Common Vulnerabilities and Exposures (CVE)

CVE-2026-105146

Oct 4, 2026 09:30:12 UTC

A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the component Admin Medal Moderation. ...

CVE-2026-97307

Oct 4, 2026 09:08:23 UTC

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.

CVE-2026-105145

Oct 4, 2026 09:00:11 UTC

A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpoint. The manipulation leads to inf...

CVE-2026-103355

Oct 4, 2026 08:00:09 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL In...

CVE-2026-103344

Oct 4, 2026 08:00:09 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XS...

CVE-2026-105144

Oct 4, 2026 08:00:06 UTC

A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static File Router. Executing a manipulation can lead to path t...

CVE-2026-105141

Oct 4, 2026 07:45:15 UTC

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handle...

CVE-2026-105137

Oct 4, 2026 07:30:11 UTC

A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launc...

CVE-2026-103062

Oct 4, 2026 07:00:43 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6.

CVE-2026-97276

Oct 4, 2026 07:00:43 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14.

CVE-2026-103354

Oct 4, 2026 07:00:42 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence ...

CVE-2026-105135

Oct 4, 2026 06:15:12 UTC

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code inj...

CVE-2026-97332

Oct 4, 2026 06:00:24 UTC

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allow...

CVE-2026-93549

Oct 4, 2026 06:00:23 UTC

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request fo...

CVE-2026-86817

Oct 4, 2026 06:00:23 UTC

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input tha...