Updated CVEs

IDDescriptionSeverityUpdated
CVE-2026-97688urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.
medium
2026-09-30
CVE-2026-97687urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.
high
2026-09-30
CVE-2026-97685An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
high
2026-09-30
CVE-2026-9737During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.
high
2026-09-30
CVE-2026-97347The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.
high
2026-09-30
CVE-2026-97316The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
medium
2026-09-30
CVE-2026-97302Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
medium
2026-09-30
CVE-2026-97301Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
medium
2026-09-30
CVE-2026-97299Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
medium
2026-09-30
CVE-2026-97298Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
medium
2026-09-30
CVE-2026-97293Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
high
2026-09-30
CVE-2026-97292Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
medium
2026-09-30
CVE-2026-97291Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
high
2026-09-30
CVE-2026-97290Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
high
2026-09-30
CVE-2026-97289Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
high
2026-09-30
CVE-2026-97288Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
medium
2026-09-30
CVE-2026-97285Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
medium
2026-09-30
CVE-2026-97282Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
medium
2026-09-30
CVE-2026-97279Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.
medium
2026-09-30
CVE-2026-97274Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
critical
2026-09-30
CVE-2026-97272Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.
high
2026-09-30
CVE-2026-97271Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
high
2026-09-30
CVE-2026-97270Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
medium
2026-09-30
CVE-2026-97267Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
medium
2026-09-30
CVE-2026-97266Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.
medium
2026-09-30
CVE-2026-97265Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
medium
2026-09-30
CVE-2026-97262Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.
medium
2026-09-30
CVE-2026-97261Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
medium
2026-09-30
CVE-2026-97259Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.
medium
2026-09-30
CVE-2026-97256Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
high
2026-09-30
CVE-2026-97253Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0.
high
2026-09-30
CVE-2026-97250Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
high
2026-09-30
CVE-2026-97249Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
medium
2026-09-30
CVE-2026-97248Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
critical
2026-09-30
CVE-2026-97247Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
medium
2026-09-30
CVE-2026-97246Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
medium
2026-09-30
CVE-2026-97245Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.
high
2026-09-30
CVE-2026-97244Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
high
2026-09-30
CVE-2026-97243Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
medium
2026-09-30
CVE-2026-97242Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.
medium
2026-09-30
CVE-2026-97241Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
high
2026-09-30
CVE-2026-97240Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
high
2026-09-30
CVE-2026-97239Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
medium
2026-09-30
CVE-2026-97238Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
medium
2026-09-30
CVE-2026-97237Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
high
2026-09-30
CVE-2026-97236Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
medium
2026-09-30
CVE-2026-97235Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
high
2026-09-30
CVE-2026-97222A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.
medium
2026-09-30
CVE-2026-97197Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
high
2026-09-30
CVE-2026-97196Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
critical
2026-09-30