In Directus versions prior to 12.1.0 a high severity vulnerability CVE-2026-10716 was detected. This vulnerability allows an authenticated administrator to execute arbitrary SQL commands, potentially leading to unauthorized data extraction via time-based blind SQL Injection (SQLi). This occurs during the collection creation flow when the instance uses PostgreSQL with the PostGIS extension enabled. By supplying a malicious fields[].type value that starts with geometry but is followed by attacker-controlled SQL syntax, an attacker can bypass input validation and manipulate the underlying database queries. To address this issue, users should upgrade Directus to version 12.1.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10716.
In WPO365 | Login component for WordPress versions 43.2 and earlier a high severity vulnerability CVE-2026-15212 was detected. This vulnerability allows an attacker to modify the plugin’s settings via a specially crafted request. To address this issue, users should upgrade WPO365 | Login to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15212.
Read more CMSIn SAML Single Sign On – SSO Login component for WordPress versions up to and including 5.4.4 a critical severity vulnerability CVE-2026-15981 was detected. This vulnerability allows attackers to bypass authentication. To address this issue, users should upgrade SAML Single Sign On – SSO Login to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15981.
Read more CMSIn Cal.com OSS a critical severity vulnerability CVE-2026-16624 was detected. This vulnerability allows any authenticated user to steal sensitive booking data, including attendee PII and video-call passwords, from any team. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16624.
Read more ProductivityIn Cal versions 4.7.15 and earlier a high severity vulnerability CVE-2024-58353 was detected. This vulnerability allows an attacker to inject arbitrary HTML or JavaScript. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58353.
Read more ProductivityIn Clover Payment Gateway by Zaytech component for WooCommerce versions before 1.3.6 a high severity vulnerability CVE-2026-12493 was detected. This vulnerability allows unauthenticated users to mark arbitrary orders as paid. To address this issue, users should upgrade Clover Payment Gateway by Zaytech to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12493.
Read more E-commerceIn Cal a critical severity vulnerability CVE-2026-16624 was detected. This vulnerability allows any authenticated user to create a webhook on any team and steal booking data. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16624.
Read more ProductivityIn the Quix Page Builder component for Joomla versions prior to 6.2.1 a high severity vulnerability CVE-2026-60027 was detected. This vulnerability allows unauthenticated users to read arbitrary files via path traversal. To address this issue, users should upgrade Quix Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60027.
Read more CMSIn Quix Page Builder component for Joomla versions 6.2.1 and earlier a medium severity vulnerability CVE-2026-60029 was detected. This vulnerability allows authenticated users to perform a stored cross-site scripting (XSS) attack. To address this issue, users should upgrade Quix Page Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60029.
Read more CMS