Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2025-66123

WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) vulnerability_CVE-2025-66123

Unauthenticated Insecure Direct Object References (IDOR) in BookPro

About Envato BookPro n/a CVE
MEDIUM 5.3 CVE-2025-64637

WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability_CVE-2025-64637

Unauthenticated Content Injection in Auros Core

Opal_WP Auros Core n/a CVE
MEDIUM 5.3 CVE-2025-64636

WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulnerability_CVE-2025-64636

Unauthenticated Broken Access Control in Donation Thermometer

rhewlif Donation Thermometer n/a CVE
MEDIUM 4.3 CVE-2025-63079

WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Control vulnerability_CVE-2025-63079

Contributor Broken Access Control in Live Copy Paste for Elementor

bdthemes Live Copy Paste for Elementor n/a CVE
MEDIUM 4.3 CVE-2025-63078

WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability_CVE-2025-63078

Subscriber Broken Access Control in Restaurant Menu by MotoPress

jetmonsters Restaurant Menu by MotoPress n/a CVE
MEDIUM 5.4 CVE-2025-63041

WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Control vulnerability_CVE-2025-63041

Contributor Broken Access Control in Forget About Shortcode Buttons

Code Amp Forget About Shortcode Buttons n/a CVE
MEDIUM 6.5 CVE-2026-9639

Authenticated Denial of Service via Malicious Backup Tarball in LXD_CVE-2026-9639

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_sto...

Canonical LXD 5.21.0 CVE
MEDIUM 5.5 CVE-2026-44018

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend_CVE-2026-44018

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2....

docling-project docling >= 2.45.0, < 2.91.0 CVE
MEDIUM 5.4 CVE-2026-56823

AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering_CVE-2026-56823

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /ap...

Significant-Gravitas AutoGPT < 0.6.64 CVE
MEDIUM 5.3 CVE-2026-55686

Podman: WORKDIR symlink traversal vulnerability_CVE-2026-55686

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains ...

podman-container-tools podman >= 3.0.0, < 5.7.1 CVE