In Phoca Cart component for Joomla versions 6.1.7 and earlier a high severity vulnerability CVE-2026-76564 was detected. This vulnerability allows attackers to execute arbitrary web scripts. To address this issue, users should upgrade Phoca Cart to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76564.
Read more CMSIn Phoca Download component for Joomla versions 5.0.0 through 6.1.4 a medium severity vulnerability CVE-2026-76569 was detected. This vulnerability allows attackers to execute arbitrary web scripts. To address this issue, users should upgrade Phoca Download to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76569.
Read more CMSIn Balbooa Forms component for Joomla versions prior to 2.4.3.2 a high severity vulnerability CVE-2026-67363 was detected. This vulnerability allows an attacker to tamper with payment amounts without authentication. To address this issue, users should upgrade Balbooa Forms to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-67363.
Read more CMSIn Flexible Subscriptions component for WordPress versions 1.8.1 and earlier a critical severity vulnerability CVE-2026-73364 was detected. This vulnerability allows attackers to inject malicious objects. To address this issue, users should upgrade Flexible Subscriptions to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73364.
Read more CMSIn the Balbooa Forms component for Joomla versions 2.4.3.1 and earlier a critical severity vulnerability CVE-2026-67364 was detected. This vulnerability allows an unauthenticated attacker to execute arbitrary PHP code on the server. To address this issue, users should upgrade Balbooa Forms to version 2.4.3.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-67364.
Read more CMSIn YITH WooCommerce Membership Premium component for WooCommerce versions 2.33.0 and earlier a high severity vulnerability CVE-2026-32552 was detected. This vulnerability allows attackers to execute arbitrary SQL commands. To address this issue, users should upgrade YITH WooCommerce Membership Premium to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32552.
Read more E-commerceIn Taxi Booking Manager for WooCommerce component for WooCommerce versions before 2.0.8 a medium severity vulnerability CVE-2026-73363 was detected. This vulnerability allows unauthenticated attackers to bypass access controls. To address this issue, users should upgrade Taxi Booking Manager for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73363.
Read more E-commerceIn Phoca Cart component for Joomla versions 6.1.6 and earlier a critical severity vulnerability CVE-2026-74251 was detected. This vulnerability allows an unauthenticated attacker to inject arbitrary SQL to extract the full database. To address this issue, users should upgrade Phoca Cart to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-74251.
Read more CMSIn Contact Form, Survey, Quiz & Popup Form Builder – ARForms component for WordPress versions 1.8.5 and earlier a critical severity vulnerability CVE-2024-13784 was detected. This vulnerability allows unauthenticated attackers to inject a PHP Object. To address this issue, users should upgrade Contact Form, Survey, Quiz & Popup Form Builder – ARForms to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13784.
Read more CMS