| CVE-2026-96836 | Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. | high | 2026-09-30 |
| CVE-2026-96835 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. | medium | 2026-09-30 |
| CVE-2026-96834 | Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | medium | 2026-09-30 |
| CVE-2026-96833 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | high | 2026-09-30 |
| CVE-2026-96832 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | high | 2026-09-30 |
| CVE-2026-96831 | Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | high | 2026-09-30 |
| CVE-2026-96830 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions. | high | 2026-09-30 |
| CVE-2026-96829 | Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions. | medium | 2026-09-30 |
| CVE-2026-96828 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | high | 2026-09-30 |
| CVE-2026-96827 | Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | high | 2026-09-30 |
| CVE-2026-96825 | Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. | medium | 2026-09-30 |
| CVE-2026-96824 | Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. | medium | 2026-09-30 |
| CVE-2026-96823 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | high | 2026-09-30 |
| CVE-2026-96822 | Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | critical | 2026-09-30 |
| CVE-2026-96821 | Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions. | medium | 2026-09-30 |
| CVE-2026-96820 | Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions. | high | 2026-09-30 |
| CVE-2026-96819 | Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions. | high | 2026-09-30 |
| CVE-2026-96818 | Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | high | 2026-09-30 |
| CVE-2026-96817 | Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | high | 2026-09-30 |
| CVE-2026-96816 | Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. | high | 2026-09-30 |
| CVE-2026-96815 | Custom role Privilege Escalation in Vitepos <= 3.5.0 versions. | high | 2026-09-30 |
| CVE-2026-96814 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions. | high | 2026-09-30 |
| CVE-2026-96740 | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker. | medium | 2026-09-30 |
| CVE-2026-96649 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode. | high | 2026-09-30 |
| CVE-2026-96538 | WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally. | high | 2026-09-30 |
| CVE-2026-96450 | Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions. | medium | 2026-09-30 |
| CVE-2026-96440 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter. | high | 2026-09-30 |
| CVE-2026-96352 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | high | 2026-09-30 |
| CVE-2026-96351 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. | high | 2026-09-30 |
| CVE-2026-96350 | Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. | critical | 2026-09-30 |
| CVE-2026-96349 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | critical | 2026-09-30 |
| CVE-2026-96348 | Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | high | 2026-09-30 |
| CVE-2026-96347 | Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. | medium | 2026-09-30 |
| CVE-2026-96346 | Author SQL Injection in WP ERP <= 1.17.9 versions. | high | 2026-09-30 |
| CVE-2026-96345 | Administrator SQL Injection in Estatik <= 4.3.5 versions. | high | 2026-09-30 |
| CVE-2026-96344 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | high | 2026-09-30 |
| CVE-2026-96343 | Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. | high | 2026-09-30 |
| CVE-2026-96342 | Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | medium | 2026-09-30 |
| CVE-2026-96338 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | medium | 2026-09-30 |
| CVE-2026-96326 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | high | 2026-09-30 |
| CVE-2026-96281 | On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities. | medium | 2026-09-30 |
| CVE-2026-95616 | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | high | 2026-09-30 |
| CVE-2026-95587 | Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | high | 2026-09-30 |
| CVE-2026-95531 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | high | 2026-09-30 |
| CVE-2026-95509 | Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading. | high | 2026-09-30 |
| CVE-2026-95371 | Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | medium | 2026-09-30 |
| CVE-2026-95359 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | low | 2026-09-30 |
| CVE-2026-95357 | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | critical | 2026-09-30 |
| CVE-2026-95356 | Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | critical | 2026-09-30 |
| CVE-2026-95355 | Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | high | 2026-09-30 |