In OrdaSoft Joomla Gallery component for Joomla versions 6.2.7 and earlier a critical severity vulnerability CVE-2026-88854 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands. To address this issue, users should upgrade OrdaSoft Joomla Gallery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-88854.
Read more CMSIn OrdaSoft Joomla Gallery component for Joomla versions before 6.2.7 a high severity vulnerability CVE-2026-88855 was detected. This vulnerability allows an authenticated attacker to execute SQL commands. To address this issue, users should upgrade OrdaSoft Joomla Gallery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-88855.
Read more CMSIn OrdaSoft Joomla Gallery component for Joomla versions before 6.2.7 a critical severity vulnerability CVE-2026-88856 was detected. This vulnerability allows an authenticated attacker to execute remote code. To address this issue, users should upgrade OrdaSoft Joomla Gallery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-88856.
Read more CMSIn OrdaSoft Joomla Gallery component for Joomla versions earlier than 6.2.7 a critical severity vulnerability CVE-2026-88857 was detected. This vulnerability allows an authenticated user to achieve remote code execution. To address this issue, users should upgrade OrdaSoft Joomla Gallery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-88857.
Read more CMSIn Web to Print Online Designer component for WordPress versions before 2.15.0 a critical severity vulnerability CVE-2026-82187 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files and achieve remote code execution. To address this issue, users should upgrade Web to Print Online Designer to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82187.
Read more CMSIn Royal Elementor Addons component for WordPress versions before 1.7.1067 a medium severity vulnerability CVE-2026-13407 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission. To address this issue, users should upgrade Royal Elementor Addons to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13407.
Read more CMSIn Formidable Forms component for WordPress versions before 6.35 a medium severity vulnerability CVE-2026-19857 was detected. This vulnerability allows unauthenticated visitors to execute arbitrary shortcodes with chosen attributes on the server. To address this issue, users should upgrade Formidable Forms to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19857.
Read more CMSIn Eventin component for WordPress versions before 4.1.24 a medium severity vulnerability CVE-2026-84906 was detected. This vulnerability allows unauthenticated visitors to mark unpaid orders of any value as paid. To address this issue, users should upgrade Eventin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84906.
Read more CMSIn Appointment Hour Booking component for WordPress versions before 1.5.95 a medium severity vulnerability CVE-2026-86475 was detected. This vulnerability allows unauthenticated visitors to take slots that are already fully booked. To address this issue, users should upgrade Appointment Hour Booking to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-86475.
Read more CMS