In the Change WP URL plugin for WordPress versions up to and including 1.0 a medium severity vulnerability CVE-2026-1398 was detected. This vulnerability allows unauthenticated attackers to change the WordPress login URL via a forged request due to missing or incorrect nonce validation on the change-wp-url page. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1398.
Read more CMSIn the Vzaar Media Management plugin for WordPress versions up to and including 1.2 a medium severity vulnerability CVE-2026-1391 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via a Reflected Cross-Site Scripting (XSS) attack due to insufficient input sanitization and output escaping on the $_SERVER[‘PHP_SELF’] variable. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1391.
Read more CMSIn the Bitcoin Donate Button plugin for WordPress versions up to and including 1.0 a medium severity vulnerability CVE-2026-1380 was detected. This vulnerability allows unauthenticated attackers to modify the plugin’s settings, including donation addresses and display configurations, via a forged request due to missing or incorrect nonce validation on the settings page. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1380.
Read more CMSIn the imwptip plugin for WordPress versions up to and including 1.1 a medium severity vulnerability CVE-2026-1377 was detected. This vulnerability allows unauthenticated attackers to update the plugin’s settings via a forged request due to missing nonce validation on the settings update functionality. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1377.
Read more CMSIn the JavaScript Notifier plugin for WordPress versions up to and including 1.2.8 a medium severity vulnerability CVE-2026-1191 was detected. This vulnerability allows authenticated attackers with administrator-level access to inject arbitrary web scripts via plugin settings, which are rendered through the wp_footer action, due to insufficient input sanitization and output escaping of user-supplied attributes. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1191.
Read more CMS NewsflashIn GitLab CE/EE versions from 12.3 up to but not including 18.6.4, 18.7 up to but not including 18.7.2, and 18.8 up to but not including 18.8.2 a medium severity vulnerability CVE-2026-1102 was detected. This vulnerability allows unauthenticated attackers to create a denial of service condition by sending repeated malformed SSH authentication requests, due to improper allocation of resources without adequate limits or throttling. To address this issue, users should upgrade GitLab to versions 18.6.4, 18.7.2, 18.8.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1102.
Read more Newsflash Developer ToolsIn GitLab CE/EE versions from 18.6 up to but not including 18.6.4, 18.7 up to but not including 18.7.2, and 18.8 up to but not including 18.8.2 a high severity vulnerability CVE-2026-0723 was detected. This vulnerability allows an attacker with prior knowledge of a victim’s credential ID to bypass two-factor authentication by submitting forged device responses, due to an unchecked return value. To address this issue, users should upgrade GitLab to versions 18.6.4, 18.7.2, 18.8.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-0723.
Read more Newsflash Developer ToolsIn GitLab CE/EE versions from 17.7 up to but not including 18.6.4, 18.7 up to but not including 18.7.2, and 18.8 up to but not including 18.8.2 a high severity vulnerability CVE-2025-13928 was detected. This vulnerability allows unauthenticated attackers to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints. To address this issue, users should upgrade GitLab to versions 18.6.4, 18.7.2, 18.8.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13928.
Read more Newsflash Developer ToolsIn GitLab CE/EE versions from 11.9 up to but not including 18.6.4, 18.7 up to but not including 18.7.2, and 18.8 up to but not including 18.8.2 a high severity vulnerability CVE-2025-13927 was detected. This vulnerability allows unauthenticated attackers to create a denial of service condition by sending crafted requests containing malformed authentication data, due to improper allocation of resources without limits or throttling. To address this issue, users should upgrade GitLab CE/EE to versions 18.6.4, 18.7.2, 18.8.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13927.
Read more Newsflash Developer Tools