|
481
|
8.2 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-49065
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
482
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-49066
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
483
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-49067
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
484
|
7.5 |
HIGH
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-49068
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
485
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-49070
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
486
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-49078
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
487
|
7.4 |
HIGH
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions.
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-49082
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
488
|
7.5 |
HIGH
Network
|
-
|
-
|
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-49083
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
489
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49085
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
490
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49104
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|