byte_size(token) > 0. Because expires_at derives from the attacker-chosen exp, a forged copy of a genuine token that keeps the real jti but backdates exp yields a revocation row that is already expired: expunge_expired removes it and the genuine token passes revoked? again. Arbitrary jti and sub values can be inserted the same way. This issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14. | medium | 2026-09-18 |
| CVE-2026-74017 | Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. | medium | 2026-09-17 |
| CVE-2026-74005 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | medium | 2026-09-17 |
| CVE-2026-74002 | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. | medium | 2026-09-19 |
| CVE-2026-74000 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | medium | 2026-09-17 |
| CVE-2026-73999 | Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | medium | 2026-09-19 |
| CVE-2026-71568 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity. | medium | 2026-09-18 |
| CVE-2026-66676 | Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | medium | 2026-09-17 |
| CVE-2026-66631 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | high | 2026-09-17 |
| CVE-2026-66630 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | high | 2026-09-19 |
| CVE-2026-66628 | Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. | high | 2026-09-17 |
| CVE-2026-66626 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | high | 2026-09-19 |
| CVE-2026-66625 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | high | 2026-09-17 |
| CVE-2026-66624 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | high | 2026-09-17 |
| CVE-2026-66619 | Administrator SQL Injection in Newsletters <= 4.18 versions. | high | 2026-09-19 |
| CVE-2026-66618 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | high | 2026-09-17 |
| CVE-2026-66617 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | medium | 2026-09-19 |
| CVE-2026-66608 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | medium | 2026-09-17 |
| CVE-2026-66580 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | high | 2026-09-17 |
| CVE-2026-66579 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | medium | 2026-09-19 |
| CVE-2026-66578 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | medium | 2026-09-17 |
| CVE-2026-66577 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | medium | 2026-09-19 |
| CVE-2026-66576 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | medium | 2026-09-17 |
| CVE-2026-66575 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | medium | 2026-09-17 |
| CVE-2026-66574 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | medium | 2026-09-19 |
| CVE-2026-66573 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | medium | 2026-09-17 |
| CVE-2026-66572 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | medium | 2026-09-19 |
| CVE-2026-66571 | Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. | high | 2026-09-17 |
| CVE-2026-62108 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. | critical | 2026-09-17 |
| CVE-2026-62104 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | critical | 2026-09-19 |
| CVE-2026-62101 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | critical | 2026-09-17 |
| CVE-2026-14850 | The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership. | high | 2026-09-18 |
| CVE-2026-92932 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http://') === 0 || strpos($input, 'https://') === 0. Because PHP's && operator has higher precedence than ||, the expression is evaluated as ($options['readFile'] && strpos($input, 'http://') === 0) || strpos($input, 'https://') === 0. As a result, when a caller explicitly sets the readFile option to false to disable file and URL reading, an input string beginning with https:// still satisfies the condition and triggers a network fetch via HttpSocket (configured to follow up to 10 redirects). The http:// branch is correctly gated by the readFile flag, but the https:// branch is not. An attacker who can influence the $input parameter passed to Xml::build() can therefore force the application to issue an outbound HTTPS request to an attacker-controlled or internal URL, even though the caller intended to suppress all remote reads. The fetched response is parsed as XML and may be returned to the caller, enabling information disclosure from internal services or external targets. This constitutes a Server-Side Request Forgery (SSRF) weakness with an information-disclosure impact. The vulnerability requires that the code path in Xml::build() be reachable with attacker-controlled input and that the readFile option be set to false (or the caller expects it to be false). | medium | 2026-09-18 |
| CVE-2026-92921 | admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligible computational effort. | medium | 2026-09-22 |
| CVE-2026-92920 | admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user's locked status and session expiry resets on each request. | medium | 2026-09-22 |
| CVE-2026-92919 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary files accessible to the server process. | high | 2026-09-22 |
| CVE-2026-92918 | admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access. | high | 2026-09-22 |
| CVE-2026-92904 | A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is restricted by a permission filter can enumerate job invocation IDs and read the live output, rendered script, and input values for other users' job invocations within their own organizations. | medium | 2026-09-18 |
| CVE-2026-81481 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | high | 2026-09-18 |
| CVE-2026-53681 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | No Score | 2026-09-17 |
| CVE-2026-92925 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS). | medium | 2026-09-22 |
| CVE-2026-92917 | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determines sandbox state by calling SandboxExtension::isSandboxed() without a Source argument, which reports only the global sandbox flag that Grav never enables, so the guard added in GHSA-mc5q-6hpj-rp7j never executes. As a result, an authenticated user with page-edit rights can render {{ config|print_r }} in page content with Twig processing enabled and dump Grav's entire merged configuration — print_r reflects the real Config object held in a private property of the SandboxConfig facade, bypassing its path redaction — exposing plugin secrets such as SMTP credentials, API tokens, webhook secrets and cache backend passwords. Grav 1.7 is not affected because it ships no Twig content sandbox. The issue is fixed in 2.0.22, where the affected filters are registered with Twig's needs_is_sandboxed flag. | high | 2026-09-19 |
| CVE-2026-92916 | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: InitializeProcessor::handleDebuggerRequest() intercepts any path containing /__clockwork/ during bootstrap and passes it to Debugger::debuggerRequest(), which performs no user lookup, IP restriction, or Clockwork authenticator check, and also supports anonymous pagination over the entire stored history. With the shipped censored: false default, each stored record contains raw request cookies (including Grav's session cookie, whose value is the PHP session id, allowing an attacker to resume another user's session, including an authenticated admin's), the full parsed request body (Grav's login form posts data[username]/data[password], so passwords are stored in plaintext because Clockwork's password filter only inspects top-level keys), and the site's entire system and plugin configuration, including operator-saved secrets such as SMTP credentials, third-party API keys, and licence keys. Authorization and X-API-Token headers are stored even when censored: true. On Grav 2.0, setting provider: debugbar does not avoid the issue because Grav forces the Clockwork provider for requests preferring a JSON response. The issue is fixed in 1.7.53.4 and 2.0.22, which restrict /__clockwork/ to server-local requests or requests presenting the new system.debugger.token secret and strip cookies and credential headers from stored records. Workarounds include setting debugger.enabled: false or blocking /__clockwork/ at the web server or CDN. | high | 2026-09-18 |
| CVE-2026-92915 | WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly from the query string, and calls User::sendVerificationLink() with no session requirement, no CSRF/global token, no relationship check between caller and target, and no enforceRateLimit() call. The only intended throttle is keyed to the caller's own session, so cookie-less requests are never limited. An unauthenticated remote attacker can therefore cause an arbitrary number of verification emails to be sent to any account ID, and can enumerate accounts and their verification status from the three distinct JSON responses ("Verification Sent", "Already verified", "Unknown error"). In addition, createVerificationCode() invokes $user->setRecoverPass() and saves the user, so each anonymous request writes a live password-recovery token onto the targeted account; that token is embedded in base64 in the verification link emailed to the account owner and is accepted by objects/userRecoverPassSave.json.php as the credential for setting a new password. | medium | 2026-09-22 |
| CVE-2026-92914 | AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass the second factor by sending a parameter-less GET request to verifyChallenge.json.php, which evaluates null == null and marks authentication complete. | high | 2026-09-22 |