| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-89193 | Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser | Unknown | Robin Image Optimizer | - | - | 2026-09-30 06:00:23 | Deep Dive |
| CVE-2026-87777 | Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute | Unknown | Hostinger Reach | - | - | 2026-09-30 06:00:23 | Deep Dive |
| CVE-2026-88797 | Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation | Unknown | Vayu X | - | - | 2026-09-30 06:00:23 | Deep Dive |
| CVE-2026-88791 | Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules | Unknown | Safe Redirect Manager | - | - | 2026-09-30 06:00:23 | Deep Dive |
| CVE-2026-85573 | All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload | Unknown | All in One Files Upload | - | - | 2026-09-30 06:00:22 | Deep Dive |
| CVE-2026-85576 | All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update | Unknown | All in One Files Upload | - | - | 2026-09-30 06:00:22 | Deep Dive |
| CVE-2026-85415 | Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL | Unknown | Audio Player Block | - | - | 2026-09-30 06:00:22 | Deep Dive |
| CVE-2026-85001 | EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute | Unknown | EmbedPress | - | - | 2026-09-30 06:00:22 | Deep Dive |
| CVE-2026-86789 | Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes | Unknown | Connections Business Directory | - | - | 2026-09-30 06:00:22 | Deep Dive |
| CVE-2026-75873 | Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload | Unknown | Zella Theme | - | - | 2026-09-30 06:00:21 | Deep Dive |
| CVE-2026-83560 | New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass | Unknown | New User Approve | - | - | 2026-09-30 06:00:21 | Deep Dive |
| CVE-2026-80333 | Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes | Unknown | Solace Extra | - | - | 2026-09-30 06:00:21 | Deep Dive |
| CVE-2026-82127 | Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields | Unknown | Schema & Structured Data for WP & AMP | - | - | 2026-09-30 06:00:21 | Deep Dive |
| CVE-2026-75823 | WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption | Unknown | User Frontend | - | - | 2026-09-30 06:00:20 | Deep Dive |
| CVE-2026-75824 | WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled | Unknown | User Frontend | - | - | 2026-09-30 06:00:20 | Deep Dive |
| CVE-2026-100143 | FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email | Unknown | FluentCart A New Era of eCommerce | - | - | 2026-09-30 06:00:20 | Deep Dive |
| CVE-2026-102913 | SourceCodester Car Driving School Management System Master.php save_enrollment sql injection | SourceCodester | Car Driving School Management System | High | 7.3 | 2026-09-30 04:15:08 | Deep Dive |
| CVE-2026-103111 | PCRE2 10.49前JIT越界写漏洞 | PCRE | PCRE2 | High | 7.6 | 2026-09-30 04:13:59 | Deep Dive |
| CVE-2026-102912 | SourceCodester Online Leave Management System page reports sql injection | SourceCodester | Online Leave Management System | Medium | 4.7 | 2026-09-30 04:00:09 | Deep Dive |
| CVE-2026-102911 | zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection | zosmaai | pi-llm-wiki | Critical | 9.9 | 2026-09-30 03:45:12 | Deep Dive |