Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-11968

Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) in TortoiseGit_CVE-2026-11968

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

TortoiseGit team TortoiseGit 1.8.10.0 CVE
MEDIUM 6.9 CVE-2026-13150

SSRF in Pentestify PDF generation endpoint via Host header_CVE-2026-13150

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 ...

Pentestify Pentestify CVE
HIGH 7.9 CVE-2026-10745

CVE-2026-10745_CVE-2026-10745

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampe...

upKeeper Solutions upKeeper Instant Privilege Access CVE
MEDIUM 4.3 CVE-2026-9724

MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update_CVE-2026-9724

The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing ...

motordesk MotorDesk CVE
MEDIUM 4.3 CVE-2026-9721

Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update_CVE-2026-9721

The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is ...

chuhpl Book a Room Event Calendar CVE
HIGH 7.2 CVE-2026-9643

WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging_CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versio...

joomunited WP Meta SEO CVE
MEDIUM 6.4 CVE-2026-9620

WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripting via Post Content Image src Attribute_CVE-2026-9620

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions ...

joomunited WP Latest Posts CVE
MEDIUM 4.3 CVE-2026-9619

Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action_CVE-2026-9619

The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is...

berfect Reviews and Rating – Docplanner CVE
MEDIUM 4.3 CVE-2026-9616

Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Security.txt Deletion via delete_securitytxt AJAX Action_CVE-2026-9616

The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to t...

verenigingvanregistrars Generate Security.txt CVE
MEDIUM 5.3 CVE-2026-9612

WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs_CVE-2026-9612

The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i...

yapacdev WhatsOrder – Instant Checkout for WooCommerce CVE