{"resultsPerPage":11,"startIndex":0,"totalResults":11,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-11T11:50:45.739","vulnerabilities":[{"cve":{"id":"CVE-2026-104732","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T04:18:08.493","lastModified":"2026-10-10T04:18:08.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error branch in the function unconditionally mints a fresh `advaipbl-2fa-interim-{user_id}` nonce and delivers it in a `Location` header to any unauthenticated caller, after which `display_2fa_login_form_step_2()` renders a valid `advaipbl-2fa-verify-{user_id}` nonce in HTML — both nonces computed against a fixed `uid=0` empty-session context and therefore fully reusable by the attacker across subsequent requests. This makes it possible for unauthenticated attackers to bypass authentication entirely for any 2FA-enabled account, including administrators, by brute-forcing an unthrottled 6-digit TOTP code (no attempt counter, no account lockout, and no `wp_login_failed` firing) and receiving a fully authenticated session cookie via `wp_set_auth_cookie` without ever supplying the account password, resulting in complete site takeover. Exploitation requires only a known `user_id` for an account that has the plugin's 2FA feature enabled."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"inilerm","product":"Advanced IP Blocker","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"8.13.13","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-2fa-manager.php#L71","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-main.php#L519","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-main.php#L6875","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-main.php#L6912","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/advanced-ip-blocker/tags/8.13.13/includes/class-advaipbl-main.php#L7022","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3725139/advanced-ip-blocker/trunk/includes/class-advaipbl-main.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d080845b-6814-4b10-a3ab-1f5aa1d09132?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-107645","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T04:18:10.090","lastModified":"2026-10-10T04:18:10.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set_customer_auth_cookie(). This makes it possible for unauthenticated attackers to elevate their privileges to a Dokan 'seller' (vendor) account — including sites where the Dokan vendor signup is explicitly turned off — and to be auto-authenticated into that account, which grants publishing capabilities beyond those of a normal customer."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"creativethemeshq","product":"Blocksy Companion","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.1.58","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L181","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L24","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.1.58/framework/features/account-auth.php#L241","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3735192/blocksy-companion/tags/2.1.59/framework/features/account-auth.php?old=3723693&old_path=blocksy-companion%2Ftags%2F2.1.58%2Fframework%2Ffeatures%2Faccount-auth.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7757f41d-c1f1-4df1-8048-b1c78a897548?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-94589","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T04:18:19.713","lastModified":"2026-10-10T04:18:19.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"htplugins","product":"Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.4.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/admin/include/class.cf7-signature.php#L222","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/admin/include/class.cf7-signature.php#L82","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/includes/class.cf7-extensions.php#L289","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/extensions-for-cf7/tags/3.4.5/includes/class.form-data-store.php#L42","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3727009/extensions-for-cf7/trunk/admin/include/class.cf7-signature.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3727009%40extensions-for-cf7%2Ftags%2F3.4.6&old=3672142%40extensions-for-cf7%2Ftags%2F3.4.5","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fa3193c4-dd3e-4d9e-be42-769c7358beae?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-103889","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T05:16:39.130","lastModified":"2026-10-10T05:16:39.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthenticated attackers to execute code on the server. The only nonce and authentication check in the handler is entirely enclosed in a block comment with no replacement, making the endpoint reachable via a single unauthenticated POST to any URL on the site."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"expivi","product":"3D Product configurator for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.16.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/pdf/class-pdf.php#L34","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/woocommerce/class-expivi-cart-manager.php#L212","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/woocommerce/class-expivi-cart-manager.php#L238","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/woocommerce/class-expivi-cart-manager.php#L598","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/woocommerce/class-expivi-cart-manager.php#L95","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/templates/pdf/pdf-configuration-details.phtml#L199","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3723323%40expivi&new=3723323%40expivi","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/46f69f7b-6d9b-494d-b123-63fc5ebcb6f3?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-97670","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T05:16:40.850","lastModified":"2026-10-10T05:16:40.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data token; the 3.16.1 trust gate is_content_request_supplied() only inspects $_POST['args']/$_GET['args'], never the $_POST['formData'] the public form-submit endpoint parses). This makes it possible for unauthenticated attackers to invoke arbitrary WordPress action hooks (multiple per request), causing state changes up to permanent, irreversible destruction of site content: a verified unauthenticated request permanently deleted trashed posts, pages, and comments via the core wp_scheduled_delete action. Other non-deny-listed hooks extend the impact to denial of service (e.g. wp_maybe_auto_update) and, where vulnerable third-party handlers are installed, further privileged writes. The same unauthenticated dynamic-data pipeline additionally exposes a blind arbitrary user/post-meta read; the read result is delivered only to the site owner and is not attacker-exfiltrable through the plugin's own email/response paths. Exploitation requires a published Avada form with AJAX submission and a notification whose email_message template includes an [all_fields] or explicit [field] placeholder - the default form configuration."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"themefusion","product":"Avada (Fusion) Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.16.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://avada.com/blog/version-7-16-2-security-update/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e2c00795-c49b-4b0a-8f0a-4ed18c966c6b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-104801","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T07:16:40.560","lastModified":"2026-10-10T07:16:40.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved byte-identically into the publicly accessible wp-content/uploads/ppom_files/confirmed/ directory, meaning the attack also results in arbitrary file read for any web-readable file on the server."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"themeisle","product":"PPOM – Product Addons & Custom Fields for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"34.0.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-product-addon/tags/34.0.10/src/Files/Handler.php#L738","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-product-addon/tags/34.0.10/src/Support/Helpers.php#L224","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-product-addon/tags/34.0.10/src/WooCommerce/Cart/CartHandler.php#L369","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-product-addon/tags/34.0.10/src/WooCommerce/Order/OrderHandler.php#L287","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3733313/woocommerce-product-addon/trunk/src/WooCommerce/Order/OrderHandler.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/650b510f-dc13-4ba4-af68-187f516b3051?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-104803","sourceIdentifier":"security@wordfence.com","published":"2026-10-10T08:17:04.210","lastModified":"2026-10-10T08:17:04.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store, allowing an unauthenticated attacker to issue a crafted GET request that writes an attacker-named, attacker-valued entry into the global session namespace (bypassing the per-visitor prefix by prepending an underscore), then issue a second GET request triggering `weapp_new_user()` to read that forged entry and resolve the attacker-supplied `openid` value to a bound WordPress account before `wp_set_auth_cookie()` establishes a fully authenticated session. This makes it possible for unauthenticated attackers to log in as any WordPress user — including administrators — whose bound social provider identifier (openid/unionid) is known or discoverable. Successful exploitation requires that the target site has at least one social provider configured (which activates the vulnerable handler) and that the attacker knows or can enumerate the victim account's bound openid or unionid."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"whyun","product":"WPCOM Member","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.7.27","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/class-sesstion.php#L13","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L1235","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L674","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.7.27/includes/social-login.php#L91","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpcom-member/trunk/includes/social-login.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3dee7f76-bd66-4e54-8ef6-bbf581ebcc11?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-108551","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-10-10T15:16:58.273","lastModified":"2026-10-10T15:16:58.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are imported or service methods called."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ferdikoomen","product":"openapi-typescript-codegen","defaultStatus":"unaffected","packageURL":"pkg:npm/openapi-typescript-codegen","versions":[{"version":"0","lessThanOrEqual":"0.31.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/ferdikoomen/openapi-typescript-codegen","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ferdikoomen/openapi-typescript-codegen/blob/v0.31.0/src/templates/core/OpenAPI.hbs#L20-L23","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ferdikoomen/openapi-typescript-codegen/blob/v0.31.0/src/templates/exportService.hbs#L89-L110","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ferdikoomen/openapi-typescript-codegen/issues/2809","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openapi-typescript-codegen-through-0.31.0-code-injection-via-handlebars-templates","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-108598","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-10-10T19:16:58.347","lastModified":"2026-10-10T19:16:58.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"floci-io","product":"floci","defaultStatus":"unaffected","repo":"https://github.com/floci-io/floci","packageURL":"pkg:github/floci-io/floci","versions":[{"version":"1.1.0","lessThan":"2.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/floci-io/floci","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floci-io/floci/blob/560b3e4aae61cea3ac7d4d51843bdffd0e3085fd/src/main/java/io/github/hectorvent/floci/services/apigateway/VtlTemplateEngine.java#L74-L114","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floci-io/floci/commit/144b90e6fa861a5ac882e99a090d503da01945c4","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floci-io/floci/releases/tag/2.2.0","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floci-io/floci/security/advisories/GHSA-3p4c-wp7w-mgjx","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ghostx-86/exploitarium/tree/main/floci-apigateway-vtl-rce-poc","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/floci-1.1.0-before-2.2.0-rce-via-api-gateway-vtl-mapping-templates","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-108707","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-10-11T02:16:39.477","lastModified":"2026-10-11T02:16:39.477","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WuKongOpenSource","product":"Wukong_HRM","defaultStatus":"unaffected","repo":"https://github.com/WuKongOpenSource/Wukong_HRM","packageURL":"pkg:github/WuKongOpenSource/Wukong_HRM","versions":[{"version":"0","lessThanOrEqual":"186115e1a5a0b827ad9596ff8c2f3a876fb0cc55","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/Wukong_HRM/poc_attachment_download_idor.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/Wukong_HRM/poc_employee_export_pii.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/Wukong_HRM/poc_salary_slip_detail_read.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WuKongOpenSource/Wukong_HRM/blob/186115e1a5a0b827ad9596ff8c2f3a876fb0cc55/common/common-web/src/main/java/com/kakarote/core/config/ParamAspect.java#L35-L55","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WuKongOpenSource/Wukong_HRM/blob/186115e1a5a0b827ad9596ff8c2f3a876fb0cc55/hrm/hrm-web/src/main/java/com/kakarote/hrm/common/EmployeeAspect.java#L28-L45","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wukong-hrm-through-commit-186115e-authentication-bypass-via-paramaspect","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-108540","sourceIdentifier":"cna@vuldb.com","published":"2026-10-11T07:17:23.303","lastModified":"2026-10-11T07:17:23.643","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"OpenSpug","product":"Spug","cpes":["cpe:2.3:a:openspug:spug:*:*:*:*:*:*:*:*"],"modules":["File Transfer"],"versions":[{"version":"3.0","status":"affected"},{"version":"3.1","status":"affected"},{"version":"3.2","status":"affected"},{"version":"3.3","status":"affected"},{"version":"3.4.0","status":"affected"},{"version":"4.0.0","status":"affected"},{"version":"4.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-77"},{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/SECWG/CVE/issues/10","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-108540","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/948328","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/416195","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/416195/cti","source":"cna@vuldb.com"}]}}]}