In Ninja Forms – Layout & Styles component for WordPress versions 3.0.31 and earlier a high severity vulnerability CVE-2026-81772 was detected. This vulnerability allows unauthenticated attackers to perform PHP object injection. To address this issue, users should upgrade Ninja Forms – Layout & Styles to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81772.
Read more CMSIn Kimai versions 2.65.0 and earlier a medium severity vulnerability CVE-2026-84804 was detected. This vulnerability allows authenticated users to bypass authorization controls. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84804.
Read more Project ManagementIn Kimai versions from 2.61.0 before 2.63.0 a medium severity vulnerability CVE-2026-84805 was detected. This vulnerability allows an authenticated regular user to use the API to modify their own admin-only work-contract data. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84805.
Read more Project ManagementIn Ultimate Gift Cards For WooCommerce component for WooCommerce versions 3.2.9 and earlier a medium severity vulnerability CVE-2026-84760 was detected. This vulnerability allows unauthenticated attackers to gain unauthorized access to restricted functionalities. To address this issue, users should upgrade Ultimate Gift Cards For WooCommerce to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84760.
Read more E-commerceIn WooCommerce Product Attachment component for WooCommerce versions 2.3.3 and earlier a high severity vulnerability CVE-2026-81774 was detected. This vulnerability allows attackers to expose sensitive data. To address this issue, users should upgrade WooCommerce Product Attachment to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-81774.
Read more E-commerceIn FreeIPA (unspecified versions) a medium severity vulnerability CVE-2026-11873 was detected. This vulnerability allows unauthenticated attackers to cause resource exhaustion through log amplification and expose internal stack traces. To address this issue, users should upgrade FreeIPA to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11873.
Read more Security