Search Results (10076 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100690 2 Gohugo, Redhat 2 Hugo, Hummingbird 2026-09-30 7.5 High
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.
CVE-2026-97248 2026-09-30 9.8 Critical
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
CVE-2026-97246 2026-09-30 4.9 Medium
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
CVE-2026-96833 2026-09-30 7.2 High
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
CVE-2026-96832 2026-09-30 7.2 High
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
CVE-2026-96831 2026-09-30 8.8 High
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
CVE-2026-96344 2026-09-30 7.2 High
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
CVE-2026-96343 2026-09-30 7.2 High
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-95531 2026-09-30 8.8 High
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
CVE-2026-94683 2026-09-30 8.8 High
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
CVE-2026-94678 2026-09-30 8.8 High
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
CVE-2026-94677 2026-09-30 7.2 High
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
CVE-2026-94122 2026-09-30 7.2 High
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
CVE-2026-94121 2026-09-30 8.8 High
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
CVE-2026-94076 2026-09-30 8.8 High
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
CVE-2026-93771 2026-09-30 7.2 High
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93651 2026-09-30 7.2 High
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93624 2026-09-30 7.2 High
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-91051 2026-09-30 6.6 Medium
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .
CVE-2026-81867 1 Google 1 Application Integration 2026-09-30 N/A
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.