Common Vulnerabilities and Exposures (CVE)

CVE-2026-83532

Sep 12, 2026 15:36:52 UTC

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts t...

CVE-2026-75800

Sep 12, 2026 15:36:38 UTC

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators,...

CVE-2026-77005

Sep 12, 2026 15:36:23 UTC

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subs...

CVE-2026-77006

Sep 12, 2026 15:36:09 UTC

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, s...

CVE-2026-84889

Sep 12, 2026 15:36:04 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

CVE-2026-79724

Sep 12, 2026 15:36:04 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

CVE-2026-78569

Sep 12, 2026 15:36:04 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

CVE-2026-70341

Sep 12, 2026 15:36:04 UTC

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

CVE-2026-77689

Sep 12, 2026 15:35:52 UTC

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking re...

CVE-2026-77705

Sep 12, 2026 15:35:37 UTC

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's c...

CVE-2026-77752

Sep 12, 2026 15:35:23 UTC

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a sing...

CVE-2026-77753

Sep 12, 2026 15:35:08 UTC

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of ...

CVE-2026-78152

Sep 12, 2026 15:34:51 UTC

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any...

CVE-2026-80491

Sep 12, 2026 15:34:36 UTC

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

CVE-2026-80494

Sep 12, 2026 15:34:21 UTC

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download a...