| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
| In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
| In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS |
| In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible |
| In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
| In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
| In JetBrains YouTrack before 2026.2.18788,
2026.1.14055,
2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |
| In JetBrains YouTrack before 2025.3.161254,
2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
| A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 |
| Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. |
| PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions |
| Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery.
This issue affects Hide My WP Ghost: from n/a through 7.0.09. |
| Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS.
This issue affects Easy Appointments: from n/a through 4.0.2.1. |
| Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions. |
| Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8. |
| Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Unbounce Landing Pages: from n/a through 1.1.4. |