Total
2603 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84769 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-85693 | 1 Mckaywrigley | 1 Chatbot-ui | 2026-09-07 | 6.5 Medium |
| Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests. | ||||
| CVE-2026-86176 | 2 Netbox, Netbox-community | 2 Netbox, Netbox | 2026-09-07 | 4.3 Medium |
| NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects. | ||||
| CVE-2026-86262 | 1 Sfturing | 1 Hosp Order | 2026-09-07 | 7.3 High |
| A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78150 | 2026-09-06 | 2.7 Low | ||
| The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata. | ||||
| CVE-2026-84225 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-09-06 | 2.2 Low |
| The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open. | ||||
| CVE-2026-81424 | 2026-09-06 | 5.3 Medium | ||
| The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for. | ||||
| CVE-2026-86183 | 1 Diem-project | 1 Diem | 2026-09-06 | 5.3 Medium |
| A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-83711 | 1 Microsoft | 2 Azure Active Directory B2c, Entra Id | 2026-09-05 | 10 Critical |
| Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-75035 | 1 Suse | 1 Rancher | 2026-09-05 | 7.7 High |
| A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affects Rancher: before 2.15.1. | ||||
| CVE-2026-72657 | 1 Elastic | 1 Fleet Server | 2026-09-04 | 6.5 Medium |
| Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without being validated against the server-side record of the requesting agent's assignment. An authenticated party in possession of a valid enrolled agent credential could therefore retrieve a policy the agent is not assigned to. | ||||
| CVE-2026-27432 | 2026-09-04 | 5.4 Medium | ||
| Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: from n/a before 3.16.0. | ||||
| CVE-2026-85638 | 1 Jofpin | 1 Trape | 2026-09-04 | 7.3 High |
| A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-85624 | 2 Blinko, Blinkospace | 2 Blinko, Blinko | 2026-09-04 | 6.5 Medium |
| Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags. | ||||
| CVE-2026-85616 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-04 | 8.5 High |
| Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger reminder emails for acceptances belonging to other companies by exploiting a null check on the legacy users.company_id column. | ||||
| CVE-2026-85611 | 1 Openpanel | 1 Openpanel | 2026-09-04 | 6.4 Medium |
| OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries. | ||||
| CVE-2026-84044 | 2026-09-04 | 5.3 Medium | ||
| The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment. | ||||
| CVE-2026-79630 | 2 Getwpfunnels, Wordpress | 2 Wpfunnels, Wordpress | 2026-09-04 | 5.3 Medium |
| The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different one, with the reduced price carried through to the total of the order they place. | ||||
| CVE-2026-85178 | 1 Helicone | 1 Helicone | 2026-09-04 | 7.7 High |
| Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider credentials for other tenants, including plaintext OpenAI, Anthropic, and Bedrock API keys. | ||||
| CVE-2026-84836 | 2 Kirillbdev, Wordpress | 2 Wc Ukraine Shipping, Wordpress | 2026-09-04 | 7.1 High |
| Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions. | ||||