CVE-2026-17000 to CVE-2026-17999
46 CVEs with public proof-of-concept exploits.
- CVE-2026-170081 PoCQuick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN
- CVE-2026-170101 PoCSaitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
- CVE-2026-170111 PoCNexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection
- CVE-2026-170121 PoCRestore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
- CVE-2026-170131 PoCWP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart
- CVE-2026-170141 PoCWP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips
- CVE-2026-170161 PoCRestore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
- CVE-2026-170171 PoCCubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation
- CVE-2026-170181 PoCCubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
- CVE-2026-170191 PoCJetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)
- CVE-2026-170201 PoCSalon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure
- CVE-2026-170211 PoCSalon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering
- CVE-2026-170221 PoCSalon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
- CVE-2026-170231 PoCSalon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback
- CVE-2026-170321 PoCSupsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
- CVE-2026-170441 PoCWordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
- CVE-2026-171062 PoCsTar extraction in moby/go-archive can write outside the destination directory via link following
- CVE-2026-173491 PoCpgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner
- CVE-2026-173512 PoCspgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
- CVE-2026-174321 PoCNousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
- CVE-2026-174331 PoCnanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
- CVE-2026-174341 PoCnanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
- CVE-2026-174571 PoCmf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
- CVE-2026-174581 PoCmf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery
- CVE-2026-174591 PoCperwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
- CVE-2026-175051 PoCTranslatePress <= 3.2.5 - Reflected Cross-Site Scripting
- CVE-2026-175141 PoCZJONSSON node-unzipper extract.js Extract path traversal
- CVE-2026-175151 PoCMLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
- CVE-2026-175201 PoCNewsletters < 4.17 - Unauthenticated API Access via Predictable API Key
- CVE-2026-175221 PoCNewsletters < 4.17 - Arbitrary Plugin Option Update via CSRF
- CVE-2026-175291 PoCAstrBotDevs AstrBot astr_main_agent.py authorization
- CVE-2026-175301 PoCAstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
- CVE-2026-175311 PoCunitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
- CVE-2026-175322 PoCsSeraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
- CVE-2026-175331 PoCAll-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
- CVE-2026-175401 PoCBit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch
- CVE-2026-175411 PoCBit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
- CVE-2026-175421 PoCBit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector
- CVE-2026-175431 PoCSQL injection in ext-pgsql via E'...' backslash breakout
- CVE-2026-175442 PoCsOut-of-bounds write in bccomp() via crafted operand and scale
- CVE-2026-175591 PoCContent Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass
- CVE-2026-175631 PoCWP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form
- CVE-2026-175651 PoCAnimation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery
- CVE-2026-175661 PoCpgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
- CVE-2026-175831 PoCThermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
- CVE-2026-175941 PoCNexus Repository 3 - Authorization Bypass in Repository Creation