|
2561
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
|
CWE-89
SQL Injection
|
CVE-2026-49067
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2562
|
7.5 |
HIGH
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-49068
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2563
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-49070
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2564
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-49078
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2565
|
7.4 |
HIGH
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions.
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-49082
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2566
|
7.5 |
HIGH
Network
|
-
|
-
|
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-49083
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2567
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49085
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2568
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49104
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2569
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49105
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2570
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49106
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|