Anwendungssicherheit
🟡 CVE-2026-19222: Medium Schwachstelle
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing...
🟡 CVE-2026-19093: Medium Schwachstelle
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media,...
🟠 CVE-2026-77945: High Schwachstelle
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component...
🟠 CVE-2026-63312: High Schwachstelle
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead...
🟠 CVE-2026-62388: High Schwachstelle
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising...
🟠 CVE-2026-2996: High Schwachstelle
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions...
🔴 CVE-2026-4703: Critical Schwachstelle
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection...
🔴 CVE-2026-78003: Critical Schwachstelle
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up...
ANWENDUNGSSICHERHEIT
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and...
ANWENDUNGSSICHERHEIT
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name,...