tgindex
🛡 Cybersecurity & Privacy 🛡 - CVEs

🛡 Cybersecurity & Privacy 🛡 - CVEs

Статистика

🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com

Последний пост
16 авг.
Последнее чтение
16 авг.
Постов за неделю
69
Всего постов
69
Тип
открытый
Язык
английский
Категория
Новости и СМИ (по похожим)
В каталоге с
15 авг.
Подписчики
456
−1 за 2 дн.
Сутки
−1
−0,22%
Неделя
 
Месяц
 
Просмотров на пост
4
40 постов
Вовлечённость
0,9%
к подписчикам
Постов в день
9,9
всего 69
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
1
1/48двое суток
1
1/72трое суток
1

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • ‼️ CVE-2026-16541 ‼️ The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a lowprivileged staff role to disclose the names and email addresses of arbitrary registered users. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-68457 ‼️ In the Linux kernel, the following vulnerability has been resolved ksmbd use opener credentials for FSCTL mutations SETSPARSE, SETZERODATA and SETCOMPRESSION operate on an open SMB handle but call VFS xattr, fallocate or fileattr helpers with the current ksmbd worker credentials. Those helpers can revalidate inode permissions, ownership and LSM policy independently of the SMB handle access mask. Run each operation with the credentials captured in the target file when the handle was opened. Keep credential handling local to these singlefile FSCTLs rather than applying session credentials to the complete IOCTL handler, which also contains handleless and multihandle operations. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-16007 ‼️ AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-16007 ‼️ AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-14230 ‼️ The ECS WordPress plugin before 4.3.8 does not perform capability or objectownership checks on its Dynamic Repeater AJAX handlers gated only by a capabilityagnostic nonce that any editposts user obtains from the Elementor editor, so a Contributor can write a datasource binding into any post including adminauthored pages whose attackercontrolled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-14230 ‼️ The ECS WordPress plugin before 4.3.8 does not perform capability or objectownership checks on its Dynamic Repeater AJAX handlers gated only by a capabilityagnostic nonce that any editposts user obtains from the Elementor editor, so a Contributor can write a datasource binding into any post including adminauthored pages whose attackercontrolled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-14229 ‼️ The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished private, draft, pending documents by supplying their identifier. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-14229 ‼️ The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished private, draft, pending documents by supplying their identifier. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-14230 ‼️ The ECS WordPress plugin before 4.3.8 does not perform capability or objectownership checks on its Dynamic Repeater AJAX handlers gated only by a capabilityagnostic nonce that any editposts user obtains from the Elementor editor, so a Contributor can write a datasource binding into any post including adminauthored pages whose attackercontrolled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-14229 ‼️ The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished private, draft, pending documents by supplying their identifier. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-18387 ‼️ The Groundhogg CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'tagquery' parameter in all versions up to, and including, 4.5.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with vendorlevel access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the attacker to trigger the vulnerable LegacyContactQuery code path by submitting an unknown filter type e.g. filters00typeforcefallback, which causes a FilterException that dispatches execution away from the modern query handler. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-17090 ‼️ The Beaver Builder Page Builder Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored CrossSite Scripting via Button Module 'button' Button Code Setting in all versions up to, and including, 2.10.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with authorlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Beaver Builder grants editor access to any WordPress role holding the editposts capability by default, meaning Authorlevel users and above can exploit this vulnerability. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-16586 ‼️ The Contest Gallery Upload Vote Photos, Media, Sell with PayPal Stripe plugin for WordPress is vulnerable to SecondOrder SQL Injection via MultipleFiles SecondOrder Payload via 'cgmultiplefilesforpost' 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with authorlevel access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-16094 ‼️ The Invisible AntiSpam CAPTCHA reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQL Injection via the 'key' parameter in all versions up to, and including, 5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editorlevel access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-15993 ‼️ The Form Maker by 10Web MobileFriendly Drag Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via 'username' Placeholder in DynamicChoice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriberlevel access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that a form is configured with a DBbacked dynamic choice field whose WHERE template references the username placeholder, and the attacker must first set their own displayname to a SQL payload via the... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-15948 ‼️ The Hydra Booking Appointment Scheduling Booking Calendar plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'firstname' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with hostlevel access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The tfhbhost role required to exploit this vulnerability can be selfassigned by any visitor via the plugin's public Signup shortcode, making this effectively exploitable by unauthenticated users who complete the registration flow. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-15453 ‼️ The KiviCare Clinic Patient Management System EHR plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with customlevel access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a KiviCare custom role with the 'settingsview' permission e.g., Doctor or Receptionist, meaning standard WordPress subscribers cannot exploit this without a KiviCareassigned role. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-13360 ‼️ The Cookie Banner for GDPR CCPA WPLP Cookie Consent plugin for WordPress is vulnerable to Stored CrossSite Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the site administrator has enabled the 'Support Google Consent Mode GCM' setting, which is disabled by default. Additionally, the AJAX handler performs no nonce or capability check, allowing any authenticated user including those with Subscriberlevel access to overwrite the affected plugin setting. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-8840 ‼️ The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary reservations as paid or completed, cancel legitimate payments, autoapprove reservations, and trigger transactional booking emails by writing attackersupplied payment status and transaction data directly into the payments table. The autoapproval of reservations is only triggered when the 'enablepsuccessapproval' site option is enabled, but payment status manipulation and email dispatch are exploitable regardless of that setting. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs

  • ‼️ CVE-2026-16080 ‼️ The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'posttitle' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with authorlevel access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs