Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42028
Total
3422
Critical
12413
High
12340
Medium
CVE ID Severity Score Description Published
CVE-2026-84802 MEDIUM 4.3 Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can … Sep 02, 2026
CVE-2026-84801 HIGH 8.8 Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs … Sep 02, 2026
CVE-2026-84800 HIGH 7.1 Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, … Sep 02, 2026
CVE-2026-84799 MEDIUM 4.3 Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with … Sep 02, 2026
CVE-2026-84798 HIGH 7.1 Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled … Sep 02, 2026
CVE-2026-84797 MEDIUM 6.3 Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers … Sep 02, 2026
CVE-2026-84796 HIGH 8.8 Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with … Sep 02, 2026
CVE-2026-84795 CRITICAL 9.8 Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with … Sep 02, 2026
CVE-2026-84794 HIGH 7.1 Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their … Sep 02, 2026
CVE-2026-84793 MEDIUM 4.8 Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can … Sep 02, 2026
CVE-2026-84792 MEDIUM 4.3 Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections … Sep 02, 2026
CVE-2026-84781 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. Sep 02, 2026
CVE-2026-84780 MEDIUM 5.3 Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. Sep 02, 2026
CVE-2026-84775 MEDIUM 5.3 Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions. Sep 02, 2026
CVE-2026-84772 MEDIUM 5.5 Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions. Sep 02, 2026
CVE-2026-84771 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. Sep 02, 2026
CVE-2026-84770 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. Sep 02, 2026
CVE-2026-84764 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. Sep 02, 2026
CVE-2026-84760 MEDIUM 5.3 Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. Sep 02, 2026
CVE-2026-84759 HIGH 7.1 Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. Sep 02, 2026
CVE-2026-84217 MEDIUM 5.4 Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Classified Listing: from n/a through 6.1.1. Sep 02, 2026
CVE-2026-83562 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. Sep 02, 2026
CVE-2026-82223 MEDIUM 6.5 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. Sep 02, 2026
CVE-2026-81775 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. Sep 02, 2026
CVE-2026-81774 HIGH 7.5 Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. Sep 02, 2026