In 6Storage Rentals component for WordPress versions up to and including 2.27.0 a critical severity vulnerability CVE-2026-16249 was detected. This vulnerability allows unauthenticated attackers to log in as any existing user, including administrators. To address this issue, users should upgrade 6Storage Rentals to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16249.
Read more CMSIn Page Builder CK component for Joomla versions 3.6.5 and earlier a critical severity vulnerability CVE-2026-77994 was detected. This vulnerability allows an attacker to execute arbitrary SQL commands. To address this issue, users should upgrade Page Builder CK to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77994.
Read more CMSIn WooCommerce File Approval component for WooCommerce versions 10.7 and earlier a high severity vulnerability CVE-2026-28171 was detected. This vulnerability allows an unauthenticated attacker to arbitrarily delete files. To address this issue, users should upgrade WooCommerce File Approval to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28171.
Read more E-commerceIn Notification Master component for WordPress versions 1.7.1 and earlier a high severity vulnerability CVE-2026-28153 was detected. This vulnerability allows unauthenticated attackers to bypass access controls. To address this issue, users should upgrade Notification Master to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28153.
Read more CMSIn BookStack versions prior to 26.05.4 a high severity vulnerability CVE-2026-82450 was detected. This vulnerability allows an authenticated user with “Import Content” and “Create Books” permissions to execute arbitrary code on the server, leading to Remote Code Execution (RCE). This occurs due to inadequate file validation within the portable ZIP import functionality. An attacker can bypass image extension validation by embedding a PHP polyglot file with a .php filename disguised as a book cover inside the ZIP archive. Because these files are subsequently stored in the public web root, the uploaded malicious script can be triggered and executed via unauthenticated web requests. To address this issue, users should upgrade BookStack to version 26.05.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82450.
In Dolibarr versions up to 21.0.4, 22.0.5, and 23.0.3 a medium severity vulnerability CVE-2026-85401 was detected. This vulnerability allows a remote attacker to bypass access restrictions, potentially leading to unauthorized access, modification, or disclosure of sensitive files. This occurs due to an improper access control flaw within the htdocs/core/filemanagerdol/connectors/php/config.inc.php file of the Legacy File Manager component. Warning: A public exploit for this vulnerability is available and could be used in active attacks. To address this issue, users should upgrade Dolibarr to version 23.0.4 or later, or apply the official patch (commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-85401.
In iCagenda component for Joomla versions 4.0.8 to 4.0.12 a high severity vulnerability CVE-2026-75948 was detected. This vulnerability allows an authenticated attacker to inject malicious scripts. To address this issue, users should upgrade iCagenda to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-75948.
Read more CMSIn Phoca Cart component for Joomla versions 5.0.0 through 6.1.7 a medium severity vulnerability CVE-2026-76565 was detected. This vulnerability allows attackers to execute arbitrary web scripts. To address this issue, users should upgrade Phoca Cart to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76565.
Read more CMSIn Zoo component for Joomla versions before 4.1.65 a medium severity vulnerability CVE-2026-76610 was detected. This vulnerability allows unauthenticated users to modify tags. To address this issue, users should upgrade Zoo to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76610.
Read more CMS