In Helix Ultimate component for Joomla versions before 2.2.10 a high severity vulnerability CVE-2026-78077 was detected. This vulnerability allows attackers to inject malicious HTML or JavaScript code. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78077.
Read more CMSIn Helix Ultimate component for Joomla versions before 2.2.10 a medium severity vulnerability CVE-2026-78075 was detected. This vulnerability allows an author to delete arbitrary files. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78075.
Read more CMSIn Helix Ultimate component for Joomla versions earlier than 2.2.10 a high severity vulnerability CVE-2026-78078 was detected. This vulnerability allows attackers to bypass file upload restrictions. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78078.
Read more CMSIn Cozmoslabs Profile Builder Plugin component for WordPress versions 3.16.1 and earlier a high severity vulnerability CVE-2026-82607 was detected. This vulnerability allows attackers to perform unauthorized actions. To address this issue, users should upgrade Cozmoslabs Profile Builder Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82607.
Read more CMSIn 爱采集数据采集和发布插件 component for WordPress versions 1.0.0 and earlier a medium severity vulnerability CVE-2026-77013 was detected. This vulnerability allows unauthenticated users to create WordPress user accounts and taxonomy terms. To address this issue, users should upgrade 爱采集数据采集和发布插件 to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77013.
Read more CMSIn Dolibarr versions 10.0.0 before 24.0.0 a medium severity vulnerability CVE-2026-82633 was detected. This vulnerability allows authenticated users to retrieve group memberships of other users. To address this issue, users should upgrade Dolibarr to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82633.
Read more ERPIn ACPT (Pro) – Custom Post Types Plugin component for WordPress versions 2.0.63 and earlier a high severity vulnerability CVE-2026-32564 was detected. This vulnerability allows an attacker to execute SQL commands. To address this issue, users should upgrade ACPT (Pro) – Custom Post Types Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32564.
Read more CMSIn Booking and Rental Manager component for WordPress versions 2.7.5 and earlier a high severity vulnerability CVE-2026-78257 was detected. This vulnerability allows authenticated attackers with low privileges to inject arbitrary PHP objects. To address this issue, users should upgrade Booking and Rental Manager to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78257.
Read more CMSIn ACPT (Pro) – Custom Post Types component for WordPress versions 2.0.63 and earlier a critical severity vulnerability CVE-2026-32566 was detected. This vulnerability allows an unauthenticated attacker to escalate their privileges. To address this issue, users should upgrade ACPT (Pro) – Custom Post Types to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32566.
Read more CMS