CVE Monitor Telegram channel photo

CVE Monitor

@CVEDetectorPublic Channel

CVE Monitor shares Cybersecurity updates and media on Telegram. Join to stay updated.

4.6k (4,615 subscribers)
Members
—
Rating
60
Total Posts
Sep 18, 2026, 7:56 PM
Updated
Apr 12, 2026
Created
Stats

You are viewing English content. To see content in other languages, change the language of the site.

Channel Information

Channel Information
Channel NameCVE Monitor
Username@CVEDetector
CategoryCybersecurity
LanguageEnglish
CountryUnited States
Members4,615
Channel TypePublic Channel
CreatedApr 12, 2026
Last UpdatedSep 18, 2026 • 8 days ago
StatusActive

Ranking

Global Ranking
#36373-22
Language Ranking
#7832-3
Category Ranking
#85No change

Participant Growth (Last 12 Days)

Total: 4.6K
24h growth: +79 2%
04/1205/0205/1907/0408/2109/0909/18

Top 10 posts

Most viewed posts from this channel

By views
  1. #1{20
  2. #2{20
  3. #3{19
  4. #4{16
  5. #5{15
  6. #6{15
  7. #7{12
  8. #8{11
  9. #9{7.0
  10. #10{6.0

Latest Posts

CVE Monitor

Sep 06, 2026, 16:05

{
"Source": "CVE FEED",
"Title": "CVE-2026-84219 - Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding",
"Content": "CVE ID :CVE-2026-84219
Published : Sept. 6, 2026, 6 a.m. | 1 hour, 22 minutes ago
Description :The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Sep 2026",
"Type": "Vulnerability"
}
🔹 🔹
12000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": "CVE FEED",
"Title": "CVE-2026-75793 - SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login",
"Content": "CVE ID :CVE-2026-75793
Published : Sept. 6, 2026, 6 a.m. | 1 hour, 22 minutes ago
Description :The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Sep 2026",
"Type": "Vulnerability"
}
🔹 🔹
4000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": "CVE FEED",
"Title": "CVE-2026-84028 - Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settings",
"Content": "CVE ID :CVE-2026-84028
Published : Sept. 6, 2026, 6 a.m. | 1 hour, 22 minutes ago
Description :The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Sep 2026",
"Type": "Vulnerability"
}
🔹 🔹
6000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": "CVE FEED",
"Title": "CVE-2026-86170 - DefaultFuction CRM edit.php sql injection",
"Content": "CVE ID :CVE-2026-86170
Published : Sept. 6, 2026, 6:16 a.m. | 1 hour, 5 minutes ago
Description :A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Sep 2026",
"Type": "Vulnerability"
}
🔹 🔹
3000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": "CVE FEED",
"Title": "CVE-2026-86171 - DefaultFuction CRM delete.php sql injection",
"Content": "CVE ID :CVE-2026-86171
Published : Sept. 6, 2026, 6:15 a.m. | 1 hour, 7 minutes ago
Description :A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "06 Sep 2026",
"Type": "Vulnerability"
}
🔹 🔹
3000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": " https://github.com/atiilla/CVE-2026-27876",
"Title": "CVE-2026-27876 (2026-03-27) atiilla/CVE-2026-27876",
"Content": "A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path.

Only instances with the sqlExpressions feature toggle enabled are vulnerable.[GitHub]Grafana SQL Expressions Arbitrary File Write to RCE",
"Detection Date": "06 Sep 2026",
"Type": "Exploit POC"
}
🔹 🔹
4000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": " https://github.com/athosgonzaga/CVE-2021-3030",
"Title": "athosgonzaga/CVE-2021-3030",
"Content": "[GitHub]Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx",
"Detection Date": "06 Sep 2026",
"Type": "Exploit POC"
}
🔹 🔹
3000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": " https://github.com/juanpoch/CVE-2026-73570",
"Title": "juanpoch/CVE-2026-73570",
"Content": "[GitHub]Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)",
"Detection Date": "06 Sep 2026",
"Type": "Exploit POC"
}
🔹 🔹
5000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": " https://github.com/eddinos2/CVE-2026-28956-jxl-messages-surface",
"Title": "CVE-2026-28956 (2026-05-11) eddinos2/CVE-2026-28956-jxl-messages-surface",
"Content": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.[GitHub]JPEG XL auto-decodes in the iOS Messages preview path — delivery-surface finding for CVE-2026-28956 (AppleJPEGXL), with patch-diff attribution (libjxl 0.10.4->0.10.5) and an honest reliability check on the public PoC.",
"Detection Date": "06 Sep 2026",
"Type": "Exploit POC"
}
🔹 🔹
3000
CVE Monitor

Sep 06, 2026, 16:05

{
"Source": " https://github.com/0xlyvio/CVE-2020-10770-keycloak-exploit-poc",
"Title": "CVE-2020-10770 (2020-12-16) 0xlyvio/CVE-2020-10770-keycloak-exploit-poc",
"Content": "A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.[GitHub]Keycloak Blind SSRF POC",
"Detection Date": "05 Sep 2026",
"Type": "Exploit POC"
}
🔹 🔹
6000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76400 - Denial of Service (DoS) through the REST API in Splunk Connect for Kafka",
"Content": "CVE ID :CVE-2026-76400
Published : Aug. 19, 2026, 9:35 p.m. | 24 minutes ago
Description :In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches until event delivery stops. The vulnerability is possible because HTTP Event Collector delivery retry handling uses an unbounded default for failed batches instead of a finite retry limit. For more information see Install Splunk Connect for Kafka (), Data ingestion parameters for Splunk Connect for Kafka (), and Set up and use HTTP Event Collector with configuration files () in the Splunk documentation.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
1000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76401 - Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka",
"Content": "CVE ID :CVE-2026-76401
Published : Aug. 19, 2026, 9:35 p.m. | 24 minutes ago
Description :In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the affected connector. The vulnerability is possible because timestamp extraction evaluates customer-supplied regular expressions without a time limit. For more information see Install Splunk Connect for Kafka () and Data ingestion parameters for Splunk Connect for Kafka () in the Splunk documentation.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
2000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76399 - Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit",
"Content": "CVE ID :CVE-2026-76399
Published : Aug. 19, 2026, 9:35 p.m. | 25 minutes ago
Description :In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
1000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76402 - Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka",
"Content": "CVE ID :CVE-2026-76402
Published : Aug. 19, 2026, 9:35 p.m. | 24 minutes ago
Description :In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials to an attacker-controlled server, allowing for exposure of credentials that compromise all relevant data sent through the connector and limited alteration of event delivery. The vulnerability is possible because HTTP Event Collector endpoint validation does not require secure transport by default. For more information see Install Splunk Connect for Kafka (), Data ingestion parameters for Splunk Connect for Kafka (), and Set up and use HTTP Event Collector with configuration files () in the Splunk documentation.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
2000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76403 - Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka",
"Content": "CVE ID :CVE-2026-76403
Published : Aug. 19, 2026, 9:35 p.m. | 24 minutes ago
Description :In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka (), Security configurations for Splunk Connect for Kafka (), and Set up and use HTTP Event Collector with configuration files () in the Splunk documentation.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
1000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-63123 - Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root",
"Content": "CVE ID :CVE-2026-63123
Published : Aug. 19, 2026, 9:41 p.m. | 18 minutes ago
Description :Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/ https://t.me/tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/ https://t.me/tinacms/cli/src/next/vite/plugins.ts still routes POST /media/upload/* to mediaRouter.handlePost. The upload code in packages/ https://t.me/tinacms/cli/src/next/commands/dev-command/server/media.ts writes attacker-controlled multipart contents inside the configured media root. A remote attacker can cause a developer's browser to submit this state-changing request by inducing the developer to visit an attacker-controlled page while tinacms dev is running. This issue is fixed in version 2.5.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
3000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76405 - Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app",
"Content": "CVE ID :CVE-2026-76405
Published : Aug. 19, 2026, 9:35 p.m. | 24 minutes ago
Description :In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store () in the Splunk documentation.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
3000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76404 - Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app",
"Content": "CVE ID :CVE-2026-76404
Published : Aug. 19, 2026, 9:35 p.m. | 24 minutes ago
Description :In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
3000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76590 - TRENDnet TEW-755AP ssi wan.cgi stack-based overflow",
"Content": "CVE ID :CVE-2026-76590
Published : Aug. 19, 2026, 9:45 p.m. | 15 minutes ago
Description :A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wanpppoepassword_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
11000
CVE Monitor

Aug 20, 2026, 04:46

{
"Source": "CVE FEED",
"Title": "CVE-2026-76850 - LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector",
"Content": "CVE ID :CVE-2026-76850
Published : Aug. 19, 2026, 9:41 p.m. | 18 minutes ago
Description :LMDeploy deserializes disaggregated-serving peer messages with pickle. The handlezmqrecv coroutine in lmdeploy/pytorch/disagg/conn/engineconn.py reads peer-to-peer cache-free requests with recvpyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplies those bytes is caller-controlled: p2pconnect passes remoteengineendpointinfo.zmqaddress from the request body to connect() on the ZMQ PULL socket, and the POST /distserve/p2pinitialize and /distserve/p2pconnect endpoints in lmdeploy/serve/openai/apiserver.py apply no authentication unless the server is started with api_keys, which defaults to None. A remote attacker can direct an engine to pull from a ZMQ endpoint under their control and execute arbitrary code in the engine process. Deployments that do not enable disaggregated serving are not affected, because the receive loop is only started once the migration backend accepts the connection.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "20 Aug 2026",
"Type": "Vulnerability"
}
🔹 🔹
7000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-2554 - WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - authenticated (vendor+) insecure direct object reference to arbitrary user deletion",
"Content": "CVE ID :CVE-2026-2554
Published : May 2, 2026, 1:26 p.m. | 16 minutes ago
Description :The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via the 'wcfmdeletewcfm_customer' due to missing validation on the 'customerid' user controlled key. This makes it possible for authenticated attackers, with Vendor-level access and above, to delete arbitrary users, including Administrators.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
4000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-7630 - innocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper authentication",
"Content": "CVE ID :CVE-2026-7630
Published : May 2, 2026, 1:15 p.m. | 27 minutes ago
Description :A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 45758e4ec22451ab944ae2ae826b1e70f6450dc9. It is recommended to apply a patch to fix this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
5000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-0703 - NextMove Lite - Thank You Page for WooCommerce <= 2.23.0 - authenticated (contributor+) stored cross-site scripting via 'xlwctycurrentdate' shortcode",
"Content": "CVE ID :CVE-2026-0703
Published : May 2, 2026, 1:26 p.m. | 16 minutes ago
Description :The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwctycurrentdate' shortcode in all versions up to, and including, 2.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
6000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-3504 - Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - unauthenticated information disclosure in store reviews rest api endpoint",
"Content": "CVE ID :CVE-2026-3504
Published : May 2, 2026, 1:26 p.m. | 16 minutes ago
Description :The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'preparereviewsfor_response' method including reviewer email addresses, usernames, and user IDs in the API response. This makes it possible for unauthenticated attackers to extract email addresses, usernames, and user IDs of all customers who left reviews on any vendor's store. The Pro version of the plugin must be installed and activated, with store reviews enabled, in order to exploit the vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
5000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-7611 - TRENDnet TEW-821DAP Firmware Update cameodev.sh platformdoupgradecameo_dev data authenticity",
"Content": "CVE ID :CVE-2026-7611
Published : May 2, 2026, 10:16 a.m. | 1 hour, 25 minutes ago
Description :A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platformdoupgradecameodev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a manipulation results in insufficient verification of data authenticity. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
19000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-5077 - Total <= 2.2.1 - authenticated (contributor+) stored cross-site scripting via post title in blog section image alt attribute",
"Content": "CVE ID :CVE-2026-5077
Published : May 2, 2026, 10:16 a.m. | 1 hour, 25 minutes ago
Description :The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping when rendering the_title() inside HTML attribute context in the home blog section template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the malicious post to be published and displayed with a featured image in the Home Page blog section.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
20000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-6449 - Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - unauthenticated authorization bypass via remote approval endpoint",
"Content": "CVE ID :CVE-2026-6449
Published : May 2, 2026, 8:16 a.m. | 1 hour, 24 minutes ago
Description :The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
20000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-7627 - 8nite metatrader-4-mcp synceafrom_file index.ts CallToolRequestSchema path traversal",
"Content": "CVE ID :CVE-2026-7627
Published : May 2, 2026, 11:15 a.m. | 25 minutes ago
Description :A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component synceafromfile. Such manipulation of the argument eaname leads to path traversal. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
15000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-7612 - itsourcecode Courier Management System edit_user.php sql injection",
"Content": "CVE ID :CVE-2026-7612
Published : May 2, 2026, 10:16 a.m. | 1 hour, 25 minutes ago
Description :A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
15000
CVE Monitor

May 02, 2026, 20:40

{
"Source": "CVE FEED",
"Title": "CVE-2026-2052 - Widget Options <= 4.2.2 - authenticated (contributor+) remote code execution via display logic",
"Content": "CVE ID :CVE-2026-2052
Published : May 2, 2026, 8:16 a.m. | 1 hour, 24 minutes ago
Description :The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic expressions with an insufficient blocklist/allowlist that can be bypassed using arraymap with string concatenation, combined with a lack of authorization enforcement on the extendedwidgetoptsblock attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. The vulnerability was partially patched in version 4.2.0.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...",
"Detection Date": "02 May 2026",
"Type": "Vulnerability"
}
🔹 🔹
16000

Showing 30 of 60 posts

Rating

Login required

Frequently Asked Questions

What is the CVE Monitor Telegram channel about?+

CVE Monitor (@CVEDetector) is a Telegram channel in the Cybersecurity category. CVE Monitor shares Cybersecurity content on Telegram.

How do I join CVE Monitor (@CVEDetector) on Telegram?+

Open the channel profile on tgdio, then use the Join / Open in Telegram button to go to @CVEDetector in the Telegram app or web client and subscribe for free.

Is CVE Monitor a good Cybersecurity channel to follow?+

On tgdio you can check CVE Monitor's rating, user reviews, ranking, and latest posts before joining. It currently lists about 4,615 subscribers on tgdio. Compare it with similar Cybersecurity channels in the same category.

Where can I see CVE Monitor stats and latest posts?+

On tgdio, open the @CVEDetector channel page for subscriber stats, ranking, ratings, and recent posts. Use the Stats link on the profile for deeper growth and activity charts.