|
841
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54835
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
842
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54837
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
843
|
8.8 |
HIGH
Network
|
-
|
-
|
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56008
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
844
|
8.8 |
HIGH
Network
|
-
|
-
|
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56010
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
845
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56028
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
846
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-56029
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
847
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56034
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
848
|
8.6 |
HIGH
Network
|
-
|
-
|
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-56035
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
849
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56041
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
850
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56043
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|