Vulnerability Notes
- CVE-2024-13784 - Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection
- CVE-2026-18316 - Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action
- CVE-2026-17123 - Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting
- CVE-2026-16098 - ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override
- CVE-2026-14498 - Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter
- CVE-2026-19924 - Tenda AC10 httpd R7WebsSecurityHandler improper authentication
- CVE-2026-73052 - SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names
- CVE-2026-73042 - SiYuan before v3.7.4 Remote Code Execution via Menu Metadata
- CVE-2026-73041 - SiYuan before v3.7.4 Remote Code Execution via PDF Annotations
- CVE-2026-18855 - Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter
- CVE-2026-19901 - LB-LINK X-PRO easycwmp hard-coded credentials
- CVE-2026-19598 - Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
- CVE-2026-19900 - LB-LINK X-PRO shadow hard-coded credentials
- CVE-2026-18500 - @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key
- CVE-2026-18438 - Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch