| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-100510 | WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS) vulnerability | BoldGrid | Post and Page Builder by BoldGrid | High | 7.1 | 2026-09-30 17:39:04 | Deep Dive |
| CVE-2026-100512 | WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability | Hook & Filter | Nested Pages | Critical | 9.8 | 2026-09-30 17:39:04 | Deep Dive |
| CVE-2026-97291 | WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vulnerability | Magazine3 | Schema & Structured Data for WP & AMP | High | 8.8 | 2026-09-30 17:39:03 | Deep Dive |
| CVE-2026-97290 | WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.36 - Cross Site Scripting (XSS) vulnerability | Sayontan Sinha | Photonic Gallery & Lightbox for Flickr, SmugMug & Others | High | 7.1 | 2026-09-30 17:39:02 | Deep Dive |
| CVE-2026-97265 | WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerability | Crocoblock. Jetimpex Inc. | JetEngine | Medium | 6.5 | 2026-09-30 17:39:01 | Deep Dive |
| CVE-2026-94171 | WordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerability | VillaTheme | CURCY | High | 7.1 | 2026-09-30 17:39:00 | Deep Dive |
| CVE-2026-97256 | WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerability | Greg – SiteOrigin | Page Builder by SiteOrigin | High | 7.2 | 2026-09-30 17:39:00 | Deep Dive |
| CVE-2026-102397 | WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerability | supsystic | Ultimate Maps by Supsystic | Medium | 6.5 | 2026-09-30 17:38:59 | Deep Dive |
| CVE-2026-103440 | pagetriagelist discloses suppressed reviewer usernames | The Wikimedia Foundation | MediaWiki PageTriage extension | Low | 1.2 | 2026-09-30 17:38:27 | Deep Dive |
| CVE-2026-103439 | Various rawParams() and escaped() updates to prevent XSS in Wikibase extension | The Wikimedia Foundation | MediaWiki Wikbase extension | Low | 0.3 | 2026-09-30 17:34:10 | Deep Dive |
| CVE-2026-103438 | Various rawParams() and escaped() updates to prevent XSS in Wikistories extension | The Wikimedia Foundation | MediaWiki Wikistories extension | Low | 0.3 | 2026-09-30 17:32:26 | Deep Dive |
| CVE-2026-55224 📌 💣 | MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall | mineadmin | MineAdmin | High | 8.7 | 2026-09-30 17:26:12 | Deep Dive |
| CVE-2026-55094 | Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`) | taskcluster | taskcluster | High | 8.7 | 2026-09-30 17:22:52 | Deep Dive |
| CVE-2026-103476 | yii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-download | yii2-starter-kit | yii2-starter-kit | Medium | 5.3 | 2026-09-30 17:22:42 | Deep Dive |
| CVE-2026-103475 | yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure | yii2-starter-kit | yii2-starter-kit | Critical | 9.1 | 2026-09-30 17:22:42 | Deep Dive |
| CVE-2026-103474 | yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE | yii2-starter-kit | yii2-starter-kit | High | 8.8 | 2026-09-30 17:22:41 | Deep Dive |
| CVE-2026-103473 | Deno 2.7.0 through 2.9.7 Command Injection via node:child_process | denoland | deno | High | 8.1 | 2026-09-30 17:22:40 | Deep Dive |
| CVE-2026-103472 | restbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame Buffering | Corvusoft | restbed | High | 7.5 | 2026-09-30 17:22:39 | Deep Dive |
| CVE-2026-103471 | restbed through 5.0.0 Denial of Service via Unbounded Header Buffering | Corvusoft | restbed | High | 7.5 | 2026-09-30 17:22:39 | Deep Dive |
| CVE-2026-103437 | ReadingLists imported metadata permits JavaScript URL XSS | The Wikimedia Foundation | MediaWiki ReadingLists extension | Low | 1.1 | 2026-09-30 17:17:36 | Deep Dive |