CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 2h ago | 7.1 | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to an arbitrary writable location outside user/pages/, including outside the Grav installation. |
| Exploit 2h ago | 8.5 | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled. |
| Exploit 2h ago | 8.8 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server. |
| 2h ago | 7.1 | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. |
| 2h ago | 7.6 | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. |
| 2h ago | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1. |
| 2h ago | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| 2h ago | 7.5 | Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. |
| 2h ago | 7.2 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| 2h ago | 7.5 | Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. |
| 2h ago | 7.1 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. |
| 2h ago | 7.5 | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. |
| 2h ago | 7.1 | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| 2h ago | 7.5 | Contributor Local File Inclusion in Vino <= 1.9 versions. |
| 2h ago | 7.5 | Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. |
| 2h ago | 7.6 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. |
| 2h ago | 8.5 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. |
| 2h ago | 8.5 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| 2h ago | 8.5 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. |
| 2h ago | 8.1 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files |
| 2h ago | 8.6 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session |
| Exploit 2h ago | 7.8 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration |
| Exploit 2h ago | 8.4 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter |
| Exploit 2h ago | 8.4 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling |
| Exploit 2h ago | 7.8 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration |
| Exploit 2h ago | 8.4 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter |