Search Results (14743 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97309 2026-10-06 N/A
Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226.
CVE-2026-97303 2026-10-06 7.6 High
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.
CVE-2026-94299 2026-10-06 6.5 Medium
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39751 2026-10-06 7.5 High
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-39749 2026-10-06 6.5 Medium
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
CVE-2026-39599 2026-10-06 4.3 Medium
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
CVE-2026-32578 2026-10-06 7.1 High
Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions.
CVE-2026-25433 2026-10-06 7.1 High
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
CVE-2026-105072 2026-10-06 7.5 High
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
CVE-2026-104386 2026-10-06 6.5 Medium
Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
CVE-2026-103337 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.
CVE-2026-103086 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.
CVE-2026-105703 1 Phpgurukul 2 User Registration & Login And User Management System, User Registration Login And User Management System 2026-10-06 4.7 Medium
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVE-2026-103762 2 B3log, Siyuan 2 Siyuan, Siyuan 2026-10-06 5.3 Medium
SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.
CVE-2026-103271 1 Ghost 1 Ghost 2026-10-06 7.5 High
Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.
CVE-2026-103266 1 Ghost 1 Ghost 2026-10-06 7.1 High
Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify that member's name, and inject content into newsletters sent to the member. Depending on the recipient's email client, the injected content may be rendered, resulting in HTML injection or cross-site scripting (XSS).
CVE-2026-105684 1 Penpot 1 Penpot 2026-10-05 4.3 Medium
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0.
CVE-2026-105695 1 Penpot 1 Penpot 2026-10-05 5.9 Medium
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
CVE-2026-105209 1 Zitadel 1 Zitadel 2026-10-05 9.6 Critical
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.