|
851
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects PPOM for WooCommerce: from n/a thr…
New
|
CWE-284
Improper Access Control
|
CVE-2026-56050
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
852
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
New
|
CWE-94
Code Injection
|
CVE-2026-56049
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
853
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56006
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
854
|
7.1 |
HIGH
Network
|
-
|
-
|
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56005
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
855
|
9.0 |
CRITICAL
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj …
New
|
CWE-79 CWE-94 CWE-116
Cross-site Scripting Code Injection Improper Encoding or Escaping of Output
|
CVE-2026-55570
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
856
|
8.3 |
HIGH
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data.
This issue affects APIExperts Square for WooC…
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54848
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
857
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54843
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
858
|
8.1 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Royal MCP: from n/a through 1.4.25.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54842
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
859
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection.
This issue affects WP Photo A…
New
|
CWE-89
SQL Injection
|
CVE-2026-54829
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
860
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54828
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|