Vulnerability Notes
- CVE-2026-86184 - Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route
- CVE-2025-9049 - Nokri – Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authenticated (Subscriber +) Privilege Escalation via Account Takeover
- CVE-2026-86196 - Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
- CVE-2026-86195 - grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag
- CVE-2026-86193 - Grav API Plugin Authentication Bypass via Group-Inherited Super
- CVE-2026-86190 - WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter
- CVE-2026-86189 - WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php
- CVE-2026-86177 - Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks
- CVE-2026-86169 - Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
- CVE-2026-86119 - Webstudio through 0.296.0 SSRF via /cgi proxy routes
- CVE-2026-86117 - Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching
- CVE-2024-11080 - Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection
- CVE-2026-81543 - Abandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
- CVE-2026-19887 - Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback
- CVE-2026-83627 - Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log
- CVE-2026-13447 - MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery
- CVE-2026-86140 - libxml2 Stack-Based Buffer Overflow
- CVE-2026-52777 - YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize