In Upsell Order Bump Offer for WooCommerce component for WooCommerce versions 3.1.5 and earlier a high severity vulnerability CVE-2026-81288 was detected. This vulnerability allows unauthenticated attackers to perform Cross-Site Scripting attacks. To address this issue, users should upgrade Upsell Order Bump Offer for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81288.
Read more E-commerceIn miniOrange extensions component for Joomla a high severity vulnerability CVE-2026-78074 was detected. This vulnerability allows unauthenticated actors to delete arbitrary installed extensions. To address this issue, users should upgrade miniOrange extensions to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78074.
Read more CMSIn Helix Ultimate component for Joomla versions 2.2.10 and earlier a medium severity vulnerability CVE-2026-78076 was detected. This vulnerability allows an authenticated user to modify layout parameters for arbitrary menu items without proper authorization. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78076.
Read more CMSIn Helix Ultimate component for Joomla versions before 2.2.10 a high severity vulnerability CVE-2026-78077 was detected. This vulnerability allows attackers to inject malicious HTML or JavaScript code. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78077.
Read more CMSIn Helix Ultimate component for Joomla versions before 2.2.10 a medium severity vulnerability CVE-2026-78075 was detected. This vulnerability allows an author to delete arbitrary files. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78075.
Read more CMSIn Helix Ultimate component for Joomla versions earlier than 2.2.10 a high severity vulnerability CVE-2026-78078 was detected. This vulnerability allows attackers to bypass file upload restrictions. To address this issue, users should upgrade Helix Ultimate to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-78078.
Read more CMSIn Dolibarr versions 10.0.0 before 24.0.0 a medium severity vulnerability CVE-2026-82633 was detected. This vulnerability allows authenticated users to retrieve group memberships of other users. To address this issue, users should upgrade Dolibarr to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82633.
Read more ERPIn Cozmoslabs Profile Builder Plugin component for WordPress versions 3.16.1 and earlier a high severity vulnerability CVE-2026-82607 was detected. This vulnerability allows attackers to perform unauthorized actions. To address this issue, users should upgrade Cozmoslabs Profile Builder Plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-82607.
Read more CMSIn 爱采集数据采集和发布插件 component for WordPress versions 1.0.0 and earlier a medium severity vulnerability CVE-2026-77013 was detected. This vulnerability allows unauthenticated users to create WordPress user accounts and taxonomy terms. To address this issue, users should upgrade 爱采集数据采集和发布插件 to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77013.
Read more CMS