| CVE-2026-75586 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in al | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-75018 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-67281 | RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uni | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-67279 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-67278 | MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-67277 | MikroTik RouterOS Missing Authentication for Critical Function Vulnerability | Mikrotik | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| 2026-09-10 |
| CVE-2026-67276 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the ke | — | 2026-09-05 | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-6554 | libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it | — | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- High
| — |
| CVE-2026-6244 | libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular unc | — | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- High
| — |
| CVE-2026-52777 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImport | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Active
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-52775 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vuln | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-52774 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attr | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-52773 | YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-52772 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field. | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- High
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-52771 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag ret | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- Low
| — |
| CVE-2026-52770 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-52769 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - expose | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- Low
| — |
| CVE-2026-52767 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the resu | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- High
AAvailability- Low
| — |
| CVE-2026-52766 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction. | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-52763 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argum | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-52762 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulne | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-4361 | The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the ` | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-3853 | The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-31912 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a ju | — | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- High
| — |
| CVE-2026-31911 | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a craf | — | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- High
| — |
| CVE-2026-19887 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deseriali | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-19861 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value | — | 2026-09-05 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- High
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-19858 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving reques | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-19769 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeate | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-18843 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' no | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- Required
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-18406 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scriptin | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-18404 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attr | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-18313 | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- Low
| — |
| CVE-2026-18238 | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious serv | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-16649 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and inc | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-15984 | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and includ | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- Low
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-15550 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This i | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- None
| — |
| CVE-2026-15247 | The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- Low
AAvailability- Low
| — |
| CVE-2026-14975 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteur | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- None
AAvailability- None
| — |
| CVE-2026-13447 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |