|
261
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to in…
New
|
CWE-89
SQL Injection
|
CVE-2026-13226
|
2026-06-27 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-68074
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
7.5 |
HIGH
Network
|
-
|
-
|
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
New
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-68064
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2025-64636
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2025-63079
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API …
New
|
CWE-22
Path Traversal
|
CVE-2026-13426
|
2026-06-27 01:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
6.7 |
MEDIUM
Local
|
-
|
-
|
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-53914
|
2026-06-27 01:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
New
|
CWE-862
Missing Authorization
|
CVE-2026-57921
|
2026-06-27 01:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
3.1 |
LOW
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
New
|
CWE-862
Missing Authorization
|
CVE-2026-57922
|
2026-06-27 01:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
5.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
New
|
CWE-862
Missing Authorization
|
CVE-2026-57923
|
2026-06-27 01:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|