CVE-2026-81000 to CVE-2026-81999
45 CVEs with public proof-of-concept exploits.
- CVE-2026-810261 PoCMasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN
- CVE-2026-811941 PoCMasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter
- CVE-2026-811951 PoCMasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route
- CVE-2026-811961 PoCMasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR
- CVE-2026-811971 PoCMasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route
- CVE-2026-811981 PoCMasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR
- CVE-2026-811991 PoCMasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route
- CVE-2026-812001 PoCMasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR
- CVE-2026-812021 PoCitsourcecode Payroll System CRUD Operation ajax.php delete missing authentication
- CVE-2026-812031 PoCSourceCodester Simple Online Food Ordering System ajax.php login2 sql injection
- CVE-2026-813421 PoCMasterStudy LMS < 3.7.43 - Unauthenticated Open Redirect
- CVE-2026-813461 PoCFrontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion
- CVE-2026-814211 PoCddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery
- CVE-2026-814261 PoCWC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF
- CVE-2026-814271 PoCWC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change
- CVE-2026-814281 PoCWC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modification via IDOR
- CVE-2026-814321 PoCJetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF
- CVE-2026-814851 PoCdanielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path traversal
- CVE-2026-814861 PoCbsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal
- CVE-2026-814911 PoCboxpositron with-context-mcp index.ts project_folder path traversal
- CVE-2026-815601 PoCblackms aistack Static File server.ts path traversal
- CVE-2026-815621 PoCAlexGladkov claude-in-mobile client.ts execSync os command injection
- CVE-2026-815711 PoCBrave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution via UTM Parameter
- CVE-2026-815781 PoCKEVPaperCut MF/NG: Authentication Bypass
- CVE-2026-815831 PoCTheme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation
- CVE-2026-816601 PoCGroundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field
- CVE-2026-817221 PoCnltk PorterStemmer before 3.10.3 Quadratic-time DoS
- CVE-2026-817231 PoCNLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView
- CVE-2026-817241 PoCNLTK before 3.10.3 Denial of Service via Uncontrolled Recursion
- CVE-2026-817261 PoCNLTK through 3.10.3 Path Traversal via Model-Artifact APIs
- CVE-2026-817271 PoCNLTK before 3.10.3 Hardlink File Overwrite via downloader
- CVE-2026-817371 PoCFAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_information
- CVE-2026-817661 PoCReally Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin
- CVE-2026-818071 PoCSimple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification
- CVE-2026-818331 PoCRooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection
- CVE-2026-818341 PoCRooCodeInc Roo-Code README File ExecaTerminalProcess code injection
- CVE-2026-818351 PoCRooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection
- CVE-2026-818361 PoCRooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
- CVE-2026-818371 PoCRooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal
- CVE-2026-818451 PoCarben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal
- CVE-2026-818471 PoCMAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal
- CVE-2026-818891 PoCelFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
- CVE-2026-818901 PoCelFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
- CVE-2026-818911 PoCelFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
- CVE-2026-819341 PoCRedis TLS pending-data list use-after-free