Common Vulnerabilities and Exposures (CVE)

CVE-2026-74848

Aug 27, 2026 09:16:06 UTC

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This i...

CVE-2026-75005

Aug 27, 2026 09:15:32 UTC

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users ar...

CVE-2026-75020

Aug 27, 2026 09:14:33 UTC

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer map...

CVE-2026-81625

Aug 27, 2026 09:06:44 UTC

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer overflow and gain full access on the compromised system.

CVE-2026-81273

Aug 27, 2026 09:03:57 UTC

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

CVE-2026-81272

Aug 27, 2026 09:03:56 UTC

Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.

CVE-2026-78293

Aug 27, 2026 09:03:55 UTC

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

CVE-2026-78289

Aug 27, 2026 09:03:53 UTC

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

CVE-2026-78276

Aug 27, 2026 09:03:52 UTC

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

CVE-2026-78275

Aug 27, 2026 09:03:51 UTC

Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

CVE-2026-78274

Aug 27, 2026 09:03:49 UTC

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

CVE-2026-78273

Aug 27, 2026 09:03:48 UTC

Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.

CVE-2026-78271

Aug 27, 2026 09:03:46 UTC

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

CVE-2026-32566

Aug 27, 2026 09:03:45 UTC

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

CVE-2026-32564

Aug 27, 2026 09:03:44 UTC

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.