Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-34101

Guardian Language-System Unauthenticated SQL Injection via id Parameter in text_file.php_CVE-2026-34101

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extens...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34100

Guardian Language-System Unauthenticated SQL Injection via id Parameter in media.php_CVE-2026-34100

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension,...

guardian language-system CVE
CRITICAL 9.3 CVE-2026-34099

Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php_CVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id ...

guardian language-system CVE
MEDIUM 4.8 CVE-2026-34098

Guardian Language-System XSS via id Parameter in media.php_CVE-2026-34098

Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines...

guardian language-system CVE
MEDIUM 4.8 CVE-2026-34097

Guardian Language-System XSS via id Parameter in text_file.php_CVE-2026-34097

Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lin...

guardian language-system CVE
MEDIUM 4.8 CVE-2026-34096

Guardian Language-System XSS via name Parameter in designer.php_CVE-2026-34096

Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57)...

guardian language-system CVE
MEDIUM 5.3 CVE-2026-27409

WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability_CVE-2026-27409

Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This i...

Webba Plugins Webba Booking n/a CVE
MEDIUM 4.3 CVE-2026-13211

Genucenter Disclosure of SNMP Credentials_CVE-2026-13211

The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to...

genua genucenter 8.0 CVE
MEDIUM 5.3 CVE-2026-57721

WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability_CVE-2026-57721

Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

WP Reloaded ApplyOnline n/a CVE
MEDIUM 4.3 CVE-2026-57720

WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability_CVE-2026-57720

Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issu...

Codexpert Inc ThumbPress n/a CVE