The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issu...
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
Unauthenticated Path Traversal in FastDup
Unauthenticated SQL Injection in eCommerce Product Catalog
Unauthenticated PHP Object Injection in OttoKit
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites
Unauthenticated PHP Object Injection in WP Travel Engine
Unauthenticated PHP Object Injection in wpForo Forum
Unauthenticated PHP Object Injection in Happyforms
Subscriber Arbitrary File Deletion in WP User Manager
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.