Skip to content
Threat Feed

September 2026 (30)

high advisory

Stored XSS in Popup Maker WordPress Plugin (CVE-2026-87915)

The Popup Maker WordPress plugin is vulnerable to Stored Cross-Site Scripting via the 'values[Name]' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the wp-admin dashboard.

Popup Maker
2t 1c
high advisory

Denial of Service Vulnerability in Quarkus WebSockets Next

A vulnerability in quarkus-websockets-next allows a remote attacker to cause a Denial of Service via heap exhaustion by streaming WebSocket messages faster than the application can process them.

Quarkus +1 denial-of-service java application-security web-application security-flaw authorization-bypass
1t 1c updated
high advisory

Stored XSS Vulnerability in Jeg Kit for Elementor

The Jeg Kit for Elementor plugin for WordPress contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary scripts when a specific widget is rendered.

Jeg Kit for Elementor wordpress xss web-application
2t 1c
low advisory

CVE-2026-89059: Denial of Service in RESTEasy IIOImageProvider

An unauthenticated remote attacker can trigger a denial of service in Red Hat RESTEasy by submitting a crafted image that causes excessive memory allocation within the JVM via the IIOImageProvider component.

RESTEasy denial-of-service java
1t 1c
high advisory

WeaselBiscuit Stealer Distributed via Malicious npm Packages

WeaselBiscuit is a lightweight JavaScript stealer discovered in 13 npm packages that harvests sensitive browser extension storage and performs host profiling across Windows, macOS, and Linux.

npm supply-chain infostealer javascript malware
4t 1i
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

open source packages +49 campaign clickfix
29i updated
low advisory

Reflected XSS in Ourphp via ourphp_out.php

Ourphp versions 7.2.0 and earlier are vulnerable to reflected cross-site scripting (XSS) via the 'out' parameter in the 'ourphp_out.php' endpoint, allowing unauthorized script execution in a victim's browser session.

Ourphp web-application xss cve-2023-30212
1r 1t 1c
high advisory

CVE-2026-7473: Arista EOS Incomplete Comparison Vulnerability Leading to Incorrect Packet Forwarding

Arista Extensible Operating System (EOS) contains CVE-2026-7473, an incomplete comparison vulnerability that allows a switch to incorrectly decapsulate and forward unexpected tunneled packets if their destination IP matches the switch's configured decapsulation IP, potentially leading to unauthorized network access or bypass of security controls.

PoC Extensible Operating System +4 vulnerability cve network-device infrastructure
2r 3t 3c updated
high advisory

Pi-hole SSRF to RCE Vulnerability via CVE-2024-34361

Pi-hole versions 5.18.2 and earlier are vulnerable to an authenticated SSRF attack via improper URL validation, which can be chained with the Gopherus protocol to achieve remote code execution on the host system.

Pi-hole vulnerability rce ssrf
1r 2t 1c
high advisory

Authorization Bypass in Master Addons for Elementor

An authorization bypass vulnerability in the Master Addons for Elementor WordPress plugin allows authenticated contributors to modify or delete arbitrary posts.

Master Addons for Elementor wordpress vulnerability authorization-bypass
1t 1c
high advisory

Stored XSS Vulnerability in Complianz WordPress Plugin

The Complianz GDPR/CCPA Cookie Consent Banner plugin is vulnerable to Stored Cross-Site Scripting (XSS) via the Elementor Cookie Blocker, allowing attackers to execute arbitrary JavaScript in the context of an administrator-approved comment.

Complianz GDPR/CCPA Cookie Consent Banner +1 wordpress xss web-application
2t 1c
high advisory

SQL Injection in Location Manager Plugin for WordPress

The Location Manager plugin for WordPress is vulnerable to unauthenticated SQL injection via REST API parameters, allowing remote attackers to extract sensitive database information.

Location Manager web-application-vulnerability sql-injection wordpress
1r 1t 1c
high advisory

SQL Injection Vulnerability in WCFM Marketplace Plugin

The WCFM Marketplace plugin for WordPress is vulnerable to unauthenticated SQL injection via the wcfmmp_user_location_lng parameter, allowing attackers to extract sensitive database information.

WCFM Marketplace – Multivendor Marketplace for WooCommerce
1r 1t 1c
high advisory

Unauthenticated SQL Injection in WP Multi Store Locator Pro

The WP Multi Store Locator Pro plugin for WordPress is vulnerable to unauthenticated SQL injection via the 'store_locatore_search_radius' parameter due to inadequate input sanitization and a lack of prepared statements.

WP Multi Store Locator Pro
1r 1t 1c
high advisory

Directory Traversal in Printcart Web to Print Product Designer for WooCommerce

The Printcart Web to Print Product Designer for WooCommerce plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary server files.

Web to Print Product Designer for WooCommerce
1r 1t 1c
high advisory

Arbitrary User Meta Write Vulnerability in Mapster WP Maps Plugin

The Mapster WP Maps WordPress plugin contains an arbitrary user meta write vulnerability via the my_profile_update() function, allowing authenticated users with Subscriber-level access to overwrite arbitrary user metadata.

WP Maps web-vulnerability wordpress arbitrary-meta-write
1t 1c
high advisory

Authorization Bypass in TECHIN2B Application

An authorization bypass vulnerability in TECHIN2B Application allows unauthenticated or low-privileged users to perform privilege abuse via user-controlled keys.

TECHIN2B Application vulnerability privilege-escalation
1t 1c
critical advisory

CVE-2026-58138: Unauthenticated Remote Code Execution in Orkes Conductor

An unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor allows attackers to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions within inline workflow definitions to the workflow API endpoint before authentication, leveraging unsandboxed GraalVM evaluators through specific task types to invoke system commands via Java reflection or direct subprocess calls.

Conductor 3.21.21 +2 RCE vulnerability Java Conductor web-application
1r 3t 2i updated
high advisory

CVE-2026-93453 Password Reset Poisoning in SOGo

SOGo versions before 5.12.11 are vulnerable to password reset poisoning, allowing unauthenticated attackers to manipulate reset links by injecting malicious values into the Origin header.

PoC SOGo +1 web-application credential-theft cve-2026-93453
1t 1c updated
high advisory

Booking Calendar Plugin Privilege Escalation via AJAX Parameter Injection

The Booking Calendar plugin for WordPress is vulnerable to privilege escalation (CVE-2026-92619) allowing authenticated Editors to modify arbitrary site settings and create administrative accounts.

Booking Calendar privilege-escalation wordpress web-application
1t 1c
high advisory

Authorization Bypass in WordPress Filter Gallery Plugin

The Filter Gallery WordPress plugin contains an authorization bypass vulnerability (CVE-2026-89413) allowing authenticated users with low-level privileges to delete arbitrary gallery records by omitting mandatory nonce checks.

Filter Gallery
1t 1c
high advisory

Chromium V8 Engine Out-of-Bounds Memory Access Vulnerability

CVE-2026-0899 is an out-of-bounds memory access vulnerability in the Chromium V8 JavaScript engine that may result in memory corruption, process crashes, or arbitrary code execution.

Chromium vulnerability browser-security
1c
high advisory

CVE-2026-17086 PHP Object Injection in ShortPixel Image Optimizer

Authenticated attackers can exploit insecure deserialization in ShortPixel Image Optimizer versions 6.5.5 and below to execute arbitrary code if a POP chain is available via other plugins or themes.

ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF wordpress vulnerability php-injection deserialization
1t 1c
high advisory

Remote Code Execution Vulnerability in Check Point Management Products

A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.

Log Server +5 vulnerability rce network-security
1c updated
high advisory

Command Injection in marcopiovanello yt-dlp-web-ui

An unauthenticated remote command injection vulnerability in yt-dlp-web-ui version 4 and earlier allows remote attackers to execute arbitrary system commands via the params argument.

yt-dlp-web-ui remote-code-execution command-injection vulnerability
2t 1c
high advisory

CSRF and Stored XSS Vulnerability in django-page-cms

An improper CSRF protection flaw in django-page-cms versions up to 2.0.13 enables attackers to force authenticated editors to inject stored XSS payloads.

django-page-cms web-vulnerability csrf xss
1t 1c
high advisory

Use-After-Free Vulnerability in GPAC Compositor

A use-after-free vulnerability in the GPAC compositor component (CVE-2026-91087) allows remote attackers to trigger memory corruption via malicious media files.

GPAC +2 vulnerability memory-corruption remote-code-execution cve
1c updated
critical advisory

Remote Code Execution in HGiga OAKlouds via Insecure Deserialization

An insecure deserialization vulnerability in the HGiga OAKlouds platform allows unauthenticated attackers to execute arbitrary code via malicious serialized payloads.

OAKlouds
2t 1c
high threat

Google Security Updates - September 2026

Roundup of Google security advisories published in September 2026.

roundup
2c updated
low advisory

Denial of Service in go-openapi/swag via Stack Overflow

The go-openapi/swag library is vulnerable to a stack overflow in its jsonutils component, allowing remote unauthenticated attackers to cause a denial-of-service by submitting deeply nested JSON documents.

swag
1c