Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-46683

Snappy: SSRF and local file read via the xsl-style-sheet option_CVE-2026-46683

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local...

KnpLabs snappy < 1.7.0 CVE
HIGH 7.5 CVE-2026-46643

Snappy: Binary path is never shell-escaped due to an inverted is_executable check_CVE-2026-46643

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(...

KnpLabs snappy < 1.7.1 CVE
HIGH 8.4 CVE-2026-46529

PDF /GoToR action argv injection enables single-click RCE via –gtk-module dlopen_CVE-2026-46529

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability ...

mate-desktop atril < 1.26.3 CVE
MEDIUM 4.6 CVE-2026-45106

Weblate: Stored HTML injection in editor search preview_CVE-2026-45106

Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without es...

WeblateOrg weblate < 2026.5 CVE
HIGH 7.5 CVE-2026-1220

CVE-2026-1220_CVE-2026-1220

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromi...

Google Chrome 144.0.7559.99 CVE
MEDIUM 5.1 CVE-2026-53742

Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes_CVE-2026-53742

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attacker...

quantumcloud Simple Link Directory CVE
MEDIUM 5.1 CVE-2026-53741

Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option_CVE-2026-53741

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitiz...

quantumcloud Simple Link Directory CVE
MEDIUM 5.1 CVE-2026-53740

Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice_CVE-2026-53740

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can sc...

Yoast Yoast Duplicate Post CVE
MEDIUM 5.1 CVE-2026-53739

Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice_CVE-2026-53739

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies n...

Yoast Yoast Duplicate Post CVE
HIGH 7.2 CVE-2026-53738

Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler_CVE-2026-53738

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers ...

Inisev Copy & Delete Posts CVE