Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-9677

Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting_CVE-2026-9677

The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it ...

Unknown Shariff for WordPress CVE
HIGH 8.1 CVE-2026-10820

ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR_CVE-2026-10820

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does no...

Unknown Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content CVE
HIGH 7 CVE-2026-49417

Multiple vulnerabilities in the sound(4) mmap path_CVE-2026-49417

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory coul...

FreeBSD FreeBSD 15.0-RELEASE CVE
HIGH 7.1 CVE-2026-49413

Flaw in Linuxulator execution of setugid binaries_CVE-2026-49413

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is n...

FreeBSD FreeBSD 15.0-RELEASE CVE
HIGH 7.8 CVE-2026-49412

Use-after-free bug in the IPV6_MSFILTER socket option handler_CVE-2026-49412

The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. ...

FreeBSD FreeBSD 15.0-RELEASE CVE
MEDIUM 6.5 CVE-2026-45259

sigqueue(2) missing capability mode restriction_CVE-2026-45259

sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not i...

FreeBSD FreeBSD 15.0-RELEASE CVE
HIGH 7.8 CVE-2026-45258

Multiple vulnerabilities in the sound(4) mmap path_CVE-2026-45258

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This additio...

FreeBSD FreeBSD 15.0-RELEASE CVE
HIGH 7.8 CVE-2026-49414

ASLR bypass for setuid executables via procctl(2)_CVE-2026-49414

The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather tha...

FreeBSD FreeBSD 15.0-RELEASE CVE
CRITICAL 9.8 CVE-2026-49048

Joomla Extension – joomcoder.com – Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1_CVE-2026-49048

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request ...

joomcoder.com JoomCCK extension for Joomla 1.0-6.4.0 CVE
MEDIUM 4.3 CVE-2026-9676

f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification_CVE-2026-9676

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing a...

Unknown F4 Post Tree CVE