Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 279/436
5.4
CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that

5.4
CVE-2026-14941

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve

5.4
CVE-2026-15238

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco

5.4
CVE-2026-17010

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o

5.4
CVE-2026-18960

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al

5.4
CVE-2026-66642

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP

5.4
CVE-2026-72570

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec

5.4
CVE-2026-72576

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho

5.4
CVE-2026-72583

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us

5.4
CVE-2026-63105

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome

5.4
CVE-2026-72725

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo

5.4
CVE-2026-56619

HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out

5.4
CVE-2026-72743

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb

5.4
CVE-2026-72918

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

5.4
CVE-2026-72542

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write

5.4
CVE-2026-72553

A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten

5.4
CVE-2026-72559

A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent

5.4
CVE-2026-72784

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne

5.4
CVE-2026-48376

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.

5.4
CVE-2026-48483

TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp

5.4
CVE-2026-69113

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica

5.4
CVE-2026-18698

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag

5.4
CVE-2026-70339

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

5.4
CVE-2026-19579

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request

5.4
CVE-2026-48762

TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u

5.4
CVE-2026-63134

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w

5.4
CVE-2026-9318

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows

5.4
CVE-2026-15249

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i

5.4
CVE-2026-16066

The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it

5.4
CVE-2026-19217

The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM

5.4
CVE-2026-70560

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri

5.4
CVE-2026-47229

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm

5.4
CVE-2026-73262

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.

5.4
CVE-2026-73287

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv

5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th

5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

5.4
CVE-2026-48552

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js

5.4
CVE-2026-73295

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc

5.4
CVE-2026-19135

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authentic

5.4
CVE-2026-72506

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly spec

5.4
CVE-2026-19088

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentica

5.4
CVE-2026-14332

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or non

5.4
CVE-2026-73621

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor

5.4
CVE-2026-67990

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager

5.4
CVE-2026-55986

Email Management API Bypasses ManageCredentials Feature Restrictions

5.4
CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation

5.4
CVE-2026-73481

phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / b

5.4
CVE-2026-16878

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o

5.4
CVE-2026-72673

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Access

5.4
CVE-2026-17226

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a deni

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started