|
2921
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49105
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2922
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49106
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2923
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49109
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2924
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-49110
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2925
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-49112
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2926
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49763
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2927
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-49764
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2928
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49765
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2929
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
|
CWE-22
Path Traversal
|
CVE-2026-49766
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2930
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49768
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|