Anwendungssicherheit
🟠 CVE-2026-81737: High Schwachstelle
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthenticated visitors before storing...
🟠 CVE-2026-19116: High Schwachstelle
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post...
🟠 CVE-2026-14357: High Schwachstelle
The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is...
🔴 CVE-2026-81286: Critical Schwachstelle
Unauthenticated SQL Injection in WCFM Marketplace
ANWENDUNGSSICHERHEIT
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration...
ANWENDUNGSSICHERHEIT
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV)...
🟡 CVE-2026-75980: Medium Schwachstelle
The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site...
🟡 CVE-2026-18488: Medium Schwachstelle
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions...
🟡 CVE-2026-11873: Medium Schwachstelle
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for...
🟡 CVE-2025-15613: Medium Schwachstelle
Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to...