Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 1 April 2026

RSS

100 vulnerabilities published on 1 April 2026

Severity:
TinaCMS Media Endpoints Allow Unrestricted File Access
GHSA-g87c-r2jp-293w CVE-2026-34603
A vulnerability in TinaCMS's media endpoints allows attackers to access and modify files outside the intended media directory by creating symlinks or junctions. This can lead to unauthorized access to...
7.1
YesWiki allows attackers to inject malicious scripts into form titles
GHSA-37fq-47qj-6j5j CVE-2026-34598
Attackers can inject JavaScript code into form titles, which can be executed in the browser of any user who views the page. This can happen even if the attacker doesn't have an account. To fix this, t...
7.1
OpenClaw Gateway allows unauthorized session reset
GHSA-5r8f-96gm-5j6g
A security issue in OpenClaw Gateway allows an attacker with limited permissions to reset and take control of a session, even if they shouldn't have that power. This could be exploited by a malicious ...
7.1
Amelia Plugin for WordPress Exposed to Sensitive Data Theft via Payments
CVE-2026-4668
The Amelia plugin for WordPress, used to manage appointments and events, has a security flaw that could allow hackers to access sensitive information from the database. This issue affects all versions...
6.5
XenForo: Malicious scripts injected through profile post content
CVE-2026-35057
Legacy XenForo profile posts can allow attackers to inject malicious scripts, which can be executed when other users view the content. This could lead to unauthorized actions or data theft. Update to ...
5.1
XenForo 2.3.8 and earlier allows malicious scripts to be injected via BB code
CVE-2026-35054
If you use XenForo, make sure you're running version 2.3.9 or later. Earlier versions can be exploited by attackers to inject malicious code into your forum, which could harm users or steal sensitive ...
5.1
z-9527 Admin Software Can Be Tricked into Changing User Permissions
CVE-2026-5251
A security flaw in the z-9527 admin software allows an attacker to remotely manipulate user permissions. This could potentially allow unauthorized access to sensitive areas of the software. Users shou...
5.3
Gougucms 4.08.18 User Registration Handler Flaw Allows Remote Manipulation
CVE-2026-5248
A flaw in the user registration process of Gougucms 4.08.18 allows an attacker to manipulate data. This could be done from anywhere on the internet, and an exploit is already available. We recommend u...
5.3
Connext Professional allows data to be read beyond its intended boundaries
CVE-2026-2394
A security issue exists in Connext Professional, a software component used for data exchange, that could allow unauthorized access to sensitive data. This issue affects multiple versions of the softwa...
6.3
XenForo Software Allows Attackers to Redirect Users to Fake Sites
CVE-2024-58342
XenForo software versions 2.2.17 and earlier, as well as 2.3.1, can redirect users to any website by entering a specially crafted URL. This could trick users into visiting fake or malicious sites. To ...
5.3
Adobe Acrobat crashes when processing malicious PDFs with loops
CVE-2026-3778
Adobe Acrobat can crash when processing certain PDF files with a specific type of loop. This can happen if attackers craft a PDF with malicious JavaScript code that refers to itself in a loop. To stay...
6.2
XenForo shared systems may expose user info to others on the same computer
CVE-2025-71280
If multiple people share a computer or browser, sensitive user information may be visible to others. This is because the information is stored in the browser cache. To fix this, update XenForo to vers...
6.9
XenForo Forum: Malicious Scripts Can Execute When Users Click on Posts
CVE-2026-35055
If you use XenForo, an attacker could inject malicious code into posts that execute when users interact with them. This can lead to unauthorized actions or data theft. Update to XenForo 2.3.9 or 2.2.1...
5.1
Outdated Cache Pointers Can Leak Sensitive Data or Crash Safari
CVE-2026-3777
Safari's internal cache can be exploited by malicious JavaScript, potentially leading to data exposure or a browser crash. Affected users should update to the latest version of Safari to ensure their ...
5.5
Adobe Acrobat Reader crashes when opening malformed PDFs
CVE-2026-3776
Adobe Acrobat Reader may crash if it's opened with a malicious PDF that's missing required data, which could disrupt business operations. This issue affects PDF file handling in Adobe Acrobat Reader. ...
5.5
YesWiki: Malicious JavaScript can be injected via URLs
GHSA-5724-x3rh-5qqq
YesWiki has a security flaw that allows malicious code to be injected into a user's browser when they visit a specially crafted URL. This could lead to unauthorized access to sensitive information or ...
5.3
Parse Server: Authenticated users can access sensitive data
CVE-2026-34595 GHSA-mmg8-87c5-jrc2
An authenticated user with permission to view certain data may be able to access protected fields in Parse Server. This could allow them to gain information they shouldn't have. Update to version 8.6....
5.3
Authenticated users can extend or bypass session expiration in Parse Server
CVE-2026-34574 GHSA-f6j3-w9v3-cq22
If you're using an outdated version of Parse Server, an authenticated user might be able to keep their session active forever. This is a security risk because it could allow unauthorized access to you...
5.3
Adobe Acrobat allows hidden data to remain in printed PDFs
CVE-2026-3774
Adobe Acrobat's PDF editing features can leave sensitive information in printed documents or allow it to remain visible on screen. This can happen when editing or redacting sensitive documents, and it...
4.7
WordPress Plugins Can Be Hacked to Steal Form Data
CVE-2026-3831
If you use the Contact Form 7, WPforms, or Elementor forms plugin on your WordPress site, an attacker with high-level access can steal sensitive information like names, emails, and phone numbers from ...
4.3
BloodBank Managing System 1.0: Admin Panel Cross-Site Scripting Risk
CVE-2026-5240
An attacker can inject malicious code into the BloodBank Managing System 1.0 admin panel, potentially taking control of it. This could allow them to access sensitive information, delete data, or disru...
5.3
Cross-Site Scripting in Gougucms 4.08.18 Can Steal User Data
CVE-2026-5249
A security weakness in the Gougucms 4.08.18 system makes it possible for hackers to inject malicious code into the site, potentially allowing them to steal user data or take control of the site. This ...
5.1
OpenClaw Image Download Allows Access to Internal URLs
GHSA-qxgf-hmcj-3xw3
A vulnerability in OpenClaw's image download feature allows a malicious FAL relay to access internal URLs and potentially expose sensitive metadata or service responses. This affects OpenClaw versions...
2.3
MINI-wxqm-7q3c-m5x4
MINI-wxqm-7q3c-m5x4
MINI-xj84-c6xc-6p6h
MINI-xj84-c6xc-6p6h