Common Vulnerabilities and Exposures (CVE)

CVE-2026-52873

Aug 18, 2026 21:28:18 UTC

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and register...

CVE-2026-52877

Aug 18, 2026 21:27:23 UTC

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal...

CVE-2026-52872

Aug 18, 2026 21:26:26 UTC

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied su...

CVE-2026-73365

Aug 18, 2026 21:25:57 UTC

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

CVE-2026-73360

Aug 18, 2026 21:25:56 UTC

Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.

CVE-2026-74015

Aug 18, 2026 21:25:55 UTC

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

CVE-2026-66634

Aug 18, 2026 21:25:53 UTC

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

CVE-2026-73339

Aug 18, 2026 21:25:52 UTC

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

CVE-2026-66633

Aug 18, 2026 21:25:51 UTC

Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.

CVE-2026-73181

Aug 18, 2026 21:25:50 UTC

Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.

CVE-2026-66627

Aug 18, 2026 21:25:48 UTC

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

CVE-2026-66621

Aug 18, 2026 21:25:47 UTC

Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.

CVE-2026-73392

Aug 18, 2026 21:25:46 UTC

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

CVE-2026-32466

Aug 18, 2026 21:25:44 UTC

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

CVE-2026-32444

Aug 18, 2026 21:25:43 UTC

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.