In Redux Framework component for WordPress versions 4.5.13.1 and earlier a medium severity vulnerability CVE-2026-5399 was detected. This vulnerability allows attackers to inject arbitrary web scripts. To address this issue, users should upgrade Redux Framework to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5399.
Read more CMSIn SP Property component for Joomla versions prior to 4.1.4 a high severity vulnerability CVE-2026-78083 was detected. This vulnerability allows attackers to perform unauthorized actions on behalf of authenticated users. To address this issue, users should upgrade SP Property to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78083.
Read more CMSIn Apache ActiveMQ versions prior to 5.19.11 a high severity vulnerability CVE-2026-74761 was detected. This vulnerability allows an authenticated client to spoof their clientId when removing a durable topic subscription. To address this issue, users should upgrade Apache ActiveMQ to version 5.19.11 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-74761.
Read more Developer ToolsIn the Portworx Operator component for OpenShift a high severity vulnerability CVE-2026-15140 was detected. This vulnerability allows a user with limited permissions to escalate privileges within the Kubernetes cluster. To address this issue, users should upgrade Portworx Operator to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15140.
Read more Developer ToolsIn Rara One Click Demo Import component for WordPress versions before 1.3.5 a high severity vulnerability CVE-2026-26212 was detected. This vulnerability allows an attacker to achieve remote code execution. To address this issue, users should upgrade Rara One Click Demo Import to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26212.
Read more CMSIn league/commonmark component for PHP versions before 2.6.0 a high severity vulnerability CVE-2024-58382 was detected. This vulnerability allows attackers to cause denial of service. To address this issue, users should upgrade league/commonmark to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58382.
Read more Web DevelopmentIn IP2Location Country Blocker component for WordPress versions before 2.45.0 a medium severity vulnerability CVE-2026-82530 was detected. This vulnerability allows unauthenticated attackers to bypass IP-based access restrictions. To address this issue, users should upgrade IP2Location Country Blocker to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82530.
Read more CMSIn EDD Product Catalog Feed by PixelYourSite component for WordPress versions 1.0.2 and earlier a high severity vulnerability CVE-2026-9331 was detected. This vulnerability allows authenticated attackers to delete arbitrary option values. To address this issue, users should upgrade EDD Product Catalog Feed by PixelYourSite to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-9331.
Read more CMSIn LearnPress – WordPress LMS Plugin for Create and Sell Online Courses component for WordPress versions up to and including 4.3.9.1 a medium severity vulnerability CVE-2026-12230 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade LearnPress – WordPress LMS Plugin for Create and Sell Online Courses to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12230.
Read more CMS