|
1051
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame …
|
CWE-79
Cross-site Scripting
|
CVE-2026-50740
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1052
|
8.8 |
HIGH
Network
|
-
|
-
|
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin ident…
|
CWE-94
Code Injection
|
CVE-2026-50741
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1053
|
4.4 |
MEDIUM
Network
|
-
|
-
|
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without…
|
CWE-79
Cross-site Scripting
|
CVE-2026-50742
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1054
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method …
|
CWE-284
Improper Access Control
|
CVE-2026-50744
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1055
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty cus…
|
CWE-79
Cross-site Scripting
|
CVE-2026-50745
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1056
|
- |
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FOSSBilling was accessible without authentication, w…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-43920
|
2026-06-27 01:10 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1057
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthor…
|
CWE-862
Missing Authorization
|
CVE-2026-1869
|
2026-06-27 00:49 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1058
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS.
This issue affects Exclusive Addons E…
|
CWE-79
Cross-site Scripting
|
CVE-2026-57620
|
2026-06-27 00:49 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1059
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-66123
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1060
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-24547
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|