Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-11942

Akaunting 3.1.21 – Stored XSS in delete confirmation modal_CVE-2026-11942

Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation flow. A user with permissi...

Akaunting Akaunting 3.1.21 CVE
MEDIUM 5.4 CVE-2026-11372

IBM TRIRIGA Cross-Site Scripting Vulnerability_CVE-2026-11372

IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embe...

IBM TRIRIGA Application Platform 5.0.2 CVE
MEDIUM 5.3 CVE-2026-7859

Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media_CVE-2026-7859

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated...

Unknown Motors CVE
MEDIUM 5.1 CVE-2026-12863

Open redirect_CVE-2026-12863

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

pretix Venueless 0.0.0 CVE
MEDIUM 4.3 CVE-2026-9162

Global session revocation does not invalidate active WebSocket connections_CVE-2026-9162

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 6.9 CVE-2026-7167

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7167

The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fak...

Gaudire Assassin game last version CVE
MEDIUM 6.4 CVE-2026-6673

Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install_CVE-2026-6673

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 4.4 7DF60A36-5B48-

Exploit for CVE-2026-2002_7DF60A36-5B48-59EB-A46D-66756D01D7E4

Sumary The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.4 CVE-2026-6062

IDOR in Jira plugin subscription edit endpoint_CVE-2026-6062

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 5.4 CVE-2026-5139

GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration_CVE-2026-5139

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE