Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,727 CVEs tagged with CWE-862435 Critical, 1,964 High, 6,036 Medium, 291 Low, 1 Unrated.

CVE-2026-56668

Published Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not veri…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55638

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rew…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-1667

Published Jul 10, 2026

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a…

CVSS 7.2 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-61441

Published Jul 10, 2026

PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-59796

Published Jul 10, 2026

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56279

Published Jul 10, 2026

Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access cont…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-9857

Published Jul 10, 2026

The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user…

CVSS 4.3 · Medium
evidence mentions
13
Buzz score
41.4

CVE-2026-11990

Published Jul 10, 2026

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the…

CVSS 5.3 · Medium
evidence mentions
13
Buzz score
41.4

CVE-2026-1946

Published Jul 10, 2026

The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
35.8

CVE-2026-15026

Published Jul 10, 2026

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_s…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
38.0

CVE-2026-12955

Published Jul 10, 2026

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-11992

Published Jul 10, 2026

The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying th…

CVSS 4.3 · Medium
evidence mentions
10
Buzz score
39.0

CVE-2026-15332

Published Jul 10, 2026

A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint.…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-15293

Published Jul 10, 2026

The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly ve…

CVSS 8.0 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-15291

Published Jul 10, 2026

The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpo…

CVSS 7.5 · High
evidence mentions
6
Buzz score
29.5

CVE-2026-44918

Published Jul 10, 2026

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
34.4

CVE-2026-11818

Published Jul 10, 2026

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14.…

CVSS 5.4 · Medium
evidence mentions
11
Buzz score
39.9

CVE-2026-15320

Published Jul 10, 2026

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulati…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-59853

Published Jul 9, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46413

Published Jul 9, 2026

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadM…

CVSS 6.5 · Medium
evidence mentions
9
Buzz score
28.0
Vendor/product tagsBeta · best-effort

CVE-2026-54695

Published Jul 9, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSoc…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-54005

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know…

CVSS 7.1 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-54004

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-49274

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed au…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
25.8
Showing 251-275 of 8,727 CVEsPage 11 of 350