Anwendungssicherheit
🟠 CVE-2026-9834: High Schwachstelle
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to...
🟠 CVE-2026-39448: High Schwachstelle
Unauthenticated Broken Access Control in NOWPayments for WooCommerce
🟠 CVE-2026-8441: High Schwachstelle
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs...
🟠 CVE-2026-9563: High Schwachstelle
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on...
🟠 CVE-2026-14249: High Schwachstelle
The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via...
🟠 CVE-2026-5821: High Schwachstelle
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This...
🟠 CVE-2026-14336: High Schwachstelle
PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of...
🟠 CVE-2025-69094: High Schwachstelle
Subscriber SQL Injection in Unicamp
🟠 CVE-2026-56037: High Schwachstelle
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through...
🟠 CVE-2026-27414: High Schwachstelle
Contributor PHP Object Injection in Werkstatt