Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 861/1152
5.4
CVE-2026-16071

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc

5.4
CVE-2026-70440

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a

5.4
CVE-2026-70441

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag

5.4
CVE-2026-70610

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,

5.4
CVE-2026-70612

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,

5.4
CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg

5.4
CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.

5.4
CVE-2026-18959

A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des

5.4
CVE-2026-13703

The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated

5.4
CVE-2026-16537

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin

5.4
CVE-2026-18395

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o

5.4
CVE-2025-13394

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque

5.4
CVE-2026-8166

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu

5.4
CVE-2026-18487

A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s

5.4
CVE-2026-54717

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable

5.4
CVE-2026-15245

The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con

5.4
CVE-2026-15386

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att

5.4
CVE-2026-16027

Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ

5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it

5.4
CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that

5.4
CVE-2026-14941

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve

5.4
CVE-2026-15238

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco

5.4
CVE-2026-17010

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o

5.4
CVE-2026-18960

The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al

5.4
CVE-2026-66642

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP

5.4
CVE-2026-72570

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec

5.4
CVE-2026-72576

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho

5.4
CVE-2026-72583

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us

5.4
CVE-2026-63105

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome

5.4
CVE-2026-72725

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo

5.4
CVE-2026-56619

HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out

5.4
CVE-2026-72743

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb

5.4
CVE-2026-72918

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7

5.4
CVE-2026-72542

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write

5.4
CVE-2026-72553

A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten

5.4
CVE-2026-72559

A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent

5.4
CVE-2026-72784

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne

5.4
CVE-2026-48376

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.

5.4
CVE-2026-48483

TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp

5.4
CVE-2026-69113

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica

5.4
CVE-2026-18698

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag

5.4
CVE-2026-70339

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

5.4
CVE-2026-19579

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request

5.4
CVE-2026-48762

TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u

5.4
CVE-2026-63134

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w

5.4
CVE-2026-9318

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows

5.4
CVE-2026-15249

The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i

5.4
CVE-2026-16066

The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it

5.4
CVE-2026-19217

The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM

5.4
CVE-2026-70560

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started