|
791
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-56027
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-56026
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54847
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54846
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54834
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
7.4 |
HIGH
Network
|
-
|
-
|
Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-54833
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54825
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-54824
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
- |
|
-
|
-
|
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.33.8, when a shell interpreter is configured (e.g. …
New
|
CWE-77 CWE-184
Command Injection Incomplete Blacklist
|
CVE-2026-54090
|
2026-06-27 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
6.5 |
MEDIUM
Network
|
-
|
-
|
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool…
New
|
CWE-862
Missing Authorization
|
CVE-2026-54027
|
2026-06-27 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|