OpenClaw is a personal AI assistant
Description
OpenClaw is a personal AI assistant
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 20297 vulnerabilities with AI analyst insights
OpenClaw is a personal AI assistant
OpenClaw is a personal AI assistant
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw is a personal AI assistant
OpenClaw is a personal AI assistant
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw is a personal AI assistant
OpenClaw is a personal AI assistant
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw is a personal AI assistant
OpenClaw is a personal AI assistant
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw is a personal AI assistant
OpenClaw is a personal AI assistant
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
systeminformation is a System and OS information library for node
systeminformation is a System and OS information library for node
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw is a personal AI assistant
OpenClaw is a personal AI assistant
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The Datalogics Ecommerce Delivery plugin for WordPress before 2.6.60 contains an unauthenticated REST endpoint vulnerability allowing remote attackers...
The Datalogics Ecommerce Delivery plugin for WordPress before 2.6.60 contains an unauthenticated REST endpoint vulnerability allowing remote attackers to modify site options and gain admin access.
Update WordPress plugin before to the latest version. Monitor for exploitation attempts and review access logs.
The installer for OM Workspace (Windows Edition) Ver 2
The installer for OM Workspace (Windows Edition) Ver 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable S...
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Gitea versions before 1.25.5 fail to use the migration HTTP transport for LFS operations, bypassing configured security protections for push and sync...
Gitea versions before 1.25.5 fail to use the migration HTTP transport for LFS operations, bypassing configured security protections for push and sync mirror requests.
---METADATA---
VENDOR: Gitea
PRODUCT: Gitea Open Source Git Server
AFFECTED_VERSIONS: 0 up to (excluding) 1.25.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Gitea versions before 1.25.5 fail to use the migration HTTP transport for LFS operations, bypassing configured security protections for push and sync mirror requests.
Executive Summary:
A critical security gap in Gitea Open Source Git Server allows attackers to bypass LFS transport protections, potentially leading to the interception or manipulation of sensitive data.
Vulnerability Details
CVE-ID: CVE-2026-26292
Affected Software: Gitea Gitea Open Source Git Server
Affected Versions: 0 up to (excluding) 1.25.5
Vulnerability: The application fails to utilize the migration HTTP transport for LFS (Large File Storage) push and sync mirror operations. This bypasses established security protections, allowing unauthenticated attackers to potentially intercept or manipulate LFS data transfers through unencrypted channels or weak authentication mechanisms.
Business Impact
This vulnerability carries a CVSS score of 9.8, reflecting the ability of an attacker to compromise both data integrity and confidentiality. By manipulating LFS data, an attacker could inject malicious files into repositories or exfiltrate sensitive large assets, leading to severe downstream impacts on software supply chains and organizational data security.
Remediation Plan
Immediate Action: Upgrade to Gitea version 1.25.5 or later to ensure that all LFS operations are correctly routed through the secure migration HTTP transport.
Proactive Monitoring: Review network traffic and server logs for anomalous LFS synchronization activity or unexpected outbound connections from the Git server.
Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect LFS-related HTTP traffic for signs of manipulation until the patch can be fully applied.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
This vulnerability presents a significant risk to the integrity of repository assets. Organizations must prioritize the upgrade to version 1.25.5 to close the transport security gap and protect LFS data from unauthorized interception or tampering.
Update Gitea Gitea Open Source Git Server to the latest version. Monitor for exploitation attempts and review access logs.
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sessi...
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7
A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information n...
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only
---METADATA---
VENDOR: Subnet Solutions
PRODUCT: PowerSYSTEM Center
AFFECTED_VERSIONS: 2020: 5.8.x-5.28.x; 2024: 6.0.x-6.1.x; 2026: 7.0.x
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An authorization bypass in the PowerSYSTEM Center REST API allows authenticated users with limited permissions to export sensitive device account information restricted to administrators.
Executive Summary:
An authenticated authorization bypass in Subnet Solutions PowerSYSTEM Center allows low-privileged users to access sensitive administrative data.
Vulnerability Details
CVE-ID: CVE-2026-26289
Affected Software: Subnet Solutions PowerSYSTEM Center
Affected Versions: See metadata for specific version ranges.
Vulnerability: This vulnerability involves incorrect authorization checks within the device account export REST API endpoint. It requires an authenticated user with limited permissions to successfully execute the attack.
Business Impact
Successful exploitation allows unauthorized access to sensitive device account information, which could be leveraged to escalate privileges or gain deeper insights into the industrial control system network. With a CVSS score of 8.2, the impact on confidentiality and integrity is substantial, particularly in critical infrastructure environments.
Remediation Plan
Immediate Action: Update PowerSYSTEM Center to the latest versions: PSC 2020 Update 29, PSC 2024 Update 2, or the PSC 2026 GA Hotfix.
Proactive Monitoring: Review user activity logs and audit trails to identify anomalous data export requests originating from low-privileged accounts.
Compensating Controls: Restrict access to the REST API to authorized management segments and ensure strong identity and access management (IAM) policies are enforced.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of May 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw requires prior authentication, which inherently limits the attack surface compared to unauthenticated vulnerabilities.
Analyst Recommendation
Organizations utilizing PowerSYSTEM Center must apply the provided updates to remediate the authorization flaw. Given the potential for sensitive information exposure, immediate patching and a review of user permission levels are strongly advised.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A lack of authentication in WebSocket endpoints allows unauthenticated attackers to impersonate charging stations, manipulate data, and issue unauthor...
A lack of authentication in WebSocket endpoints allows unauthenticated attackers to impersonate charging stations, manipulate data, and issue unauthorized commands via the OCPP protocol.
---METADATA---
VENDOR: Unknown
PRODUCT: OCPP Charging Infrastructure
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A lack of authentication in WebSocket endpoints allows unauthenticated attackers to impersonate charging stations, manipulate data, and issue unauthorized commands via the OCPP protocol.
Executive Summary:
Missing authentication in OCPP WebSocket endpoints enables unauthenticated attackers to impersonate charging stations, leading to unauthorized infrastructure control and data corruption.
Vulnerability Details
CVE-ID: CVE-2026-26288
Affected Software: OCPP-based Charging Management Systems
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability involves a total lack of authentication on WebSocket endpoints used for the Open Charge Point Protocol (OCPP). An unauthenticated attacker can establish a connection using a valid station ID, allowing them to intercept or inject charging commands and manipulate the backend's view of the network status.
Business Impact
The impact is critical, as evidenced by the CVSS score of 9.4, involving potential privilege escalation and unauthorized control over EV charging hardware. Successful exploitation could lead to revenue loss, incorrect billing, and significant reputational damage if the charging network is compromised or rendered inoperable.
Remediation Plan
Immediate Action: Apply the latest security updates provided by the vendor to enforce authentication on all WebSocket communication channels.
Proactive Monitoring: Implement logging for all WebSocket connection attempts and set up alerts for any connection requests that do not provide valid, pre-shared credentials.
Compensating Controls: Utilize a Web Application Firewall (WAF) capable of inspecting WebSocket traffic or place the management backend behind a secure gateway that requires mutual TLS (mTLS) for all station connections.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 6, 2026, there is no public information indicating active exploitation of this vulnerability. The technical simplicity of exploiting unauthenticated endpoints suggests that scanning for vulnerable instances may begin shortly.
Analyst Recommendation
Immediate action is required to secure the charging infrastructure. Security teams should verify that all endpoints require robust authentication and that no "default" or "test" endpoints remain exposed to the public internet.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,...
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
systeminformation is a System and OS information library for node
systeminformation is a System and OS information library for node
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The All-in-One Microsoft 365 SSO Login plugin for WordPress allows unauthenticated attackers to bypass authentication and gain full administrative acc...
The All-in-One Microsoft 365 SSO Login plugin for WordPress allows unauthenticated attackers to bypass authentication and gain full administrative access due to an insecure login implementation.
---METADATA---
VENDOR: miniOrange
PRODUCT: All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login (WordPress Plugin)
AFFECTED_VERSIONS: Up to, and including, 2.2.5
---END_METADATA---
Description Summary:
The All-in-One Microsoft 365 SSO Login plugin for WordPress allows unauthenticated attackers to bypass authentication and gain full administrative access due to an insecure login implementation.
Executive Summary:
An unauthenticated authentication bypass vulnerability in the miniOrange Microsoft 365 SSO plugin for WordPress allows remote attackers to gain full administrative control over affected websites.
Vulnerability Details
CVE-ID: CVE-2026-2628
Affected Software: miniOrange All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login
Affected Versions: Up to, and including, 2.2.5
Vulnerability: This vulnerability constitutes a critical authentication bypass. It allows unauthenticated remote attackers to spoof identities and log in as any existing user, including site administrators, without requiring a password or valid SSO token.
Business Impact
A successful exploit grants the attacker total control over the WordPress environment, leading to complete data exfiltration, site defacement, or the installation of persistent backdoors. Given the CVSS score of 9.8, this represents a critical risk to confidentiality, integrity, and availability, potentially resulting in significant reputational damage and loss of sensitive customer data.
Remediation Plan
Immediate Action: Update the All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin to the latest version (at least 2.2.6) immediately to close the authentication gap.
Proactive Monitoring: Review WordPress audit logs for unexpected administrative logins or the creation of new, unauthorized administrator accounts originating from unknown IP addresses.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules designed to block unauthorized access to wp-login.php and monitor for suspicious SSO callback patterns.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Mar 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, because the flaw allows for unauthenticated administrative access, the potential for exploitation is extremely high once technical details are reverse-engineered.
Analyst Recommendation
This vulnerability is critical and should be treated as a top priority for remediation. Organizations using this plugin for SSO must apply the vendor-provided update immediately to prevent unauthorized administrative access and potential site takeover.
Update Microsoft Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
A typo in Froxlor's input validation enables an authenticated administrator to achieve root-level remote code execution via shell command injection.
A typo in Froxlor's input validation enables an authenticated administrator to achieve root-level remote code execution via shell command injection.
---METADATA---
VENDOR: Froxlor
PRODUCT: Froxlor
AFFECTED_VERSIONS: Prior to 2.3.4
---END_METADATA---
Description Summary:
A typo in Froxlor's input validation enables an authenticated administrator to achieve root-level remote code execution via shell command injection.
Executive Summary:
A critical input validation failure in Froxlor allows an authenticated administrator to gain full root-level control of the server through malicious shell command injection.
Vulnerability Details
CVE-ID: CVE-2026-26279
Affected Software: Froxlor
Affected Versions: Prior to 2.3.4
Vulnerability: A logic error (using "==" instead of "=") disables email format checking in settings fields. An authenticated administrator can inject arbitrary strings into the panel.adminmail setting, which is subsequently executed as root by a system cron job using a shell command.
Business Impact
With a CVSS score of 9.1, this vulnerability poses a severe risk to server infrastructure. A compromised administrator account can be leveraged to gain total control over the underlying operating system. This could lead to data destruction, lateral movement within the network, and complete service disruption.
Remediation Plan
Immediate Action: Update Froxlor to version 2.3.4 immediately to correct the validation logic and prevent command injection.
Proactive Monitoring: Review the panel.adminmail setting for suspicious characters (such as pipes or semicolons) and inspect cron job logs for unauthorized command execution.
Compensating Controls: Implement the principle of least privilege for administrative accounts and use file integrity monitoring on critical system configuration files.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Mar 3, 2026, there is no public information indicating active exploitation. However, the simplicity of the typo makes this vulnerability trivial to exploit for any user with administrative panel access.
Analyst Recommendation
While this requires administrative authentication, the resulting root-level access makes it a critical priority. Organizations must update to version 2.3.4 immediately to secure their server management infrastructure.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
httpsig-hyper is a hyper extension for http message signatures
httpsig-hyper is a hyper extension for http message signatures
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A broken authentication vulnerability in Known allows unauthenticated attackers to retrieve password reset tokens from hidden HTML fields, enabling fu...
A broken authentication vulnerability in Known allows unauthenticated attackers to retrieve password reset tokens from hidden HTML fields, enabling full account takeover of any user.
---METADATA---
VENDOR: Known
PRODUCT: Known (Social Publishing Platform)
AFFECTED_VERSIONS: 1.6.2 and earlier
---END_METADATA---
Description Summary:
A broken authentication vulnerability in Known allows unauthenticated attackers to retrieve password reset tokens from hidden HTML fields, enabling full account takeover of any user.
Executive Summary:
Known social publishing platform is vulnerable to full account takeover because password reset tokens are leaked to unauthenticated attackers via the password reset page.
Vulnerability Details
CVE-ID: CVE-2026-26273
Affected Software: Known
Affected Versions: 1.6.2 and earlier
Vulnerability: The application incorrectly includes the password reset token within a hidden HTML input field on the reset request page. This allows any unauthenticated attacker to capture the token by querying a target's email address, bypassing the need for email inbox access.
Business Impact
This vulnerability poses a critical risk to user privacy and platform integrity, as it facilitates unauthorized access to any account, including administrative profiles. Such an exploit could lead to complete site defacement, data theft, and loss of user trust. The CVSS score of 9.8 underscores the ease of exploitation and the severe impact on account security.
Remediation Plan
Immediate Action: Update the Known installation to version 1.6.3 or later immediately to ensure password reset tokens are no longer exposed in the browser.
Proactive Monitoring: Monitor web server logs for a high volume of requests to the password reset endpoint, which may indicate an attacker attempting to harvest tokens for multiple users.
Compensating Controls: Implement rate limiting on password reset requests and consider disabling the reset feature temporarily if an immediate update is not feasible.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Feb 13, 2026, there is no public information indicating active exploitation of this vulnerability. However, because the flaw is trivially exploitable via standard browser tools, the risk of rapid adoption by threat actors is significant.
Analyst Recommendation
The ability to take over any user account without authentication represents a terminal risk to the platform. Administrators must treat this as a high-priority emergency and apply the 1.6.3 patch immediately to protect the user base from unauthorized account access.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in Softland FBackup up to 9
A security flaw has been discovered in Softland FBackup up to 9
---METADATA---
VENDOR: Softland
PRODUCT: FBackup
AFFECTED_VERSIONS: Up to version 9
---END_METADATA---
Description Summary:
A security flaw has been identified in Softland FBackup up to version 9 that could allow for unauthorized access or data manipulation.
Executive Summary:
Softland FBackup versions up to 9 contain a high-severity security flaw that threatens the integrity and confidentiality of backup data.
Vulnerability Details
CVE-ID: CVE-2026-2627
Affected Software: Softland FBackup
Affected Versions: Up to version 9
Vulnerability: While specific technical details are limited, the flaw in FBackup versions up to 9 suggests a vulnerability that could be exploited to compromise the backup software's operations. Based on the "High" severity, it likely involves unauthorized access or local privilege escalation.
Business Impact
The compromise of backup software is a critical risk, as it can lead to the loss of data recovery capabilities or the exposure of sensitive archived information. The CVSS score of 7.8 indicates a significant risk to the business's disaster recovery posture and data privacy.
Remediation Plan
Immediate Action: Apply the latest security updates from Softland immediately to move beyond version 9 and resolve the identified flaw.
Proactive Monitoring: Monitor for unusual file access patterns within the FBackup directories and review logs for unauthorized backup job modifications.
Compensating Controls: Ensure that backup repositories are encrypted and restricted to only the necessary service accounts to limit the impact of a software compromise.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 18, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Backup systems are a primary target for attackers, particularly in ransomware scenarios. Administrators should treat this high-severity update as a priority to ensure the continued security and reliability of their data protection strategy.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Cursor is a code editor built for programming with AI
Cursor is a code editor built for programming with AI
---METADATA---
VENDOR: Anysphere
PRODUCT: Cursor
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The Cursor AI-powered code editor is affected by a high-severity vulnerability that could impact the security of the developer's environment and source code.
Executive Summary:
Cursor, a popular AI-integrated code editor, contains a high-severity vulnerability that poses a risk to developer workstation security and the integrity of source code repositories.
Vulnerability Details
CVE-ID: CVE-2026-26268
Affected Software: Anysphere Cursor
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability affects the Cursor code editor. While the specific vulnerability type is not disclosed, a CVSS score of 8.0 suggests a High severity flaw that could potentially allow for remote code execution or unauthorized access to the local file system through the editor's AI or extension capabilities.
Business Impact
A vulnerability in a code editor can lead to the compromise of a developer's entire workstation. This provides a pathway for attackers to steal source code, inject malicious code into software products (Supply Chain Attack), or steal sensitive environment variables and SSH keys. The CVSS score of 8.0 underscores the significant risk to the software development lifecycle.
Remediation Plan
Immediate Action: Developers should update the Cursor editor to the latest version immediately via the in-app update mechanism or the official website.
Proactive Monitoring: Review repository commit history for unauthorized changes and monitor developer workstations for unusual process activity or unauthorized file access.
Compensating Controls: Use endpoint detection and response (EDR) solutions to monitor for suspicious behavior originating from development tools and enforce the use of signed commits.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 14, 2026, there is no public information indicating active exploitation of this vulnerability. However, vulnerabilities in modern IDEs are increasingly exploited to facilitate supply chain compromises.
Analyst Recommendation
We recommend that all organizations using Cursor for development mandate an immediate update across all engineering teams. The potential for a workstation compromise to escalate into a full-scale supply chain attack makes this a critical priority for security administrators. Focus on ensuring the integrity of the development environment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
soroban-sdk is a Rust SDK for Soroban contracts
soroban-sdk is a Rust SDK for Soroban contracts
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A stored cross-site scripting (XSS) vulnerability in AliasVault Web Client allows attackers to execute malicious JavaScript in the victim's browser vi...
A stored cross-site scripting (XSS) vulnerability in AliasVault Web Client allows attackers to execute malicious JavaScript in the victim's browser via crafted emails.
---METADATA---
VENDOR: AliasVault
PRODUCT: AliasVault Web Client
AFFECTED_VERSIONS: 0.25.3 and lower
---END_METADATA---
Description Summary:
A stored cross-site scripting (XSS) vulnerability in AliasVault Web Client allows attackers to execute malicious JavaScript in the victim's browser via crafted emails.
Executive Summary:
AliasVault Web Client is vulnerable to a critical stored cross-site scripting attack that enables unauthenticated attackers to execute malicious code in the context of a user's session.
Vulnerability Details
CVE-ID: CVE-2026-26266
Affected Software: AliasVault Web Client
Affected Versions: 0.25.3 and lower
Vulnerability: The email rendering feature fails to properly sanitize HTML content or provide origin isolation when using the srcdoc attribute in iframes. An unauthenticated attacker can send a crafted email containing malicious JavaScript that executes when viewed by the victim.
Business Impact
This vulnerability carries a CVSS score of 9.3, signifying High/Critical severity. Successful exploitation allows for session hijacking, theft of sensitive password manager data, and unauthorized actions performed on behalf of the user. Because AliasVault is a privacy-focused tool, this flaw directly undermines the core security promise of the product.
Remediation Plan
Immediate Action: Administrators and users must upgrade the AliasVault Web Client to version 0.26.0 or higher immediately.
Proactive Monitoring: Monitor web application logs for suspicious script injection patterns or unusual client-side behavior reported by users.
Compensating Controls: Employ a Content Security Policy (CSP) to restrict the execution of unauthorized inline scripts and external resources within the web client.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Mar 3, 2026, there is no public information indicating active exploitation of this vulnerability. The lack of sanitization makes this a highly reliable attack vector for targeting password manager users.
Analyst Recommendation
The ability to execute arbitrary scripts within a password management interface is a catastrophic security failure. Immediate migration to version 0.26.0 is mandatory to protect user credentials and maintain organizational privacy.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Discourse is an open source discussion platform
Discourse is an open source discussion platform
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
GLPI is a free asset and IT management software package
GLPI is a free asset and IT management software package
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The divi-booster WordPress plugin before 5
The divi-booster WordPress plugin before 5
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
Gitea versions before 1.25.5 fail to correctly persist OAuth2 PKCE S256 challenges, allowing token exchange to proceed without mandatory verifier vali...
Gitea versions before 1.25.5 fail to correctly persist OAuth2 PKCE S256 challenges, allowing token exchange to proceed without mandatory verifier validation.
---METADATA---
VENDOR: Gitea
PRODUCT: Gitea Open Source Git Server
AFFECTED_VERSIONS: 0 up to (excluding) 1.25.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Gitea versions before 1.25.5 fail to correctly persist OAuth2 PKCE S256 challenges, allowing token exchange to proceed without mandatory verifier validation.
Executive Summary:
A critical security flaw in Gitea Open Source Git Server allows attackers to bypass OAuth2 PKCE verifier checks, weakening the integrity of the authentication process.
Vulnerability Details
CVE-ID: CVE-2026-26247
Affected Software: Gitea Gitea Open Source Git Server
Affected Versions: 0 up to (excluding) 1.25.5
Vulnerability: The application fails to correctly persist the PKCE (Proof Key for Code Exchange) S256 challenge method during the authorization flow. This allows an unauthenticated attacker to complete the token exchange process without the required cryptographic verification, undermining the OAuth2 security model.
Business Impact
By bypassing PKCE verifiers, attackers can potentially intercept or spoof authorization flows, leading to unauthorized access to user accounts and repository resources. The CVSS score of 9.1 highlights the critical nature of this flaw, as it allows an attacker to subvert core authentication protections, risking the confidentiality and integrity of hosted development environments.
Remediation Plan
Immediate Action: Apply the vendor-provided patch by upgrading Gitea to version 1.25.5 or later immediately.
Proactive Monitoring: Monitor access logs for unusual OAuth2 token exchange requests that do not follow standard flow patterns.
Compensating Controls: Ensure that TLS is strictly enforced for all OAuth2 callback endpoints to minimize the window for interception while the upgrade is being deployed.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the potential for unauthorized access, administrators must treat this as a high-priority update. Upgrading to version 1.25.5 is the only effective way to restore the integrity of the OAuth2 authentication process and prevent potential account compromise.
Update Gitea Gitea Open Source Git Server to the latest version. Monitor for exploitation attempts and review access logs.
A buffer overflow vulnerability has been reported to affect File Station 5
A buffer overflow vulnerability has been reported to affect File Station 5
---METADATA---
VENDOR: QNAP Systems Inc.
PRODUCT: File Station 5
AFFECTED_VERSIONS: File Station 5 version 5.5.0
---END_METADATA---
Description Summary:
A buffer overflow vulnerability in QNAP File Station 5 allows authenticated remote attackers to modify memory or crash system processes.
Executive Summary:
A buffer overflow vulnerability in QNAP File Station 5 could allow an authenticated attacker to compromise system stability or manipulate memory.
Vulnerability Details
CVE-ID: CVE-2026-26239
Affected Software: QNAP Systems Inc. File Station 5
Affected Versions: File Station 5 version 5.5.0
Vulnerability: This is a buffer overflow vulnerability triggered within the File Station 5 application. It requires an attacker to possess a valid user account to successfully exploit the flaw, which can lead to unauthorized memory modification or process termination.
Business Impact
The CVSS score of 8.1 (High) reflects the potential for significant disruption to QNAP storage services. Successful exploitation allows an attacker to cause a denial-of-service condition or potentially execute arbitrary code, which could lead to unauthorized access to sensitive files stored on the NAS, resulting in data loss or reputational damage.
Remediation Plan
Immediate Action: Update File Station 5 to version 5.5.6.5208 or later as specified in the vendor advisory.
Proactive Monitoring: Review system access logs for unusual account activity or repeated process crashes that may indicate exploitation attempts.
Compensating Controls: Restrict network access to the QNAP management interface to trusted IP ranges and ensure that user privileges are strictly managed according to the principle of least privilege.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 14, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the severity of this memory-based vulnerability, administrators should prioritize updating to the patched version immediately. Ensuring that only authorized users have access to File Station services is critical to preventing exploitation of this flaw.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
JUNG Smart Visu Server 1
JUNG Smart Visu Server 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Gitea versions before 1.25.5 fail to properly enforce OAuth2 authorization code expiry and single-use requirements, allowing attackers to replay codes...
Gitea versions before 1.25.5 fail to properly enforce OAuth2 authorization code expiry and single-use requirements, allowing attackers to replay codes to bypass authentication.
---METADATA---
VENDOR: Gitea
PRODUCT: Gitea Open Source Git Server
AFFECTED_VERSIONS: 0 up to (excluding) 1.25.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Gitea versions before 1.25.5 fail to properly enforce OAuth2 authorization code expiry and single-use requirements, allowing attackers to replay codes to bypass authentication.
Executive Summary:
A critical authentication bypass vulnerability in Gitea Open Source Git Server allows unauthenticated attackers to hijack sessions by replaying captured OAuth2 authorization codes.
Vulnerability Details
CVE-ID: CVE-2026-26232
Affected Software: Gitea Gitea Open Source Git Server
Affected Versions: 0 up to (excluding) 1.25.5
Vulnerability: This vulnerability involves improper enforcement of OAuth2 authorization state, where captured codes are not invalidated after use. An unauthenticated attacker can exploit this flaw to perform a replay attack, effectively bypassing authentication mechanisms.
Business Impact
Successful exploitation of this vulnerability allows unauthorized access to the Git server, potentially exposing sensitive source code, intellectual property, and internal project data. With a CVSS score of 9.1, this represents a critical risk to business operations, as it permits full account takeover without requiring valid credentials.
Remediation Plan
Immediate Action: Upgrade all Gitea instances to version 1.25.5 or later, as this release contains the necessary security logic to enforce single-use OAuth2 codes.
Proactive Monitoring: Review authentication and OAuth2 callback logs for anomalous patterns, such as multiple identical authorization exchanges occurring within a short timeframe.
Compensating Controls: Implement strict network access controls to limit exposure of the Gitea interface to trusted networks while the upgrade process is scheduled.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 3, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The severity of this flaw necessitates immediate attention. Organizations utilizing Gitea for repository management should prioritize the update to version 1.25.5 to eliminate the risk of session hijacking and unauthorized repository access.
Update Gitea Gitea Open Source Git Server to the latest version. Monitor for exploitation attempts and review access logs.
Gitea versions up to and including 1
Gitea versions up to and including 1
---METADATA---
VENDOR: Gitea
PRODUCT: Gitea Open Source Git Server
AFFECTED_VERSIONS: Gitea versions prior to 1.26.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Gitea is susceptible to an authorization bypass where authenticated low-privilege users can push unauthorized commits to repositories by abusing the pull request maintainer edit flag.
Executive Summary:
A critical authorization bypass vulnerability in Gitea allows authenticated low-privileged users to perform unauthorized write operations on repositories.
Vulnerability Details
CVE-ID: CVE-2026-26231
Affected Software: Gitea Open Source Git Server
Affected Versions: Gitea versions prior to 1.26.2
Vulnerability: This is an authorization bypass vulnerability affecting the "Allow edits from maintainers" feature. An authenticated user with read-only access can exploit this by using reverse-fork pull requests to push commits to an upstream repository without proper write-access validation.
Business Impact
The ability for unauthorized users to push arbitrary code to repositories poses a severe risk to software supply chain integrity. With a CVSS score of 8.5, this vulnerability could lead to the injection of malicious code, backdoors, or the corruption of production-ready source code, resulting in significant reputational damage and potential system compromise.
Remediation Plan
Immediate Action: Upgrade all Gitea instances to version 1.26.2 or later to resolve the authorization logic flaw.
Proactive Monitoring: Review repository commit logs for suspicious activity or unexpected contributions from users who do not hold write permissions.
Compensating Controls: Strictly enforce branch protection rules and require signed commits to ensure that only authorized changes are merged into critical branches.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the high CVSS score of 8.5, this vulnerability represents a significant risk to development environments. Organizations should prioritize the update to Gitea 1.26.2 immediately to prevent unauthorized code injection and maintain the integrity of their Git workflows.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The newbee-mall application uses unsalted MD5 hashing for password storage, allowing attackers who obtain the database to rapidly recover plaintext cr...
The newbee-mall application uses unsalted MD5 hashing for password storage, allowing attackers who obtain the database to rapidly recover plaintext credentials via offline attacks.
---METADATA---
VENDOR: newbee-mall
PRODUCT: newbee-mall
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The newbee-mall application uses unsalted MD5 hashing for password storage, allowing attackers who obtain the database to rapidly recover plaintext credentials via offline attacks.
Executive Summary:
Weak password hashing in newbee-mall exposes user credentials to rapid offline cracking, significantly increasing the risk of account takeover following a data breach.
Vulnerability Details
CVE-ID: CVE-2026-26219
Affected Software: newbee-mall
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The application stores passwords using the MD5 algorithm without per-user salts or computational cost controls. This makes the stored hashes highly susceptible to rapid recovery through rainbow tables or brute-force attacks if the database is compromised.
Business Impact
A CVSS score of 9.1 indicates a critical risk. If attackers gain access to database backups or exports, they can quickly decrypt administrative and user passwords, leading to widespread account takeovers and the potential compromise of other systems where users have reused their passwords.
Remediation Plan
Immediate Action: Update the application to a version that implements secure password hashing (e.g., Argon2 or bcrypt) and force a password reset for all users upon the next login.
Proactive Monitoring: Monitor for suspicious database access or unauthorized attempts to export user tables.
Compensating Controls: Implement database-at-rest encryption and strict access controls to prevent unauthorized personnel from obtaining the password hashes in the first place.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Feb 12, 2026, there is no public information indicating active exploitation. This vulnerability is typically exploited post-compromise to maximize the impact of a data breach.
Analyst Recommendation
Modern security standards require robust, salted hashing algorithms. Organizations should update newbee-mall immediately to a version that supports secure credential storage and educate users on the importance of unique passwords to mitigate the impact of hash disclosure.
Update LG Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
The newbee-mall application utilizes pre-seeded administrator accounts with predictable default passwords, allowing unauthenticated attackers to gain...
The newbee-mall application utilizes pre-seeded administrator accounts with predictable default passwords, allowing unauthenticated attackers to gain full administrative control upon deployment.
---METADATA---
VENDOR: newbee-mall
PRODUCT: newbee-mall
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The newbee-mall application utilizes pre-seeded administrator accounts with predictable default passwords, allowing unauthenticated attackers to gain full administrative control upon deployment.
Executive Summary:
The presence of hardcoded, predictable administrative credentials in newbee-mall poses a critical risk, potentially allowing unauthenticated attackers to seize complete control of the application.
Vulnerability Details
CVE-ID: CVE-2026-26218
Affected Software: newbee-mall
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability involves the use of hardcoded, pre-seeded administrator accounts within the database initialization script. Unauthenticated attackers can leverage these predictable default credentials to bypass security controls and access the administrative interface.
Business Impact
A successful exploit grants an attacker full administrative privileges, leading to a total compromise of the application's integrity, confidentiality, and availability. With a CVSS score of 9.8, the impact is categorized as Critical, potentially resulting in the theft of customer data, financial fraud, and significant reputational damage to the organization.
Remediation Plan
Immediate Action: Change all default administrative passwords immediately and remove any unnecessary pre-seeded accounts from the database.
Proactive Monitoring: Monitor authentication logs for successful logins to administrative accounts from unrecognized IP addresses or at unusual times.
Compensating Controls: Implement multi-factor authentication (MFA) for all administrative accounts and restrict access to the admin panel to trusted network ranges via an IP allowlist.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Feb 12, 2026, there is no public information indicating active exploitation of this vulnerability. However, because the credentials are predictable and included in public scripts, the potential for exploitation is extremely high.
Analyst Recommendation
The reliance on default credentials is a severe security oversight that must be addressed immediately. It is highly recommended that administrators audit their database initialization processes to ensure all default accounts are secured or disabled before the application is exposed to any network.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Crawl4AI versions prior to 0
Crawl4AI versions prior to 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Crawl4AI versions prior to 0.8.0 allow unauthenticated remote code execution via the `/crawl` endpoint by exploiting the `hooks` parameter to import a...
Crawl4AI versions prior to 0.8.0 allow unauthenticated remote code execution via the `/crawl` endpoint by exploiting the `hooks` parameter to import arbitrary Python modules.
---METADATA---
VENDOR: Crawl4AI
PRODUCT: Docker API deployment
AFFECTED_VERSIONS: Versions prior to 0.8.0
---END_METADATA---
Description Summary:
Crawl4AI versions prior to 0.8.0 allow unauthenticated remote code execution via the /crawl endpoint by exploiting the hooks parameter to import arbitrary Python modules.
Executive Summary:
An unauthenticated remote code execution vulnerability in Crawl4AI's Docker API allows attackers to achieve full server compromise, including data exfiltration and lateral movement.
Vulnerability Details
CVE-ID: CVE-2026-26216
Affected Software: Crawl4AI
Affected Versions: Versions prior to 0.8.0
Vulnerability: The /crawl endpoint accepts a hooks parameter containing Python code executed via exec(). Because the __import__ builtin was not restricted, unauthenticated attackers can import arbitrary modules and execute system commands on the host.
Business Impact
This vulnerability carries a CVSS score of 10, the highest possible severity. Successful exploitation allows for complete system takeover, sensitive data theft, and the ability for attackers to pivot into internal networks, resulting in catastrophic operational and financial damage.
Remediation Plan
Immediate Action: Update the Crawl4AI Docker API deployment to version 0.8.0 or later immediately to remove the vulnerable code execution path.
Proactive Monitoring: Review API logs for requests to the /crawl endpoint that include suspicious Python code or attempts to use the hooks parameter.
Compensating Controls: Place the Docker API behind a Web Application Firewall (WAF) with rules designed to block Python-style injection and restrict API access to authenticated users only.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Feb 12, 2026, there is no public information indicating active exploitation. However, the technical nature of the flaw makes it trivial to exploit once the endpoint is identified.
Analyst Recommendation
A CVSS 10.0 vulnerability requires immediate, out-of-band patching. Organizations must ensure that no Crawl4AI instances are exposed to the public internet without authentication and that all instances are updated to version 0.8.0 or higher.
Update Docker API deployment to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3
Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a...
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted pickle payload to the exposed ZMQ socket to execute arbitrary code on the server with the privileges of the ktransformers process.
---METADATA---
VENDOR: KTransformers
PRODUCT: KTransformers
AFFECTED_VERSIONS: 0 through 0.5.3
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
KTransformers versions 0 through 0.5.3 are vulnerable to unsafe deserialization via the balance_serve backend mode, allowing unauthenticated remote code execution.
Executive Summary:
A critical unsafe deserialization vulnerability in KTransformers allows unauthenticated attackers to achieve remote code execution on the host server.
Vulnerability Details
CVE-ID: CVE-2026-26210
Affected Software: KTransformers
Affected Versions: 0 through 0.5.3
Vulnerability: The application binds a ZMQ ROUTER socket to all interfaces without authentication and uses pickle.loads() to process incoming messages, which is an unsafe deserialization practice.
Business Impact
With a CVSS score of 9.8, this vulnerability poses a severe risk to any environment running KTransformers. An attacker can execute arbitrary code with the privileges of the service, potentially leading to full server compromise, data exfiltration, or the deployment of persistent malware.
Remediation Plan
Immediate Action: Upgrade to the latest version of KTransformers immediately. If an update is not available, cease use of the 'balance_serve' feature or isolate the service from all untrusted networks.
Proactive Monitoring: Inspect network traffic for unauthorized connections to the ZMQ socket port and monitor server process behavior for anomalous activity.
Compensating Controls: Implement strict network segmentation to ensure the ZMQ socket is not exposed to the public internet or untrusted internal segments.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of April 24, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The use of pickle for deserializing untrusted data is a high-risk practice that should be avoided entirely.
Analyst Recommendation
This vulnerability is highly critical due to the ease of exploitation. Security teams must ensure that instances of KTransformers are not exposed to the internet and should prioritize upgrading to a version that replaces unsafe deserialization methods.
Update KTransformers Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3
A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
ADB Explorer is a fluent UI for ADB on Windows
ADB Explorer is a fluent UI for ADB on Windows
---METADATA---
VENDOR: ADB Explorer
PRODUCT: ADB Explorer
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
ADB Explorer, a fluent UI for ADB on Windows, contains a high-severity vulnerability that could lead to unauthorized system access or data manipulation.
Executive Summary:
ADB Explorer for Windows is affected by a high-severity vulnerability that could allow for unauthorized access to connected devices or the host system.
Vulnerability Details
CVE-ID: CVE-2026-26208
Affected Software: ADB Explorer
Affected Versions: See vendor advisory for affected versions
Vulnerability: The specific nature of this vulnerability is currently undisclosed, but the CVSS score of 7.8 indicates a high-risk security flaw. Given the application's function, it likely involves insecure handling of ADB commands or local privilege escalation.
Business Impact
A successful exploit could allow an attacker to gain unauthorized access to Android devices connected to the Windows host or potentially escalate privileges on the host machine itself. This poses a risk to sensitive data stored on mobile devices and the security of the developer workstation.
Remediation Plan
Immediate Action: Update ADB Explorer to the most recent version available and limit the use of the tool to trusted administrative users.
Proactive Monitoring: Monitor for unusual ADB traffic or unauthorized attempts to access the ADB daemon on Windows workstations.
Compensating Controls: Ensure that "USB Debugging" is disabled on mobile devices when not actively in use to reduce the attack surface.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 14, 2026, no active exploitation has been reported. Users should remain vigilant and apply updates as they become available from the project maintainers.
Analyst Recommendation
Due to the high severity score, users of ADB Explorer should prioritize updating the software. Until a patch is confirmed, exercise caution when connecting devices to workstations running this software.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Penpot is an open-source design tool for design and code collaboration
Penpot is an open-source design tool for design and code collaboration
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HDF5 is software for managing data
HDF5 is software for managing data
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A weakness has been identified in Huace Monitoring and Early Warning System 2
A weakness has been identified in Huace Monitoring and Early Warning System 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Ormar ORM aggregate queries lack sanitization in `min()` and `max()` methods, allowing unauthenticated attackers to inject raw SQL and extract entire...
Ormar ORM aggregate queries lack sanitization in `min()` and `max()` methods, allowing unauthenticated attackers to inject raw SQL and extract entire database contents via subqueries.
---METADATA---
VENDOR: Ormar
PRODUCT: Ormar ORM
AFFECTED_VERSIONS: 0.9.9 through 0.22.0
---END_METADATA---
Description Summary:
Ormar ORM aggregate queries lack sanitization in min() and max() methods, allowing unauthenticated attackers to inject raw SQL and extract entire database contents via subqueries.
Executive Summary:
A critical SQL injection vulnerability in the Ormar ORM for Python allows unauthenticated attackers to exfiltrate sensitive database contents by manipulating aggregate query parameters.
Vulnerability Details
CVE-ID: CVE-2026-26198
Affected Software: Ormar ORM
Affected Versions: 0.9.9 through 0.22.0
Vulnerability: This SQL injection flaw occurs because user-supplied column names are passed directly into sqlalchemy.text() without validation. An unauthenticated attacker can exploit the min() and max() methods to embed raw SQL subqueries into aggregate function calls.
Business Impact
Successful exploitation allows an unauthorized actor to read the entire database, including tables completely unrelated to the application's models. Given the CVSS score of 9.8, this represents a near-total loss of data confidentiality and could lead to significant regulatory non-compliance and reputational damage.
Remediation Plan
Immediate Action: Administrators must upgrade the Ormar package to version 0.23.0 or later immediately to resolve the unsanitized SQL construction.
Proactive Monitoring: Review database logs for unusual subqueries within aggregate functions and monitor for unexpected data egress patterns.
Compensating Controls: Implement strict input validation at the application layer to ensure only known-good column names are passed to aggregate methods.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Feb 24, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the ease of injecting SQL via standard ORM methods, the potential for exploitation is extremely high for any application exposing these aggregate functions to user input.
Analyst Recommendation
This vulnerability is categorized as Critical due to the lack of authentication required and the high impact on data confidentiality. Organizations using affected versions of Ormar must prioritize the update to version 0.23.0 to mitigate the risk of full database compromise.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Datalogics
PRODUCT: Ecommerce Delivery (WordPress plugin)
AFFECTED_VERSIONS: Versions before 2.6.60
---END_METADATA---
Description Summary:
The Datalogics Ecommerce Delivery plugin for WordPress before 2.6.60 contains an unauthenticated REST endpoint vulnerability allowing remote attackers to modify site options and gain admin access.
Executive Summary:
A critical vulnerability in the Datalogics Ecommerce Delivery WordPress plugin allows unauthenticated attackers to escalate privileges to Administrator by manipulating site configuration options.
Vulnerability Details
CVE-ID: CVE-2026-2631
Affected Software: Datalogics Ecommerce Delivery (WordPress plugin)
Affected Versions: Versions before 2.6.60
Vulnerability: This flaw exists in an unauthenticated REST endpoint that permits the modification of the
datalogics_tokenoption. An attacker can exploit this lack of verification to authenticate against a protected endpoint and execute arbitraryupdate_option()calls, enabling user registration and setting the default role to Administrator.Business Impact
A successful exploit grants an attacker full control over the WordPress environment. By enabling registration and promoting themselves to the Administrator role, attackers can steal sensitive customer data, deface the website, or deploy malware. The CVSS score of 9.8 reflects the critical nature of this unauthenticated remote privilege escalation.
Remediation Plan
Immediate Action: Update the Datalogics Ecommerce Delivery plugin to version 2.6.60 or later immediately to patch the vulnerable REST endpoint.
Proactive Monitoring: Review WordPress user logs for unauthorized new Administrator accounts and inspect the
wp_optionstable for unexpected changes to thedefault_roleorusers_can_registersettings.Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to block unauthorized requests to WordPress REST API endpoints, specifically those targeting plugin-specific options.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 11, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw and the ease of automating REST API attacks, the potential for exploitation is high.
Analyst Recommendation
This vulnerability represents a total loss of confidentiality, integrity, and availability for affected WordPress sites. IT administrators must prioritize this update, as the ability for unauthenticated users to modify core site options is a worst-case scenario. Apply the version 2.6.60 patch immediately.