| CVE-2026-65487 | Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | medium | 2026-07-23 |
| CVE-2026-65486 | Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | medium | 2026-07-23 |
| CVE-2026-65485 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | medium | 2026-07-23 |
| CVE-2026-65484 | Contributor Broken Access Control in Style Kits <= 2.6.5 versions. | medium | 2026-07-23 |
| CVE-2026-65483 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | medium | 2026-07-23 |
| CVE-2026-65482 | Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | medium | 2026-07-23 |
| CVE-2026-65481 | Contributor Local File Inclusion in Vino <= 1.9 versions. | high | 2026-07-23 |
| CVE-2026-65480 | Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions. | medium | 2026-07-23 |
| CVE-2026-65479 | Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | medium | 2026-07-23 |
| CVE-2026-65478 | Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. | medium | 2026-07-23 |
| CVE-2026-65477 | Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. | high | 2026-07-23 |
| CVE-2026-65476 | Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. | medium | 2026-07-23 |
| CVE-2026-65475 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. | medium | 2026-07-23 |
| CVE-2026-65474 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | medium | 2026-07-23 |
| CVE-2026-65473 | Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions. | medium | 2026-07-23 |
| CVE-2026-65472 | Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. | medium | 2026-07-23 |
| CVE-2026-65471 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | critical | 2026-07-23 |
| CVE-2026-65470 | Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | medium | 2026-07-23 |
| CVE-2026-65469 | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | medium | 2026-07-23 |
| CVE-2026-65468 | Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | medium | 2026-07-23 |
| CVE-2026-65467 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | medium | 2026-07-23 |
| CVE-2026-65466 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | medium | 2026-07-23 |
| CVE-2026-65465 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. | medium | 2026-07-23 |
| CVE-2026-65464 | Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. | medium | 2026-07-23 |
| CVE-2026-65463 | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | medium | 2026-07-23 |
| CVE-2026-65462 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | high | 2026-07-23 |
| CVE-2026-65461 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | critical | 2026-07-23 |
| CVE-2026-65460 | Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. | medium | 2026-07-23 |
| CVE-2026-65458 | Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions. | medium | 2026-07-23 |
| CVE-2026-65457 | Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. | medium | 2026-07-23 |
| CVE-2026-65456 | Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. | medium | 2026-07-23 |
| CVE-2026-65455 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | critical | 2026-07-23 |
| CVE-2026-65454 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | high | 2026-07-23 |
| CVE-2026-65453 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | medium | 2026-07-23 |
| CVE-2026-65452 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | medium | 2026-07-23 |
| CVE-2026-65451 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | high | 2026-07-23 |
| CVE-2026-65450 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | high | 2026-07-23 |
| CVE-2026-65449 | Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | medium | 2026-07-23 |
| CVE-2026-65319 | Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and extract plain-text content of all stored articles, including private newsletter content, personal page-saves, and articles from any user's private subscriptions. | high | 2026-07-23 |
| CVE-2026-65318 | Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database endpoints or cloud instance metadata services to retrieve sensitive credentials. | critical | 2026-07-23 |
| CVE-2026-65317 | Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and port parameters to the /api/connect endpoint to cause the server to issue outbound GET requests to attacker-controlled infrastructure. | critical | 2026-07-23 |
| CVE-2026-65316 | XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can enumerate log records across all job groups by calling the logDetailCat endpoint with incremented logId parameter values, bypassing the permission check present in the sibling logDetailPage endpoint, and retrieve sensitive log content from restricted job groups. | high | 2026-07-23 |
| CVE-2026-65314 | Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions. | medium | 2026-07-23 |
| CVE-2026-65069 | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | medium | 2026-07-23 |
| CVE-2026-65068 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | low | 2026-07-23 |
| CVE-2026-65067 | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | low | 2026-07-23 |
| CVE-2026-65066 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | low | 2026-07-23 |
| CVE-2026-65064 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h with open(path, O_RDWR | O_CREAT | O_CLOEXEC, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | low | 2026-07-23 |
| CVE-2026-65063 | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | low | 2026-07-23 |
| CVE-2026-65062 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open. | low | 2026-07-23 |