Vulnerabilities
Summary — last 7 days
New vulnerabilities2,871▲ 236 vs. last week
Critical / high1,338▼ 92 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
403,885 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.3) | 0.24% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong to the caller's workspace. An authenticated user can link issues from any workspace to modules in their own workspace. This issue is fixed in 1.4.0. | |
| Deferred | Medium (5.4) | 0.25% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ allows the user to modify the token's allowed_rate_limit field without server-side validation or a maximum value. A user… | |
| Undergoing Analysis | Medium (6.9) | 0.39% | — | Joomlafry TF ContentAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of… | |
| Undergoing Analysis | Medium (6.3) | 0.32% | — | Svenbluege Event GalleryAI | 10/5/2026 | 10/6/2026 | Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took… | |
| Deferred | High (7.1) | 0.15% | 💥 PoC | Adm-zipAI | 10/5/2026 | 10/7/2026 | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never… | |
| Deferred | Medium (6.5) | 0.27% | — | ApiadminAI | 10/5/2026 | 10/6/2026 | ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter. | |
| Deferred | High (7.2) | 1.0% | — | ApiadminAI | 10/5/2026 | 10/6/2026 | ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory public/upload/Ymd/.… | |
| Deferred | Critical (9.8) | 0.39% | — | GouguoaAI | 10/5/2026 | 10/6/2026 | GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. | |
| Deferred | Critical (9.8) | 0.39% | — | WookteamAI | 10/5/2026 | 10/6/2026 | WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An… | |
| Deferred | Critical (9.8) | 0.74% | — | Dormakaba Evolo ServiceAI | 10/5/2026 | 10/6/2026 | An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component. | |
| Deferred | Medium (5.1) | 0.17% | — | Thimpress LearnpressAI | 10/5/2026 | 10/7/2026 | LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that… | |
| Deferred | Low (2.1) | 0.40% | — | TallcmsAI | 10/5/2026 | 10/7/2026 | A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManager.php of the component PluginManager. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been publicly disclosed… | |
| Deferred | High (8.7) | 0.25% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0. | |
| Deferred | High (7.5) | 0.28% | — | Insumermodel Mppx Condition GateAIInsumermodel Mppx Token GateAI | 10/5/2026 | 10/6/2026 | mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain… | |
| Deferred | High (7.2) | 0.42% | — | Kunstmaan CMSAI | 10/5/2026 | 10/7/2026 | Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend… | |
| Undergoing Analysis | Medium (6.9) | 0.26% | — | Joomlafry TF ContentAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the… | |
| Undergoing Analysis | Medium (5.3) | 0.15% | — | Svenbluege.de Event GalleryAI | 10/5/2026 | 10/6/2026 | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address… | |
| Undergoing Analysis | Medium (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 10/5/2026 | 10/6/2026 | Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting… | |
| Undergoing Analysis | High (8.7) | 0.38% | — | Phoca CartAI | 10/5/2026 | 10/6/2026 | Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only — they… | |
| Undergoing Analysis | Critical (9.3) | 0.28% | 💥 PoC | Ordasoft Joomla CCKAI | 10/5/2026 | 10/6/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector. | |
| Undergoing Analysis | Medium (5.3) | 0.29% | — | Joomshaper SP Page Builder PROAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fieldId> request parameter, split on the delimiter "l-r", HTML-escaped inside the data-value attribute, and then echoed… | |
| Deferred | Medium (6.5) | 0.38% | — | K6 MCP ServerAI | 10/5/2026 | 10/6/2026 | A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory… | |
| Deferred | High (7.5) | 0.57% | — | WookteamAI | 10/5/2026 | 10/6/2026 | WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file)… | |
| Deferred | High (7.5) | 0.69% | — | UnimallAI | 10/5/2026 | 10/6/2026 | Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code. | |
| Awaiting Analysis | Critical (9.8) | 0.36% | — | Dromara NorthstarAI | 10/5/2026 | 10/6/2026 | Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via… |