Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,732 CVEs tagged with CWE-862437 Critical, 1,965 High, 6,038 Medium, 291 Low, 1 Unrated.

CVE-2026-54695

Published Jul 9, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSoc…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-54005

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know…

CVSS 7.1 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-54004

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-49274

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed au…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
25.8

CVE-2026-59227

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59226

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking…

CVSS 3.1 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59225

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapp…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59217

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59216

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to…

CVSS 7.7 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-12593

Published Jul 9, 2026

The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9240

Published Jul 9, 2026

The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the up…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-9237

Published Jul 9, 2026

The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is du…

CVSS 4.3 · Medium
evidence mentions
8
Buzz score
33.5

CVE-2026-9235

Published Jul 9, 2026

The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce ve…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-9028

Published Jul 9, 2026

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not pro…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-9021

Published Jul 9, 2026

The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoice_accep…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-4298

Published Jul 9, 2026

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-12428

Published Jul 9, 2026

The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-…

CVSS 6.5 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-8996

Published Jul 9, 2026

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recen…

CVSS 6.5 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-8848

Published Jul 9, 2026

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to…

CVSS 7.2 · High
evidence mentions
13
Buzz score
37.9

CVE-2026-7558

Published Jul 9, 2026

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-14245

Published Jul 9, 2026

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions…

CVSS 9.8 · Critical
evidence mentions
11
Buzz score
36.4

CVE-2026-12406

Published Jul 9, 2026

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-11359

Published Jul 9, 2026

The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in ve…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-48492

Published Jul 8, 2026

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 276-300 of 8,732 CVEsPage 12 of 350