Common Vulnerabilities and Exposures (CVE)

CVE-2026-100512

Sep 30, 2026 17:39:04 UTC

Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.

CVE-2026-100510

Sep 30, 2026 17:39:03 UTC

Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.

CVE-2026-97291

Sep 30, 2026 17:39:02 UTC

Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.

CVE-2026-97290

Sep 30, 2026 17:39:02 UTC

Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.

CVE-2026-97256

Sep 30, 2026 17:39:00 UTC

Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.

CVE-2026-94171

Sep 30, 2026 17:38:59 UTC

Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.

CVE-2026-102397

Sep 30, 2026 17:38:58 UTC

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.

CVE-2026-103440

Sep 30, 2026 17:38:27 UTC

Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.

CVE-2026-100677

Sep 30, 2026 17:38:09 UTC

stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error responses. Unauthenticated attackers can distinguish between registered and unregistered email addresses...

CVE-2026-103439

Sep 30, 2026 17:34:10 UTC

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1....

CVE-2026-103438

Sep 30, 2026 17:32:26 UTC

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: ...

CVE-2026-48541

Sep 30, 2026 17:29:32 UTC

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person na...

CVE-2026-89032

Sep 30, 2026 17:29:32 UTC

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_sema...

CVE-2026-93366

Sep 30, 2026 17:29:32 UTC

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by supplyin...

CVE-2026-97064

Sep 30, 2026 17:29:32 UTC

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOr...