Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-50127

Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)_CVE-2026-50127

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for s...

WeblateOrg weblate >= 5.15, < 2026.6 CVE
MEDIUM 6.9 CVE-2026-46683

Snappy: SSRF and local file read via the xsl-style-sheet option_CVE-2026-46683

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local...

KnpLabs snappy < 1.7.0 CVE
MEDIUM 4.6 CVE-2026-45106

Weblate: Stored HTML injection in editor search preview_CVE-2026-45106

Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without es...

WeblateOrg weblate < 2026.5 CVE
MEDIUM 5.1 CVE-2026-53742

Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes_CVE-2026-53742

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attacker...

quantumcloud Simple Link Directory CVE
MEDIUM 5.1 CVE-2026-53741

Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option_CVE-2026-53741

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitiz...

quantumcloud Simple Link Directory CVE
MEDIUM 5.1 CVE-2026-53740

Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice_CVE-2026-53740

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can sc...

Yoast Yoast Duplicate Post CVE
MEDIUM 5.1 CVE-2026-53739

Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice_CVE-2026-53739

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies n...

Yoast Yoast Duplicate Post CVE
MEDIUM 5.3 CVE-2026-53737

Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response_CVE-2026-53737

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the ...

saas.group Juicer CVE
MEDIUM 5.1 CVE-2026-53736

Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post Action_CVE-2026-53736

Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verifica...

bplugins Easy Twitter Feeds CVE
MEDIUM 4.3 CVE-2026-53634

Sharp: Missing Authorization Check in Quick Creation Command Endpoints_CVE-2026-53634

Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints...

code16 sharp >= 9.0.0, < 9.22.3 CVE