home.social

#cve β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve, aggregated by home.social.

  1. 🚨 SIGINT // Cybersecurity Watch β€” 2026-07-21
    SonicWall zero-days exploited to deliver custom malware for weeks before a patch existed β€” perimeter devices remain prime attacker targets.
    securityweek.com/sonicwall-zer

  2. Security Tip: Verify the integrity of every software package. πŸ›‘οΈ In an era of supply chain attacks, downloading from a 'trusted' site isn't enough. Always check digital signatures or SHA-256 checksums provided by the vendor. This ensures the file hasn't been tampered with mid-transit or on the mirror server. For the latest vulnerability intelligence, visit: cvedatabase.com

  3. Security Tip: Buy time with Virtual Patching. πŸ›‘οΈ When a critical CVE drops, immediate patching isn't always feasible due to testing requirements. Virtual patching uses security controls like WAFs or IPS to intercept exploit attempts at the network layer. This provides a stop-gap defense while you prepare the permanent fix. Don't leave the window openβ€”shield first, then remediate. Explore vulnerabilities: cvedatabase.com

  4. 282,000+ VEX records are now in Vulnerability-Lookup πŸŽ‰

    πŸ”Ž vulnerability.circl.lu/vex

    SUSE just joined Red Hat and Microsoft as a VEX source β€” so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

    VEX statements are attached directly to each vulnerability and available via the open API.

    πŸ§‘β€πŸ’» github.com/vulnerability-looku

    #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability

  5. 282,000+ VEX records are now in Vulnerability-Lookup πŸŽ‰

    πŸ”Ž vulnerability.circl.lu/vex

    SUSE just joined Red Hat and Microsoft as a VEX source β€” so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

    VEX statements are attached directly to each vulnerability and available via the open API.

    πŸ§‘β€πŸ’» github.com/vulnerability-looku

    #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability

  6. CVE-2026-12080 - Privilege Escalation in QEMU Guest Agent. TOCTOU & symlink abuse in guest-ssh-add-authorized-keys. CVSS 7.3. Unpatched. Restrict qga access immediately. #CVE #infosec #QEMU

    valtersit.com/cve/CVE-2026-120

  7. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 24 CVEs across 26 images:
    β€’ πŸ”΄ Critical: 1
    β€’ 🟠 High: 5
    β€’ 🟑 Medium: 13
    β€’ πŸ”΅ Low: 5

    Check the full report πŸ‘‰ lambdawatchdog.com/

  8. 🚨 Security Alert: Our Weekly CVE Roundup is live! This week, we analyze CVE-2026-31022, a critical RCE in Next.js, and explore the evolving threat landscape for server-side rendering and edge architectures. Stay informed and secure: cvedatabase.com/blog/weekly-cv

  9. Security Tip: Automate your dependency audits. πŸ›‘οΈ Modern apps rely on hundreds of third-party libraries. Manually checking for vulnerabilities is impossible. Integrate tools like Snyk, Trivy, or OWASP Dependency-Check directly into your CI/CD pipeline. This ensures every build is scanned against known CVEs before deployment. Stay informed on the latest threats and vulnerability intelligence at cvedatabase.com

  10. CVE-2026-42566 - DoS in Meshtastic via malformed User.long_name. BLE crash on iOS. CVSS 7.5. Unpatched. Review your mesh setup. #CVE #IoT #infosec

    valtersit.com/cve/CVE-2026-425

  11. 🚨 EUVD-2026-45876

    πŸ“Š Score: n/a
    πŸ“¦ Product: Unlimited Elements For Elementor
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  12. 🚨 EUVD-2026-45876

    πŸ“Š Score: n/a
    πŸ“¦ Product: Unlimited Elements For Elementor
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  13. 🚨 EUVD-2026-45876

    πŸ“Š Score: n/a
    πŸ“¦ Product: Unlimited Elements For Elementor
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  14. 🚨 EUVD-2026-45876

    πŸ“Š Score: n/a
    πŸ“¦ Product: Unlimited Elements For Elementor
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  15. 🚨 EUVD-2026-45877

    πŸ“Š Score: n/a
    πŸ“¦ Product: Reviews Feed
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  16. 🚨 EUVD-2026-45877

    πŸ“Š Score: n/a
    πŸ“¦ Product: Reviews Feed
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  17. 🚨 EUVD-2026-45877

    πŸ“Š Score: n/a
    πŸ“¦ Product: Reviews Feed
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  18. 🚨 EUVD-2026-45877

    πŸ“Š Score: n/a
    πŸ“¦ Product: Reviews Feed
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  19. 🚨 EUVD-2026-45880

    πŸ“Š Score: n/a
    πŸ“¦ Product: WP Travel
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  20. 🚨 EUVD-2026-45880

    πŸ“Š Score: n/a
    πŸ“¦ Product: WP Travel
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  21. 🚨 EUVD-2026-45880

    πŸ“Š Score: n/a
    πŸ“¦ Product: WP Travel
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  22. 🚨 EUVD-2026-45880

    πŸ“Š Score: n/a
    πŸ“¦ Product: WP Travel
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  23. 🚨 EUVD-2026-45879

    πŸ“Š Score: n/a
    πŸ“¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  24. 🚨 EUVD-2026-45879

    πŸ“Š Score: n/a
    πŸ“¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  25. 🚨 EUVD-2026-45879

    πŸ“Š Score: n/a
    πŸ“¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  26. 🚨 EUVD-2026-45879

    πŸ“Š Score: n/a
    πŸ“¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  27. 🚨 EUVD-2026-45878

    πŸ“Š Score: n/a
    πŸ“¦ Product: All in One SEO
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  28. 🚨 EUVD-2026-45878

    πŸ“Š Score: n/a
    πŸ“¦ Product: All in One SEO
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  29. 🚨 EUVD-2026-45878

    πŸ“Š Score: n/a
    πŸ“¦ Product: All in One SEO
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  30. 🚨 EUVD-2026-45878

    πŸ“Š Score: n/a
    πŸ“¦ Product: All in One SEO
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  31. 🚨 EUVD-2026-45881

    πŸ“Š Score: n/a
    πŸ“¦ Product: SlimStat Analytics
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  32. 🚨 EUVD-2026-45884

    πŸ“Š Score: n/a
    πŸ“¦ Product: All-in-One WP Migration and Backup
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  33. 🚨 EUVD-2026-45881

    πŸ“Š Score: n/a
    πŸ“¦ Product: SlimStat Analytics
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  34. 🚨 EUVD-2026-45884

    πŸ“Š Score: n/a
    πŸ“¦ Product: All-in-One WP Migration and Backup
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  35. 🚨 EUVD-2026-45881

    πŸ“Š Score: n/a
    πŸ“¦ Product: SlimStat Analytics
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  36. 🚨 EUVD-2026-45884

    πŸ“Š Score: n/a
    πŸ“¦ Product: All-in-One WP Migration and Backup
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  37. 🚨 EUVD-2026-45881

    πŸ“Š Score: n/a
    πŸ“¦ Product: SlimStat Analytics
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  38. 🚨 EUVD-2026-45884

    πŸ“Š Score: n/a
    πŸ“¦ Product: All-in-One WP Migration and Backup
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  39. 🚨 EUVD-2026-45883

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  40. 🚨 EUVD-2026-45883

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  41. 🚨 EUVD-2026-45883

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  42. 🚨 EUVD-2026-45883

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  43. 🚨 EUVD-2026-45882

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  44. 🚨 EUVD-2026-45882

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  45. 🚨 EUVD-2026-45882

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  46. 🚨 EUVD-2026-45882

    πŸ“Š Score: n/a
    πŸ“¦ Product: Kirki
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  47. 🚨 EUVD-2026-45885

    πŸ“Š Score: n/a
    πŸ“¦ Product: LearnPress
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  48. 🚨 EUVD-2026-45885

    πŸ“Š Score: n/a
    πŸ“¦ Product: LearnPress
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  49. 🚨 EUVD-2026-45885

    πŸ“Š Score: n/a
    πŸ“¦ Product: LearnPress
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  50. 🚨 EUVD-2026-45885

    πŸ“Š Score: n/a
    πŸ“¦ Product: LearnPress
    🏒 Vendor: Unknown
    πŸ“… Updated: 2026-07-20

    πŸ“ The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability