Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 C0C41549-A96F-

Exploit for CVE-2026-49777_C0C41549-A96F-54F9-85D8-1A24CFAE99BD

CVE-2026-49777 CVE-2026-49777 - ShapedPlugin Product Slider Pro for WooCommerce Backdoor RCE In-Depth Technical Analysis: Product Slider Pro Backdo...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 8A02EE6F-39EF-

Exploit for CVE-2026-8809_8A02EE6F-39EF-56A6-B360-BF2E4D44DF48

CVE-2026-8809 Advanced Custom Fields: Extended = 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to 'acfpostid' Parameter This...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2026-48611

CVE-2026-48611_CVE-2026-48611

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthor...

phpBB phpBB 3.3.0 CVE
CRITICAL 9.9 CVE-2026-47370

CVE-2026-47370_CVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices r...

Ubiquiti Inc UniFi OS Server CVE
CRITICAL 9.9 CVE-2026-47369

CVE-2026-47369_CVE-2026-47369

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices r...

Ubiquiti Inc UniFi OS Server CVE
CRITICAL 9.9 CVE-2026-47367

CVE-2026-47367_CVE-2026-47367

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Ag...

Ubiquiti Inc UID Enterprise Agent CVE
CRITICAL 9.9 CVE-2026-47365

CVE-2026-47365_CVE-2026-47365

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tena...

WebPros WordPress-Toolkit CVE
CRITICAL 9.8 CVE-2026-49060

WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability_CVE-2026-49060

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile Ap...

Hippoo Hippoo Mobile App for WooCommerce n/a CVE
CRITICAL 9.3 CVE-2026-42647

WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability_CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection....

Beardev JoomSport n/a CVE
CRITICAL 9.3 CVE-2026-39494

WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability_CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blin...

WBW Plugins Product Filter by WBW n/a CVE