CVE-2026-16000 to CVE-2026-16999
244 CVEs with public proof-of-concept exploits.
- CVE-2026-160071 PoCAuthenticated SQL Injection in AppFlowy
- CVE-2026-160091 PoCitsourcecode Hospital Management System prescriptionorderdetail.php sql injection
- CVE-2026-160131 PoCliftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
- CVE-2026-160141 PoCcode-projects Hospital Bed Management System Login Form sql injection
- CVE-2026-160151 PoCpoco-ai poco-claw executor_manager API tasks.py create_task missing authentication
- CVE-2026-160161 PoCpoco-ai poco-claw task.py run_task server-side request forgery
- CVE-2026-160171 PoCmosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
- CVE-2026-160301 PoCMStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
- CVE-2026-160321 PoCLWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring
- CVE-2026-160351 PoCminiOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
- CVE-2026-160361 PoCminiOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
- CVE-2026-160381 PoCMStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
- CVE-2026-160391 PoCMStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
- CVE-2026-160411 PoCMStore API < 4.21.0 - Unauthenticated Product Review Creation
- CVE-2026-160421 PoCLWS Optimize < 3.4 - Subscriber+ Cache Deletion
- CVE-2026-160511 PoCWPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action
- CVE-2026-160541 PoCDrag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle
- CVE-2026-160551 PoCContest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
- CVE-2026-160561 PoCContest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts
- CVE-2026-160571 PoCContest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
- CVE-2026-160581 PoCYayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration
- CVE-2026-160601 PoCInsert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload
- CVE-2026-160611 PoCRest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}
- CVE-2026-160621 PoCEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
- CVE-2026-160631 PoCEvent Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content
- CVE-2026-160641 PoCEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event
- CVE-2026-160651 PoCWelcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
- CVE-2026-160661 PoCWelcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name
- CVE-2026-160671 PoCEvent Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
- CVE-2026-160681 PoCBrizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
- CVE-2026-160691 PoCBrizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
- CVE-2026-160701 PoCBrizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
- CVE-2026-160731 PoCAstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting
- CVE-2026-160741 PoCAstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery
- CVE-2026-160751 PoCAstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
- CVE-2026-160761 PoCAstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
- CVE-2026-160771 PoCAstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
- CVE-2026-160811 PoCSipeed PicoClaw auth.go cross-site request forgery
- CVE-2026-160821 PoCSipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
- CVE-2026-160831 PoCSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
- CVE-2026-160841 PoCSipeed PicoClaw web.go web_fetch server-side request forgery
- CVE-2026-160851 PoCSipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere
- CVE-2026-160881 PoChalo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal
- CVE-2026-161191 PoCnextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
- CVE-2026-161201 PoCnextlevelbuilder GoClaw exec_approval.go extractBin name resolution
- CVE-2026-161211 PoCnextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization
- CVE-2026-161221 PoCnextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization
- CVE-2026-161231 PoCnextlevelbuilder GoClaw Invoke Endpoint tools_invoke.go ToolsInvokeHandler.ServeHTTP authorization
- CVE-2026-161241 PoCnextlevelbuilder GoClaw web_fetch web_shared.go isPrivateIP server-side request forgery
- CVE-2026-161251 PoCzevorn rt-claw http_request net.c claw_net_post server-side request forgery
- CVE-2026-161261 PoCzevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization
- CVE-2026-161271 PoCzevorn rt-claw http_request tool_net.c claw_net_post server-side request forgery
- CVE-2026-161281 PoCzevorn rt-claw http_request swarm.c receiver_thread server-side request forgery
- CVE-2026-161291 PoCprincezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist
- CVE-2026-161301 PoCnearai ironclaw write_file path_utils.rs validate_path link following
- CVE-2026-161311 PoCitsourcecode Hospital Management System prescriptionrecord.php sql injection
- CVE-2026-161331 PoCLiuMengxuan04 MiniCode mcp.ts child_process.spawn command injection
- CVE-2026-161521 PoCSourceCodester Class and Exam Timetabling System edit_rooma.php sql injection
- CVE-2026-161541 PoCSourceCodester Class and Exam Timetabling System edit_room1.php sql injection
- CVE-2026-161551 PoCSourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting
- CVE-2026-161561 PoCSourceCodester Class and Exam Timetabling System forexam.php cross site scripting
- CVE-2026-161941 PoCzhayujie CowAgent web_fetch.py WebFetch.execute server-side request forgery
- CVE-2026-161951 PoCSipeed PicoClaw Group Message wecom.go dispatchIncoming authorization
- CVE-2026-161961 PoCSipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP server-side request forgery
- CVE-2026-161971 PoCSipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization
- CVE-2026-161981 PoCSipeed PicoClaw First Run Setup access_control.go authentication bypass
- CVE-2026-161991 PoCnextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization
- CVE-2026-162001 PoCzevorn rt-claw RPC swarm.c claw_tool_invoke authorization
- CVE-2026-162011 PoCzevorn rt-claw http_request net.c claw_net_post information disclosure
- CVE-2026-162021 PoCSourceCodester Class and Exam Timetabling System CYS.php cross site scripting
- CVE-2026-162031 PoCSourceCodester Class and Exam Timetabling System forCYS.php cross site scripting
- CVE-2026-162041 PoCzevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
- CVE-2026-162051 PoCPluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
- CVE-2026-162091 PoCGerapy Project Upload Endpoint views.py missing authentication
- CVE-2026-162101 PoCnewpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication
- CVE-2026-162111 PoCallegro Hostname Allocation assets.py AssetLastHostname.increment_hostname race condition
- CVE-2026-162121 PoCawesto django-shop Purchase Stock inventory.py race condition
- CVE-2026-162141 PoCgeex-arts django-jet Dashboard views.py authorization
- CVE-2026-162151 PoCgeex-arts django-jet OAuth Credential Revoke authorization
- CVE-2026-162161 PoCgeex-arts django-jet OAuth cross-site request forgery
- CVE-2026-162171 PoCguohongze adminset Delivery Deployment Endpoint deli.py authorization
- CVE-2026-162191 PoCCroogo CMS Admin File Manager FileManager.php isEditable path traversal
- CVE-2026-162201 PoCcode-projects Online Examination System account.php cross site scripting
- CVE-2026-162221 PoC1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery
- CVE-2026-162231 PoC1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery
- CVE-2026-162251 PoCdavenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write
- CVE-2026-162271 PoCSourceCodester Class and Exam Timetabling System edit_subject.php sql injection
- CVE-2026-162281 PoCSourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
- CVE-2026-162291 PoCitsourcecode Courier Management System index.php cross site scripting
- CVE-2026-162324 PoCsKEVAuthentication Bypass in the SmartConsole Login Process Using an Application Token
- CVE-2026-162441 PoCitsourcecode Hospital Management System prescriptionorderreport.php sql injection
- CVE-2026-162481 PoCTenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow
- CVE-2026-162501 PoCPersonal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
- CVE-2026-162521 PoCBeijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection
- CVE-2026-162531 PoCTotal Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret
- CVE-2026-162561 PoCPouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
- CVE-2026-162571 PoCArvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling
- CVE-2026-162581 PoCAjax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
- CVE-2026-162591 PoCUix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
- CVE-2026-162601 PoCPost Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title Field
- CVE-2026-162611 PoCHuge IT Login <= 1.0.4 - Unauthenticated Account Takeover
- CVE-2026-162621 PoCEstatik < 4.3.3 - Login CSRF
- CVE-2026-162631 PoCWP Maps < 4.9.7 - Subscriber+ Local File Inclusion
- CVE-2026-162651 PoCWP Maps < 4.9.7 - Subscriber+ Denial of Service
- CVE-2026-162671 PoCNewsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
- CVE-2026-162682 PoCsNewsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler
- CVE-2026-162691 PoCNewsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
- CVE-2026-162731 PoCNarrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta
- CVE-2026-162741 PoCClassified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts
- CVE-2026-162761 PoCClassified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search
- CVE-2026-162821 PoCAppointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter
- CVE-2026-162851 PoCWooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download
- CVE-2026-162891 PoCProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
- CVE-2026-162901 PoCProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
- CVE-2026-162911 PoCProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
- CVE-2026-162921 PoCFrontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF
- CVE-2026-162931 PoCBlubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL
- CVE-2026-162941 PoCBlubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL
- CVE-2026-162951 PoCClearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher
- CVE-2026-162961 PoCClearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler
- CVE-2026-162971 PoCClearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import
- CVE-2026-162981 PoCFoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
- CVE-2026-162991 PoCSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
- CVE-2026-163001 PoCChama < 1.0.13 - Unauthenticated Arbitrary User Password Reset
- CVE-2026-163241 PoCMetasoft 美特软件 MetaCRM upload.jsp unrestricted upload
- CVE-2026-163271 PoCD-Link DNS-320 upload.php unrestricted upload
- CVE-2026-163291 PoCD-Link DNS-320 uploadify.php unrestricted upload
- CVE-2026-163301 PoCD-Link DNS-320 uploadify.php unrestricted upload
- CVE-2026-163311 PoCD-Link DNS-320 save_ajax.php unrestricted upload
- CVE-2026-163321 PoCD-Link DNS-320 multi_uploadify.php unrestricted upload
- CVE-2026-163341 PoCitsourcecode Hospital Management System prescriptionorder.php sql injection
- CVE-2026-163481 PoCCommand Injection Vulnerability in VPN connection of Archer BE800
- CVE-2026-164471 PoCD-Link DNS-320 multi_uploadify.php unrestricted upload
- CVE-2026-164481 PoCD-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
- CVE-2026-164491 PoCzsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
- CVE-2026-164501 PoCzsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
- CVE-2026-164511 PoCzsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload
- CVE-2026-164841 PoCSourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection
- CVE-2026-164851 PoCSourceCodester Class and Exam Timetabling System class.php cross site scripting
- CVE-2026-164861 PoCSourceCodester Class and Exam Timetabling System BSIS.php cross site scripting
- CVE-2026-164881 PoCQUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection
- CVE-2026-164891 PoCjsforce SFDX Connection Registry sfdx.js _execCommand os command injection
- CVE-2026-164901 PoCitsourcecode Hospital Management System prescription.php sql injection
- CVE-2026-164921 PoCumijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
- CVE-2026-164941 PoCMissing Authorization in GitLab
- CVE-2026-165321 PoCLink Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form
- CVE-2026-165341 PoCImport and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
- CVE-2026-165351 PoCLink Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
- CVE-2026-165361 PoCSimple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id
- CVE-2026-165371 PoCSlick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
- CVE-2026-165381 PoCTeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up
- CVE-2026-165391 PoCSM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
- CVE-2026-165402 PoCsSimply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
- CVE-2026-165411 PoCSimply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
- CVE-2026-165461 PoCWired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
- CVE-2026-165471 PoCREST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
- CVE-2026-165481 PoCBit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
- CVE-2026-165581 PoCYMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
- CVE-2026-165591 PoCYMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
- CVE-2026-165611 PoCSunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
- CVE-2026-165621 PoCWP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
- CVE-2026-165631 PoCAcademy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
- CVE-2026-165641 PoCDokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
- CVE-2026-165651 PoCDokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
- CVE-2026-165671 PoCDocument Embedder < 2.3.1 - Unauthenticated Private Document Download via Token Oracle
- CVE-2026-165681 PoCShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR
- CVE-2026-165691 PoCShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update
- CVE-2026-165701 PoCNextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback
- CVE-2026-165721 PoCLogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
- CVE-2026-165731 PoCBit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
- CVE-2026-165741 PoCDokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
- CVE-2026-165751 PoCDokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint
- CVE-2026-165761 PoCDokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API
- CVE-2026-165771 PoCDokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount
- CVE-2026-165781 PoCAdmin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
- CVE-2026-165831 PoCOrbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
- CVE-2026-165891 PoCWP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
- CVE-2026-165901 PoCWP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
- CVE-2026-165941 PoCWP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
- CVE-2026-165951 PoCWP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
- CVE-2026-166001 PoCSmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_image
- CVE-2026-166021 PoCContent Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint
- CVE-2026-166031 PoCContent Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
- CVE-2026-166041 PoCContent Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute
- CVE-2026-166051 PoCMultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization
- CVE-2026-166081 PoCDownload Monitor < 5.2.6 - Unauthenticated Download Log Injection
- CVE-2026-166111 PoCProduct Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
- CVE-2026-166121 PoCFiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information Disclosure
- CVE-2026-166131 PoCGDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
- CVE-2026-166161 PoCSimple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal
- CVE-2026-166171 PoCSimple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
- CVE-2026-166181 PoCImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution
- CVE-2026-166191 PoCminiOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
- CVE-2026-166201 PoCWPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
- CVE-2026-166211 PoCPayment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler
- CVE-2026-166231 PoCCreate Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)
- CVE-2026-166271 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-166281 PoCoclif JIT Plugin Entry child_process.exec os command injection
- CVE-2026-166301 PoCsyncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
- CVE-2026-166311 PoCpublint package-manager pack.js child_process.exec os command injection
- CVE-2026-166321 PoCboazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation
- CVE-2026-166501 PoCCharitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass
- CVE-2026-166531 PoCboazsegev facil.io Public Folder http.c http_sendfile2 path traversal
- CVE-2026-166541 PoCAvada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute
- CVE-2026-167237 PoCsRemote Code Execution in fastjson 1.2.68–1.2.83
- CVE-2026-167321 PoCfastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
- CVE-2026-167331 PoCbahmutov find-cypress-specs Branch index.js shell.exec os command injection
- CVE-2026-167341 PoCStripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation
- CVE-2026-167351 PoCrelease-it conventional-changelog Changelog File index.js writeChangelog os command injection
- CVE-2026-167361 PoCUser Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
- CVE-2026-167371 PoCWP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart
- CVE-2026-167381 PoCConekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion via Webhook Forgery
- CVE-2026-167391 PoCEpeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery
- CVE-2026-167461 PoCMultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint
- CVE-2026-167471 PoCKirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
- CVE-2026-167631 PoClocalstack serverless-localstack Configuration index.js os command injection
- CVE-2026-167651 PoCCodeAstro Online Classroom loginlinkadmin.php sql injection
- CVE-2026-167671 PoCNe-Lexa php-zip ZIP ZipFile.php extractTo path traversal
- CVE-2026-169401 PoCCustom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
- CVE-2026-169421 PoCWP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
- CVE-2026-169471 PoCTotal Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure
- CVE-2026-169481 PoCSolace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
- CVE-2026-169491 PoCTerm Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
- CVE-2026-169501 PoCProduct Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products
- CVE-2026-169531 PoCAI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
- CVE-2026-169541 PoCAI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens
- CVE-2026-169551 PoCAI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
- CVE-2026-169571 PoCSlim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure
- CVE-2026-169591 PoCMedia Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
- CVE-2026-169621 PoCTamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation
- CVE-2026-169651 PoCSolace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status
- CVE-2026-169661 PoCSolace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Disclosure via get_elementor_content
- CVE-2026-169681 PoCGeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
- CVE-2026-169771 PoCForm Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
- CVE-2026-169791 PoCSmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
- CVE-2026-169811 PoCDHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
- CVE-2026-169831 PoCGutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST API
- CVE-2026-169841 PoCWP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure
- CVE-2026-169851 PoCSqueeze < 1.7.12 - Author+ Arbitrary File Upload
- CVE-2026-169861 PoCBooking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters
- CVE-2026-169881 PoCGeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint
- CVE-2026-169901 PoCPayment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
- CVE-2026-169921 PoCCreate by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
- CVE-2026-169931 PoCDHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory