|
1441
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
|
CWE-89
SQL Injection
|
CVE-2026-54849
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1442
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54841
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1443
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
|
CWE-89
SQL Injection
|
CVE-2026-54838
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1444
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
|
CWE-94
Code Injection
|
CVE-2026-54823
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1445
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
|
CWE-89
SQL Injection
|
CVE-2026-54822
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1446
|
9.9 |
CRITICAL
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via …
|
CWE-79 CWE-1188
Cross-site Scripting Insecure Default Initialization of Resource
|
CVE-2026-54067
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1447
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghos…
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-53945
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1448
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v…
|
CWE-200
Information Exposure
|
CVE-2026-52815
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1449
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evalu…
|
CWE-284
Improper Access Control
|
CVE-2026-52810
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1450
|
7.1 |
HIGH
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:o…
|
CWE-269 CWE-863
Improper Privilege Management Incorrect Authorization
|
CVE-2026-52808
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|