All 6 CVE vulnerabilities found in Breeze Cache, with AI-generated Chinese analysis, references, and POCs.
Vendor: cloudways
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-79713 | Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters | 6.5 | Medium | 2026-09-18 |
| CVE-2026-79706 | Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal | - | - | 2026-08-28 |
| CVE-2026-10551 | Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library | - | - | 2026-07-13 |
| CVE-2026-2128 | Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to an Unauthorized Actor via Crafted Login Cookie CWE-200 | 5.3 | Medium | 2026-05-29 |
| CVE-2026-3844 | Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote CWE-434 | 9.8 | Critical | 2026-04-23 |
| CVE-2025-13864 | Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletion CWE-862 | 5.3 | Medium | 2026-02-19 |
All 6 known CVE vulnerabilities affecting Breeze Cache with full Chinese analysis, references, and POCs where available.