4.3 CVE-2026-10630
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses...

2026-08-25T18:17:51.470

6.5 CVE-2026-15023
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable...

2026-08-25T16:16:47.807

CVE-2026-16434
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix...

2026-08-25T02:16:40.110

4.3 CVE-2026-19801
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin...

2026-08-25T20:16:52.550

4.7 CVE-2026-34959
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"]...

2026-08-25T02:16:40.400

5.8 CVE-2026-34964
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server...

2026-08-25T02:16:40.553

5.4 CVE-2026-34967
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write...

2026-08-25T16:16:52.343

8.1 CVE-2026-34968
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list...

2026-08-25T16:16:52.477

8.8 CVE-2026-56702
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload...

2026-08-25T02:16:41.900

7.2 CVE-2026-56703
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM...

2026-08-25T18:17:56.320

6.1 CVE-2026-56704
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid...

2026-08-25T02:16:42.187

9.8 CVE-2026-56705
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing...

2026-08-25T16:16:56.103

6.8 CVE-2026-56706
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value...

2026-08-25T16:16:56.227

7.7 CVE-2026-56707
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability...

2026-08-25T02:16:42.637

5.3 CVE-2026-56708
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery...

2026-08-25T18:17:56.467

7.5 CVE-2026-56709
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when...

2026-08-25T02:16:42.930

9.8 CVE-2026-56710
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the...

2026-08-25T16:16:56.343

8.1 CVE-2026-72695
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows...

2026-08-25T18:18:02.107

8.4 CVE-2026-72696
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile()...

2026-08-25T02:16:45.253

6.5 CVE-2026-72697
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function...

2026-08-25T18:18:02.263

6.5 CVE-2026-72698
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig...

2026-08-25T02:16:45.550