CVE-2026-13000 to CVE-2026-13999
172 CVEs with public proof-of-concept exploits.
- CVE-2026-130013 PoCsPodlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
- CVE-2026-131421 PoCPasswordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force
- CVE-2026-131431 PoCWP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
- CVE-2026-131451 PoCWP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
- CVE-2026-131472 PoCsKirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
- CVE-2026-131521 PoCCustom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
- CVE-2026-131531 PoCEssential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint
- CVE-2026-131541 PoCEssential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint
- CVE-2026-131561 PoCMailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
- CVE-2026-131572 PoCsTheme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
- CVE-2026-131582 PoCsEverest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
- CVE-2026-131681 PoCEventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API
- CVE-2026-131691 PoCEventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR
- CVE-2026-131701 PoCEventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
- CVE-2026-131711 PoCEventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint
- CVE-2026-131721 PoCEventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure
- CVE-2026-131731 PoCEventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
- CVE-2026-131741 PoCEventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
- CVE-2026-131751 PoCEventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
- CVE-2026-131761 PoCEventin < 4.1.21 - Contributor+ Server-Side Request Forgery
- CVE-2026-131771 PoCEventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR
- CVE-2026-131781 PoCEventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
- CVE-2026-132331 PoCOpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
- CVE-2026-133111 PoCshell-quote parse() is quadratic in token count, enabling denial of service
- CVE-2026-133201 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-133281 PoCTLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification
- CVE-2026-133291 PoCWC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund
- CVE-2026-133301 PoCAnimation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload
- CVE-2026-133321 PoCMasteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)
- CVE-2026-133401 PoCSVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
- CVE-2026-133421 PoCSecurity Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
- CVE-2026-133441 PoCEssential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
- CVE-2026-133451 PoCEssential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
- CVE-2026-133891 PoCWebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
- CVE-2026-133901 PoCThe Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation
- CVE-2026-133921 PoCElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)
- CVE-2026-133931 PoCElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)
- CVE-2026-133951 PoCBookly < 27.8 - Unauthenticated SQL Injection via staff_id
- CVE-2026-133991 PoCPayment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
- CVE-2026-134001 PoCSimply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information
- CVE-2026-134021 PoCRoyal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
- CVE-2026-134041 PoCRoyal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init
- CVE-2026-134051 PoCRoyal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder
- CVE-2026-134061 PoCRoyal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure
- CVE-2026-134141 PoCCMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax
- CVE-2026-134151 PoCCMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings
- CVE-2026-134161 PoCCMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia
- CVE-2026-134231 PoCStreamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
- CVE-2026-134321 PoCThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
- CVE-2026-134831 PoCarc53 DocsGPT Credential Storage encryption.py encrypt_credentials data authenticity
- CVE-2026-134841 PoCMLflow Experiment-scoped Label Schema CRUD API authorization
- CVE-2026-134851 PoCSourceCodester Class and Exam Timetabling System preview.php sql injection
- CVE-2026-134861 PoCSourceCodester Class and Exam Timetabling System preview6.php sql injection
- CVE-2026-134871 PoCSourceCodester Class and Exam Timetabling System archive.php sql injection
- CVE-2026-134881 PoCSourceCodester Class and Exam Timetabling System preview7.php sql injection
- CVE-2026-134891 PoC78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization
- CVE-2026-134911 PoC78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
- CVE-2026-134931 PoCAIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
- CVE-2026-134951 PoCitsourcecode Hospital Management System adminprofile.php sql injection
- CVE-2026-134961 PoCitsourcecode Hospital Management System ajaxmedicine.php sql injection
- CVE-2026-134971 PoCitsourcecode Hospital Management System appointment.php sql injection
- CVE-2026-134981 PoCyashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
- CVE-2026-134991 PoCyashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
- CVE-2026-135001 PoCantlr ANTLR4 Grammar Action Block OutputFile.java code injection
- CVE-2026-135011 PoCantlr ANTLR4 gofmt GoTarget.java GoTarget command injection
- CVE-2026-135021 PoCantlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
- CVE-2026-135031 PoCantlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path traversal
- CVE-2026-135041 PoCcode-projects Project Management System Mail Compose mail.php cross site scripting
- CVE-2026-135081 PoCkhoj-ai khoj Conversation Sharing api_chat.py authorization
- CVE-2026-135091 PoCRAGapp Knowledge File files.py FileHandler.remove_file path traversal
- CVE-2026-135101 PoCSimStudioAI sim Password Protection deployment.ts weak hash
- CVE-2026-135111 PoCVoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
- CVE-2026-135121 PoCDatabend Tenant client_session_manager.rs state_key authorization
- CVE-2026-135131 PoCMyScale MyScaleDB SegmentId.h getCacheKey data authenticity
- CVE-2026-135141 PoCChess Play and Learn App com.chess AndroidManifest.xml backup
- CVE-2026-135151 PoCTenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
- CVE-2026-135161 PoCTenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow
- CVE-2026-135171 PoCTenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow
- CVE-2026-135181 PoCTenda JD12L addressNat fromAddressNat stack-based overflow
- CVE-2026-135191 PoCTenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow
- CVE-2026-135201 PoCitsourcecode Hospital Management System Appointment appointmentapproval.php sql injection
- CVE-2026-135211 PoCSourceCodester Class and Exam Timetabling System preview5.php sql injection
- CVE-2026-135231 PoCGPAC ISOBMFF base_encoding.c data amplification
- CVE-2026-135241 PoCCherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
- CVE-2026-135251 PoCCodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection
- CVE-2026-135261 PoCSourceCodester Class and Exam Timetabling System edit_class.php sql injection
- CVE-2026-135271 PoCSourceCodester Class and Exam Timetabling System preview4.php sql injection
- CVE-2026-135281 PoCYunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal
- CVE-2026-135291 PoCYzmCMS index.php sql injection
- CVE-2026-135301 PoCitsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
- CVE-2026-135311 PoCitsourcecode Hospital Management System department.php sql injection
- CVE-2026-135321 PoCitsourcecode Hospital Management System departmentDoctor.php sql injection
- CVE-2026-135331 PoCagentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
- CVE-2026-135341 PoCCherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
- CVE-2026-135351 PoCCodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection
- CVE-2026-135361 PoCGotoHTTP reg.12x cross site scripting
- CVE-2026-135371 PoCCodeAstro Human Resource Management System cross-site request forgery
- CVE-2026-135381 PoCWavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
- CVE-2026-135391 PoCWavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow
- CVE-2026-135401 PoCGitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-side request forgery
- CVE-2026-135411 PoCitsourcecode Hospital Management System doctorchangepassword.php sql injection
- CVE-2026-135421 PoCitsourcecode Hospital Management System doctorprofile.php sql injection
- CVE-2026-135431 PoCDocumenso Google OAuth Login handle-oauth-callback-url.ts improper authentication
- CVE-2026-135441 PoCFeehi CMS API users access control
- CVE-2026-135451 PoCD-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
- CVE-2026-135461 PoCFeehi CMS REST API Endpoint articles missing authentication
- CVE-2026-135471 PoCHanwang e-Face General Management Platform upload.do unrestricted upload
- CVE-2026-135481 PoCitsourcecode Hospital Management System doctortimings.php sql injection
- CVE-2026-135491 PoCCodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
- CVE-2026-135501 PoCitsourcecode Baptism Information Management System delbaptism.php sql injection
- CVE-2026-135511 PoCitsourcecode Baptism Information Management System editBaptism.php sql injection
- CVE-2026-135521 PoCitsourcecode Online Hotel Management System controller.php edit sql injection
- CVE-2026-135531 PoCitsourcecode Online Hotel Management System controller.php add unrestricted upload
- CVE-2026-135541 PoCitsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
- CVE-2026-135551 PoCitsourcecode Online Hotel Management System controller.php add sql injection
- CVE-2026-135561 PoCitsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
- CVE-2026-135571 PoCitsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
- CVE-2026-135581 PoCCodeAstro Complaint Management System Report addreport cross site scripting
- CVE-2026-135591 PoCcode-projects Real State Services single-list_sale.php add sql injection
- CVE-2026-135601 PoCEdimax EW-7478APC POST Request formAccept os command injection
- CVE-2026-135611 PoCEdimax EW-7478APC POST Request formiNICbasic os command injection
- CVE-2026-135621 PoCEdimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow
- CVE-2026-135631 PoCEdimax EW-7478APC POST Request formL2TPSetup stack-based overflow
- CVE-2026-135641 PoCEdimax EW-7478APC POST Request formPPPoESetup stack-based overflow
- CVE-2026-135651 PoCSourceCodester Class and Exam Timetabling System edit_class1.php sql injection
- CVE-2026-135661 PoCSourceCodester Class and Exam Timetabling System preview3.php sql injection
- CVE-2026-135671 PoCcode-projects Online Music Site POST Request Feedback.php cross site scripting
- CVE-2026-135691 PoCweng-xianhu EyouCMS API index.php sql injection
- CVE-2026-135711 PoCSourceCodester Simple Food Ordering System cart.php logic error
- CVE-2026-135721 PoCitsourcecode Hospital Management System insertbillingrecord.php sql injection
- CVE-2026-135731 PoCllvm llvm-project ValueSymbolTable ValueSymbolTable.cpp insert stack-based overflow
- CVE-2026-135741 PoCllvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
- CVE-2026-135781 PoCitsourcecode Hospital Management System patientdetail.php sql injection
- CVE-2026-135791 PoCitsourcecode Hospital Management System patientchangepassword.php sql injection
- CVE-2026-135801 PoCEdimax EW-7478APC POST Request formQoS buffer overflow
- CVE-2026-135811 PoCEdimax EW-7478APC POST Request formStaDrvSetup os command injection
- CVE-2026-135821 PoCEdimax EW-7478APC POST Request formUSBAccount buffer overflow
- CVE-2026-135831 PoCEdimax EW-7478APC POST Request formUSBFolder buffer overflow
- CVE-2026-135851 PoCAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System…
- CVE-2026-135871 PoCseladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
- CVE-2026-135881 PoCseladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
- CVE-2026-135891 PoCseladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
- CVE-2026-135901 PoCseladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
- CVE-2026-135911 PoCDeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
- CVE-2026-135921 PoCliftoff-sr CIPster EtherNet IP Message append out-of-bounds write
- CVE-2026-135961 PoCParticipants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search
- CVE-2026-135971 PoCQRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
- CVE-2026-135981 PoCRestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator
- CVE-2026-136001 PoCAutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
- CVE-2026-136041 PoCPixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
- CVE-2026-136051 PoCPhoto Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
- CVE-2026-136091 PoCFrontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field
- CVE-2026-136102 PoCsKiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
- CVE-2026-136121 PoCKiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR
- CVE-2026-136131 PoCKiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint
- CVE-2026-136901 PoCUsersWP < 1.2.67 - Two-Factor Authentication Bypass
- CVE-2026-136921 PoCPayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
- CVE-2026-136931 PoCBit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
- CVE-2026-136941 PoCBit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass
- CVE-2026-137001 PoCWooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure
- CVE-2026-137011 PoCAdvanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
- CVE-2026-137031 PoCSEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
- CVE-2026-137121 PoCDivi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
- CVE-2026-137143 PoCsRealtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
- CVE-2026-137251 PoCDynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
- CVE-2026-137261 PoCMultiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode
- CVE-2026-137291 PoCPodlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
- CVE-2026-137311 PoCWPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter
- CVE-2026-137362 PoCsNewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API
- CVE-2026-137531 PoCCertain HP DeskJet All in One – Potential Information Disclosure
- CVE-2026-137682 PoCsGardyn IoT Hub Use of Hard-coded Credentials
- CVE-2026-139341 PoCInsufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had…