Vulnerabilities

Summary — last 7 days

New vulnerabilities2,768▲ 15 vs. last week
Critical / high1,274▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

611 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedMedium (6.1)——10web Form MakerAI10/10/202610/10/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inputs (array key)' parameter in all versions up to, and including, 1.15.48 due to insufficient input sanitization and output escaping. This makes it possible for…
Awaiting AnalysisMedium (6.5)——ProcessmakerAI10/9/202610/9/2026
ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\Traits\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled…
Awaiting AnalysisCritical (9.3)1.4%—Amazon Sagemaker DistributionAI10/2/202610/6/2026
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated…
DeferredMedium (5.4)0.22%—Popup Maker WPAI10/2/202610/2/2026
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables…
DeferredMedium (4.3)0.15%—Code-atlantic Popup MakerAI10/2/202610/2/2026
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service…
DeferredHigh (7.2)0.30%—10web Form MakerAI10/1/202610/3/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for…
DeferredHigh (8.2)0.36%—MakecommerceAI9/30/20269/30/2026
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
DeferredMedium (5.5)0.28%—Abdurrab5 Online-makeup-storeAI9/23/20269/24/2026
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been…
DeferredMedium (5.5)0.25%—Abdurrab5 Online-makeup-storeAI9/23/20269/29/2026
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published…
DeferredMedium (5.5)0.25%—Abdurrab5 Online-makeup-storeAI9/23/20269/24/2026
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product…
AnalyzedHigh (7.3)0.10%—Claris Filemaker PRO9/23/202610/5/2026
A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3.
AnalyzedCritical (9.1)0.32%—Claris Filemaker Server9/23/202610/5/2026
An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3.
AnalyzedCritical (9.1)0.29%—Claris Filemaker Server9/23/202610/5/2026
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.
AnalyzedHigh (7.8)0.13%—Claris Filemaker Server9/23/202610/6/2026
A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3.
DeferredMedium (6.5)0.18%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.
DeferredHigh (8.2)0.24%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from…
DeferredMedium (4.3)0.18%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
DeferredMedium (4.3)0.18%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
DeferredCritical (9.1)0.68%💥 PoCBootstrapped WP Recipe MakerAI9/19/20269/21/2026
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the…
DeferredMedium (5.4)0.24%—Bootstrapped WP Recipe MakerAI9/18/20269/18/2026
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
DeferredHigh (7.2)0.49%💥 PoCCode-atlantic Popup MakerAI9/18/20269/18/2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible…
DeferredMedium (6.4)0.26%—Code-atlantic Popup MakerAI9/18/20269/19/2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for…
DeferredMedium (5.3)0.36%—NetmakerAI9/15/20269/30/2026
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform boolean-based SQL injection. Version 1.5.0 fixes…
DeferredMedium (6.1)0.38%—10web Form MakerAI9/10/20269/11/2026
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for…
DeferredMedium (4.3)0.37%—Bootstrapped WP Recipe MakerAI9/9/20269/9/2026
The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to…
Orbitaley — Vulnerabilities