|
261
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a…
New
|
CWE-285
Improper Authorization
|
CVE-2026-10580
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is exposed to unauthenticated users, allowing unauthenti…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-46390
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct substring-only matching …
New
|
CWE-183 CWE-918
Permissive List of Allowed Inputs Server-Side Request Forgery (SSRF)
|
CVE-2026-46391
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated users to fetch …
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46393
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of `<iframe>` el…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-46396
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attacker can exploit this…
New
|
CWE-15 CWE-73 CWE-78
External Control of System or Configuration Setting External Control of File Name or Path OS Command
|
CVE-2026-46399
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git.php library of the HAXcms PHP backend. The applic…
New
|
CWE-78
OS Command
|
CVE-2026-46394
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSetti…
New
|
CWE-79 CWE-522 CWE-922
Cross-site Scripting Insufficiently Protected Credentials Insecure Storage of Sensitive Information
|
CVE-2026-46511
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includ…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5411
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-5415
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|