4.3 CVE-2026-10630
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses...
6.5 CVE-2026-15023
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable...
CVE-2026-16434
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix...
4.3 CVE-2026-19801
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin...
4.7 CVE-2026-34959
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"]...
5.8 CVE-2026-34964
Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server...
5.4 CVE-2026-34967
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write...
8.1 CVE-2026-34968
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list...
8.8 CVE-2026-56702
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload...
7.2 CVE-2026-56703
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM...
6.1 CVE-2026-56704
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid...
9.8 CVE-2026-56705
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing...
6.8 CVE-2026-56706
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value...
7.7 CVE-2026-56707
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability...
5.3 CVE-2026-56708
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery...
7.5 CVE-2026-56709
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when...
9.8 CVE-2026-56710
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the...
8.1 CVE-2026-72695
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows...
8.4 CVE-2026-72696
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile()...
6.5 CVE-2026-72697
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function...
6.5 CVE-2026-72698
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig...