Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84802 | MEDIUM | 4.3 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can … | Sep 02, 2026 |
| CVE-2026-84801 | HIGH | 8.8 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs … | Sep 02, 2026 |
| CVE-2026-84800 | HIGH | 7.1 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, … | Sep 02, 2026 |
| CVE-2026-84799 | MEDIUM | 4.3 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with … | Sep 02, 2026 |
| CVE-2026-84798 | HIGH | 7.1 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled … | Sep 02, 2026 |
| CVE-2026-84797 | MEDIUM | 6.3 | Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers … | Sep 02, 2026 |
| CVE-2026-84796 | HIGH | 8.8 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with … | Sep 02, 2026 |
| CVE-2026-84795 | CRITICAL | 9.8 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with … | Sep 02, 2026 |
| CVE-2026-84794 | HIGH | 7.1 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their … | Sep 02, 2026 |
| CVE-2026-84793 | MEDIUM | 4.8 | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can … | Sep 02, 2026 |
| CVE-2026-84792 | MEDIUM | 4.3 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections … | Sep 02, 2026 |
| CVE-2026-84781 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | Sep 02, 2026 |
| CVE-2026-84780 | MEDIUM | 5.3 | Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. | Sep 02, 2026 |
| CVE-2026-84775 | MEDIUM | 5.3 | Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions. | Sep 02, 2026 |
| CVE-2026-84772 | MEDIUM | 5.5 | Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions. | Sep 02, 2026 |
| CVE-2026-84771 | MEDIUM | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. | Sep 02, 2026 |
| CVE-2026-84770 | HIGH | 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | Sep 02, 2026 |
| CVE-2026-84764 | HIGH | 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | Sep 02, 2026 |
| CVE-2026-84760 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. | Sep 02, 2026 |
| CVE-2026-84759 | HIGH | 7.1 | Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. | Sep 02, 2026 |
| CVE-2026-84217 | MEDIUM | 5.4 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Classified Listing: from n/a through 6.1.1. | Sep 02, 2026 |
| CVE-2026-83562 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. | Sep 02, 2026 |
| CVE-2026-82223 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. | Sep 02, 2026 |
| CVE-2026-81775 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. | Sep 02, 2026 |
| CVE-2026-81774 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | Sep 02, 2026 |