Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

450 CVEs · published 2026-07-27 to 2026-07-27

CVEs (450)

Showing 1–25 of 450

CVE ID Severity Patch CVSS Published Description
CVE-2026-9830 HIGH Patched 8.2 2026-07-27 The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespa…
CVE-2026-66825 NONE — 2026-07-27 Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, we…
CVE-2026-66824 NONE — 2026-07-27 A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline Jav…
CVE-2026-66759 HIGH 7.1 2026-07-27 A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifyi…
CVE-2026-66758 HIGH 7.8 2026-07-27 A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width an…
CVE-2026-66757 MEDIUM 5.5 2026-07-27 A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysiz…
CVE-2026-66731 HIGH 7.5 2026-07-27 facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to cra…
CVE-2026-66730 HIGH 7.5 2026-07-27 facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze wo…
CVE-2026-66729 HIGH 7.5 2026-07-27 facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server …
CVE-2026-66477 MEDIUM 5.3 2026-07-27 Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
CVE-2026-66476 MEDIUM 4.9 2026-07-27 Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
CVE-2026-66475 MEDIUM 5.9 2026-07-27 Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.
CVE-2026-66474 MEDIUM 4.3 2026-07-27 Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.
CVE-2026-66473 HIGH 7.5 2026-07-27 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-66448 MEDIUM 6.5 2026-07-27 Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
CVE-2026-66445 MEDIUM 6.5 2026-07-27 Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
CVE-2026-66442 MEDIUM 5.4 2026-07-27 Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
CVE-2026-66438 MEDIUM 5.3 2026-07-27 Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
CVE-2026-66437 MEDIUM 4.9 2026-07-27 Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
CVE-2026-66434 MEDIUM 6.5 2026-07-27 Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.
CVE-2026-66433 MEDIUM 6.5 2026-07-27 Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
CVE-2026-66428 MEDIUM 4.3 2026-07-27 Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
CVE-2026-66427 HIGH 7.6 2026-07-27 Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
CVE-2026-66412 MEDIUM 6.5 2026-07-27 Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by sup&hellip;
CVE-2026-66399 MEDIUM Patched 6.5 2026-07-27 phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to&hellip;