In the Snow Monkey Forms plugin for WordPress versions up to and including 12.0.3 a critical severity vulnerability CVE-2026-1056 was detected. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the generate_user_dirpath function. To address this issue, users should upgrade Snow Monkey Forms plugin to version 12.0.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1056.
Read more CMSIn the Vzaar Media Management plugin for WordPress versions up to and including 1.2 a medium severity vulnerability CVE-2026-1391 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via a Reflected Cross-Site Scripting (XSS) attack due to insufficient input sanitization and output escaping on the $_SERVER[‘PHP_SELF’] variable. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1391.
Read more CMSIn the Bitcoin Donate Button plugin for WordPress versions up to and including 1.0 a medium severity vulnerability CVE-2026-1380 was detected. This vulnerability allows unauthenticated attackers to modify the plugin’s settings, including donation addresses and display configurations, via a forged request due to missing or incorrect nonce validation on the settings page. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1380.
Read more CMSIn the imwptip plugin for WordPress versions up to and including 1.1 a medium severity vulnerability CVE-2026-1377 was detected. This vulnerability allows unauthenticated attackers to update the plugin’s settings via a forged request due to missing nonce validation on the settings update functionality. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1377.
Read more CMSIn the Change WP URL plugin for WordPress versions up to and including 1.0 a medium severity vulnerability CVE-2026-1398 was detected. This vulnerability allows unauthenticated attackers to change the WordPress login URL via a forged request due to missing or incorrect nonce validation on the change-wp-url page. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1398.
Read more CMSIn the WP Hello Bar plugin for WordPress versions up to and including 1.02 a medium severity vulnerability CVE-2026-1042 was detected. This vulnerability allows authenticated attackers with administrator-level access and above to inject arbitrary web scripts through the digit_one and digit_two parameters due to insufficient input sanitization and output escaping, resulting in stored cross-site scripting that executes when users access affected pages. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1042.
Read more CMS NewsflashIn the Viet Contact plugin for WordPress versions up to and including 1.3.2 a medium severity vulnerability CVE-2026-1045 was detected. This vulnerability allows authenticated attackers with administrator-level permissions and above to perform stored cross-site scripting (XSS) by injecting arbitrary web scripts through improperly sanitized admin settings, which execute when a user accesses the affected pages. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1045.
Read more CMS NewsflashIn Umbraco CMS version 8.14.1 a medium severity vulnerability CVE-2021-47776 was detected. This vulnerability allows attackers to perform server-side request forgery (SSRF) by manipulating the baseUrl parameter in multiple dashboard and help controller endpoints, causing the server to initiate unauthorized requests to external hosts. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2021-47776.
Read more CMS NewsflashIn Ghost versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3 a high severity vulnerability CVE-2026-22594 was detected. This vulnerability allows authenticated staff users to bypass the email-based two-factor authentication (2FA) mechanism, weakening account security and increasing the risk of unauthorized access. To address this issue, users should upgrade Ghost to versions 5.130.6 or 6.11.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-22594.
Read more CMS