Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43999
Total
3569
Critical
13202
High
13005
Medium
CVE ID Severity Score Description Published
CVE-2026-78562 HIGH 8.1 The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for … Aug 25, 2026
CVE-2026-77146 UNKNOWN The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to … Aug 25, 2026
CVE-2026-77145 UNKNOWN The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with … Aug 25, 2026
CVE-2026-77144 UNKNOWN The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. … Aug 25, 2026
CVE-2026-77143 UNKNOWN The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a … Aug 25, 2026
CVE-2026-77142 UNKNOWN The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, … Aug 25, 2026
CVE-2026-77141 UNKNOWN The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check … Aug 25, 2026
CVE-2026-77140 UNKNOWN The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that … Aug 25, 2026
CVE-2026-77139 UNKNOWN The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An … Aug 25, 2026
CVE-2026-77138 UNKNOWN The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted … Aug 25, 2026
CVE-2026-77137 UNKNOWN The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary … Aug 25, 2026
CVE-2026-77136 UNKNOWN The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View … Aug 25, 2026
CVE-2026-77135 UNKNOWN The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to … Aug 25, 2026
CVE-2026-77134 UNKNOWN The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor … Aug 25, 2026
CVE-2026-77133 UNKNOWN The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default … Aug 25, 2026
CVE-2026-77131 UNKNOWN When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already … Aug 25, 2026
CVE-2026-77130 UNKNOWN The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate … Aug 25, 2026
CVE-2026-77129 UNKNOWN The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event … Aug 25, 2026
CVE-2026-77128 UNKNOWN The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or … Aug 25, 2026
CVE-2026-77127 UNKNOWN The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, … Aug 25, 2026
CVE-2026-63587 HIGH 8.6 The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry … Aug 25, 2026
CVE-2026-63586 CRITICAL 9.8 The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without … Aug 25, 2026
CVE-2026-56096 UNKNOWN The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. … Aug 25, 2026
CVE-2026-56095 UNKNOWN The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and … Aug 25, 2026
CVE-2026-56094 UNKNOWN The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder … Aug 25, 2026