CVE Monitor
286214 CVEs found
CVE-2026-48017
HIGH
15 Jun 2026
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with full process privileges, bypassing the require=null sandbox restriction. An authenticated user with basic access (no admin role, no run-shell-script permission required) can: execute arbitrary OS commands on the DbGate server with the privileges of the Node.js process, read/write any file accessible to the process, pivot to connected databases by reading connection credentials from DbGate's storage, and compromise the host system - in Docker deployments, this typically means root access within the container.
CVE-2026-52703
CRITICAL
15 Jun 2026
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-52702
HIGH
15 Jun 2026
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
CVE-2026-52700
HIGH
15 Jun 2026
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
CVE-2026-52699
HIGH
15 Jun 2026
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
CVE-2026-52697
HIGH
15 Jun 2026
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
CVE-2026-52695
HIGH
15 Jun 2026
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
CVE-2026-52694
HIGH
15 Jun 2026
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
CVE-2026-52693
CRITICAL
15 Jun 2026
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2026-52692
HIGH
15 Jun 2026
Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
CVE-2026-49781
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
CVE-2026-49780
HIGH
15 Jun 2026
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
CVE-2026-49776
CRITICAL
15 Jun 2026
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.
CVE-2026-49775
MEDIUM
15 Jun 2026
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
CVE-2026-49773
MEDIUM
15 Jun 2026
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
CVE-2026-49770
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
CVE-2026-49769
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-49768
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
CVE-2026-49766
CRITICAL
15 Jun 2026
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
CVE-2026-49765
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
CVE-2026-49764
CRITICAL
15 Jun 2026
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
CVE-2026-49763
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
CVE-2026-49112
HIGH
15 Jun 2026
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
CVE-2026-49110
HIGH
15 Jun 2026
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
CVE-2026-49109
CRITICAL
15 Jun 2026
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
Page 400 of 400