| CVE-2026-97688 | urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0. | medium | 2026-09-30 |
| CVE-2026-97687 | urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0. | high | 2026-09-30 |
| CVE-2026-97685 | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey. | high | 2026-09-30 |
| CVE-2026-9737 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure. | high | 2026-09-30 |
| CVE-2026-97347 | The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings. | high | 2026-09-30 |
| CVE-2026-97316 | The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services. | medium | 2026-09-30 |
| CVE-2026-97302 | Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions. | medium | 2026-09-30 |
| CVE-2026-97301 | Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions. | medium | 2026-09-30 |
| CVE-2026-97299 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | medium | 2026-09-30 |
| CVE-2026-97298 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions. | medium | 2026-09-30 |
| CVE-2026-97293 | Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions. | high | 2026-09-30 |
| CVE-2026-97292 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. | medium | 2026-09-30 |
| CVE-2026-97291 | Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | high | 2026-09-30 |
| CVE-2026-97290 | Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | high | 2026-09-30 |
| CVE-2026-97289 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | high | 2026-09-30 |
| CVE-2026-97288 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | medium | 2026-09-30 |
| CVE-2026-97285 | Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | medium | 2026-09-30 |
| CVE-2026-97282 | Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | medium | 2026-09-30 |
| CVE-2026-97279 | Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. | medium | 2026-09-30 |
| CVE-2026-97274 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | critical | 2026-09-30 |
| CVE-2026-97272 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. | high | 2026-09-30 |
| CVE-2026-97271 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | high | 2026-09-30 |
| CVE-2026-97270 | Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions. | medium | 2026-09-30 |
| CVE-2026-97267 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | medium | 2026-09-30 |
| CVE-2026-97266 | Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions. | medium | 2026-09-30 |
| CVE-2026-97265 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | medium | 2026-09-30 |
| CVE-2026-97262 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. | medium | 2026-09-30 |
| CVE-2026-97261 | Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions. | medium | 2026-09-30 |
| CVE-2026-97259 | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4. | medium | 2026-09-30 |
| CVE-2026-97256 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | high | 2026-09-30 |
| CVE-2026-97253 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0. | high | 2026-09-30 |
| CVE-2026-97250 | Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | high | 2026-09-30 |
| CVE-2026-97249 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | medium | 2026-09-30 |
| CVE-2026-97248 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | critical | 2026-09-30 |
| CVE-2026-97247 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | medium | 2026-09-30 |
| CVE-2026-97246 | Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. | medium | 2026-09-30 |
| CVE-2026-97245 | Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions. | high | 2026-09-30 |
| CVE-2026-97244 | Contributor Path Traversal in Creator LMS <= 1.2.19 versions. | high | 2026-09-30 |
| CVE-2026-97243 | Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. | medium | 2026-09-30 |
| CVE-2026-97242 | Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions. | medium | 2026-09-30 |
| CVE-2026-97241 | Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. | high | 2026-09-30 |
| CVE-2026-97240 | Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | high | 2026-09-30 |
| CVE-2026-97239 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | medium | 2026-09-30 |
| CVE-2026-97238 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | medium | 2026-09-30 |
| CVE-2026-97237 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | high | 2026-09-30 |
| CVE-2026-97236 | Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | medium | 2026-09-30 |
| CVE-2026-97235 | Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | high | 2026-09-30 |
| CVE-2026-97222 | A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash. | medium | 2026-09-30 |
| CVE-2026-97197 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | high | 2026-09-30 |
| CVE-2026-97196 | Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9. | critical | 2026-09-30 |