|
751
|
- |
|
-
|
-
|
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src
attribute of these images pointed to an URL, the PDF rendering engine
would d…
New
|
CWE-80
Basic XSS
|
CVE-2026-57535
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
New
|
CWE-80
Basic XSS
|
CVE-2026-57534
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the page pretix shows when
redirection to an untrusted page occurs. Since this page has a
Content-Security-Policy, this can mainly be used for phishing…
New
|
CWE-80
Basic XSS
|
CVE-2026-57533
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
- |
|
-
|
-
|
Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was executed when the PDF editor is opened in the
browser. This could allow one backend user to inject J…
New
|
CWE-80
Basic XSS
|
CVE-2026-57532
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
2.6 |
LOW
Network
|
-
|
-
|
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-…
New
|
CWE-178 CWE-184 CWE-611
Improper Handling of Case Sensitivity Incomplete Blacklist XXE
|
CVE-2026-57234
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56071
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
7.1 |
HIGH
Network
|
-
|
-
|
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56042
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-56023
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:…
New
|
CWE-749 CWE-1188
Exposed Dangerous Method or Function Insecure Default Initialization of Resource
|
CVE-2026-55454
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54849
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|