|
1431
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their articles. To prevent fal…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-50128
|
2026-06-26 01:32 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1432
|
7.5 |
HIGH
Network
|
-
|
-
|
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability), due to missing exception …
|
CWE-248
Uncaught Exception
|
CVE-2026-50129
|
2026-06-26 01:32 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1433
|
- |
|
-
|
-
|
Our payment integration with Mollie did not properly validate payment
status responses. An attacker could use a successful payment status
response from one payment and supply it to the system for a…
|
CWE-841
Improper Enforcement of Behavioral Workflow
|
CVE-2026-57536
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1434
|
- |
|
-
|
-
|
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src
attribute of these images pointed to an URL, the PDF rendering engine
would d…
|
CWE-80
Basic XSS
|
CVE-2026-57535
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1435
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
|
CWE-80
Basic XSS
|
CVE-2026-57534
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1436
|
- |
|
-
|
-
|
Malicious HTML content could be injected into the page pretix shows when
redirection to an untrusted page occurs. Since this page has a
Content-Security-Policy, this can mainly be used for phishing…
|
CWE-80
Basic XSS
|
CVE-2026-57533
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1437
|
- |
|
-
|
-
|
Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was executed when the PDF editor is opened in the
browser. This could allow one backend user to inject J…
|
CWE-80
Basic XSS
|
CVE-2026-57532
|
2026-06-26 01:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1438
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-56071
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1439
|
7.1 |
HIGH
Network
|
-
|
-
|
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-56042
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1440
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-56023
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|