Количество 382 285
Количество 382 285
CVE-2026-5957
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) which may not exist, causing it to return false. In PHP 8.x, strpos($real_path, false) implicitly converts false to an empty string, and strpos() with an empty needle always returns 0, causing the check strpos(...) !== 0 to evaluate to false and bypassing the path validation entirely. This makes it possible for authenticated attackers, with Author-level access and above, to read arbitrary files from the server, including sensitive files such as wp-config.php, by supplying an absolute path to the emailkit-editor-template REST API parameter.
CVE-2026-59568
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
CVE-2026-59567
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
CVE-2026-59566
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
CVE-2026-59565
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
CVE-2026-59564
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
CVE-2026-59561
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
CVE-2026-59560
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-5955
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.
CVE-2026-59559
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
CVE-2026-59558
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
CVE-2026-59557
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
CVE-2026-59556
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
CVE-2026-59555
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVE-2026-59554
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-59553
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
CVE-2026-59552
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
CVE-2026-59551
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59550
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
CVE-2026-59549
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-5957 The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) which may not exist, causing it to return false. In PHP 8.x, strpos($real_path, false) implicitly converts false to an empty string, and strpos() with an empty needle always returns 0, causing the check strpos(...) !== 0 to evaluate to false and bypassing the path validation entirely. This makes it possible for authenticated attackers, with Author-level access and above, to read arbitrary files from the server, including sensitive files such as wp-config.php, by supplying an absolute path to the emailkit-editor-template REST API parameter. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-59568 Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. | CVSS3: 9.1 | 0% Низкий | 3 дня назад | |
CVE-2026-59567 Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | CVSS3: 8.8 | 0% Низкий | 3 дня назад | |
CVE-2026-59566 A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | CVSS3: 8.4 | 0% Низкий | 3 дня назад | |
CVE-2026-59565 A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | CVSS3: 8.8 | 0% Низкий | 3 дня назад | |
CVE-2026-59564 An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | CVSS3: 9.1 | 0% Низкий | 3 дня назад | |
CVE-2026-59561 Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | CVSS3: 7.8 | 1% Низкий | 3 дня назад | |
CVE-2026-59560 Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5955 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57. | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59559 Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59558 Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59557 Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59556 Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59555 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | CVSS3: 10 | 1% Низкий | около 1 месяца назад | |
CVE-2026-59554 Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59553 Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59552 Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | CVSS3: 7.2 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59551 Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | CVSS3: 8.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59550 Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59549 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу