Updated CVEs

IDDescriptionSeverityUpdated
CVE-2026-65487Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
medium
2026-07-23
CVE-2026-65486Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
medium
2026-07-23
CVE-2026-65485Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
medium
2026-07-23
CVE-2026-65484Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
medium
2026-07-23
CVE-2026-65483Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
medium
2026-07-23
CVE-2026-65482Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
medium
2026-07-23
CVE-2026-65481Contributor Local File Inclusion in Vino <= 1.9 versions.
high
2026-07-23
CVE-2026-65480Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.
medium
2026-07-23
CVE-2026-65479Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
medium
2026-07-23
CVE-2026-65478Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
medium
2026-07-23
CVE-2026-65477Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
high
2026-07-23
CVE-2026-65476Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
medium
2026-07-23
CVE-2026-65475Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
medium
2026-07-23
CVE-2026-65474Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
medium
2026-07-23
CVE-2026-65473Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
medium
2026-07-23
CVE-2026-65472Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
medium
2026-07-23
CVE-2026-65471Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
critical
2026-07-23
CVE-2026-65470Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
medium
2026-07-23
CVE-2026-65469Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
medium
2026-07-23
CVE-2026-65468Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
medium
2026-07-23
CVE-2026-65467Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
medium
2026-07-23
CVE-2026-65466Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
medium
2026-07-23
CVE-2026-65465Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
medium
2026-07-23
CVE-2026-65464Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
medium
2026-07-23
CVE-2026-65463Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
medium
2026-07-23
CVE-2026-65462Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
high
2026-07-23
CVE-2026-65461Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
critical
2026-07-23
CVE-2026-65460Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
medium
2026-07-23
CVE-2026-65458Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
medium
2026-07-23
CVE-2026-65457Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
medium
2026-07-23
CVE-2026-65456Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
medium
2026-07-23
CVE-2026-65455Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
critical
2026-07-23
CVE-2026-65454Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
high
2026-07-23
CVE-2026-65453Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
medium
2026-07-23
CVE-2026-65452Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
medium
2026-07-23
CVE-2026-65451Contributor SQL Injection in MapSVG <= 8.14.0 versions.
high
2026-07-23
CVE-2026-65450Contributor SQL Injection in MapSVG <= 8.14.0 versions.
high
2026-07-23
CVE-2026-65449Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
medium
2026-07-23
CVE-2026-65319Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and extract plain-text content of all stored articles, including private newsletter content, personal page-saves, and articles from any user's private subscriptions.
high
2026-07-23
CVE-2026-65318Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database endpoints or cloud instance metadata services to retrieve sensitive credentials.
critical
2026-07-23
CVE-2026-65317Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and port parameters to the /api/connect endpoint to cause the server to issue outbound GET requests to attacker-controlled infrastructure.
critical
2026-07-23
CVE-2026-65316XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can enumerate log records across all job groups by calling the logDetailCat endpoint with incremented logId parameter values, bypassing the permission check present in the sibling logDetailPage endpoint, and retrieve sensitive log content from restricted job groups.
high
2026-07-23
CVE-2026-65314Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions.
medium
2026-07-23
CVE-2026-65069Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
medium
2026-07-23
CVE-2026-65068Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
low
2026-07-23
CVE-2026-65067Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
low
2026-07-23
CVE-2026-65066Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
low
2026-07-23
CVE-2026-65064Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h with open(path, O_RDWR | O_CREAT | O_CLOEXEC, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
low
2026-07-23
CVE-2026-65063Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
low
2026-07-23
CVE-2026-65062Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.
low
2026-07-23