In Smash Balloon Social Photo Feed – Easy Social Feeds Plugin component for WordPress versions 6.11.3 and earlier a medium severity vulnerability CVE-2026-15452 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Smash Balloon Social Photo Feed – Easy Social Feeds Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15452.
Read more CMSIn affected versions of Rancher a critical severity vulnerability CVE-2026-44945 was detected. This vulnerability allows an attacker to escalate privileges. To address this issue, users should upgrade Rancher to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44945.
Read more Developer ToolsIn Documize in affected versions a high severity vulnerability CVE-2026-71234 was detected. This vulnerability allows an attacker to download attachments without proper authentication. To address this issue, users should upgrade Documize to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-71234.
Read more ProductivityIn wp-downloadmanager component for WordPress versions 1.68.11 and earlier a high severity vulnerability CVE-2026-18933 was detected. This vulnerability allows an administrator to upload arbitrary files. To address this issue, users should upgrade wp-downloadmanager to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18933.
Read more CMSIn Content Egg – Affiliate Product Importer & Price Comparison component for WordPress versions 11.3.0 and earlier a high severity vulnerability CVE-2026-15979 was detected. This vulnerability allows attackers to delete arbitrary files on the server. To address this issue, users should upgrade Content Egg – Affiliate Product Importer & Price Comparison to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15979.
Read more CMSIn Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8 a medium severity vulnerability CVE-2026-15337 was detected. This vulnerability allows a potential denial-of-service attack. To address this issue, users should upgrade Django to version 5.2.17 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15337.
Read more Application DevelopmentIn Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8 a medium severity vulnerability CVE-2026-15920 was detected. This vulnerability allows attackers to craft malicious URLs in the admin interface. To address this issue, users should upgrade Django to version 5.2.17 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15920.
Read more Application DevelopmentIn pdm component for Python versions prior to 2.27.0 a high severity vulnerability CVE-2026-47764 was detected. This vulnerability allows an attacker to perform path traversal. To address this issue, users should upgrade pdm to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-47764.
Read more Application DevelopmentIn OpenWebUI versions 0.8.8 up to 0.11.0 a medium severity vulnerability CVE-2026-70490 was detected. This vulnerability allows an attacker to bypass user verification on terminal routes. To address this issue, users should upgrade OpenWebUI to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-70490.
Read more Security