|
301
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54835
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54837
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
8.8 |
HIGH
Network
|
-
|
-
|
Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56008
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
8.8 |
HIGH
Network
|
-
|
-
|
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56010
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56028
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-56029
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56034
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
8.6 |
HIGH
Network
|
-
|
-
|
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-56035
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56041
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56043
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|