Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.4 CVE-2026-9134

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter_CVE-2026-9134

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up ...

fooplugins Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel CVE
HIGH 7.2 CVE-2026-9109

GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage_CVE-2026-9109

The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Si...

john-dagelmore GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites CVE
MEDIUM 6.4 CVE-2026-9629

Canvas <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute_CVE-2026-9629

The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 du...

codesupplyco Canvas CVE
MEDIUM 6.4 CVE-2026-3297

Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block_CVE-2026-3297

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block ...

softaculous Page Builder: Pagelayer – Drag and Drop website builder CVE
MEDIUM 4.3 CVE-2026-2470

Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'_CVE-2026-2470

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, an...

softaculous Page Builder: Pagelayer – Drag and Drop website builder CVE
MEDIUM 6.4 CVE-2026-11769

Operator – Namespaced User Path Traversal_CVE-2026-11769

We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escala...

Grafana Grafana Operator CVE
HIGH 7.5 CVE-2026-9848

WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter_CVE-2026-9848

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, ...

emarket-design Customer Support Ticket System & Helpdesk CVE
MEDIUM 5.5 CVE-2026-54231

Abrt: unsanitized systemd journal content written to dump directory files enables content injection_CVE-2026-54231

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journa...

Red Hat Red Hat Enterprise Linux 6 CVE
HIGH 7 CVE-2026-54230

Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites_CVE-2026-54230

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shel...

Red Hat Red Hat Enterprise Linux 6 CVE
HIGH 7 CVE-2026-54229

Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking_CVE-2026-54229

A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY ...

Red Hat Red Hat Enterprise Linux 6 CVE