In ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce component for WordPress versions 1.17.8 and earlier a critical severity vulnerability CVE-2026-18080 was detected. This vulnerability allows attackers to upload arbitrary files of any type. To address this issue, users should upgrade ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18080.
Read more CMSIn Classified Listing – Mobile Number Verification component for WordPress versions 1.6.0 and earlier a high severity vulnerability CVE-2026-15985 was detected. This vulnerability allows unauthenticated attackers to authenticate as any user with a registered phone number. To address this issue, users should upgrade Classified Listing – Mobile Number Verification to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15985.
Read more CMSIn Mobile App for WooCommerce component for WooCommerce versions 0.4.62 and earlier a high severity vulnerability CVE-2026-27330 was detected. This vulnerability allows unauthenticated attackers to gain unauthorized access to the application. To address this issue, users should upgrade Mobile App for WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27330.
Read more E-commerceIn Apache Hive versions before 4.2.1 a critical severity vulnerability CVE-2026-55976 was detected. This vulnerability allows an authenticated remote attacker to perform Server-Side Request Forgery (SSRF) attacks. To address this issue, users should upgrade Apache Hive to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-55976.
Read more Data AnalyticsIn the keycloak-services component for Keycloak in unpatched versions a medium severity vulnerability CVE-2026-79652 was detected. This vulnerability allows an authenticated attacker to bypass user consent requirements and gain unauthorized access. To address this issue, users should upgrade Keycloak to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-79652.
Read more SecurityIn eCommerce Product Catalog component for WordPress versions 3.5.10 and earlier a medium severity vulnerability CVE-2026-76128 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade eCommerce Product Catalog to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-76128.
Read more CMSIn Apache Hive versions before 4.2.1 a critical severity vulnerability CVE-2026-49845 was detected. This vulnerability allows authenticated users to read, modify, or affect unintended partition metadata. To address this issue, users should upgrade Apache Hive to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-49845.
Read more Data AnalyticsIn Apache Hive versions 4.0.0 through 4.2.0 a high severity vulnerability CVE-2026-53561 was detected. This vulnerability allows an unauthenticated attacker to authenticate as an arbitrary user. To address this issue, users should upgrade Apache Hive to version 4.2.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-53561.
Read more Data AnalyticsIn ShopBuilder Pro – Elementor WooCommerce Builder Addons component for WooCommerce versions 2.2.0 and earlier a high severity vulnerability CVE-2026-32477 was detected. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server. To address this issue, users should upgrade ShopBuilder Pro – Elementor WooCommerce Builder Addons to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32477.
Read more E-commerce