Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 8 April 2026
RSS716 vulnerabilities published on 8 April 2026
Severity:
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affect...
CVE-2026-39636
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Stored XSS.This issue affects L...
Grand Portfolio allows hackers to trick users into making unintended changes
CVE-2026-39634
A flaw in Grand Portfolio allows hackers to trick users into making unintended changes to the website. This can lead to unauthorized actions being taken on the user's account. Users and administrators...
Grand Blog: Unauthorized Actions through Malicious Links
CVE-2026-39632
A security weakness in Grand Blog software makes it possible for attackers to trick users into performing unintended actions on the site. This could happen if a user clicks on a malicious link or open...
WPSchoolPress: Insecure Access Control Lets Hackers Access Sensitive Data
CVE-2026-39631
WPSchoolPress, a plugin for WordPress, has a security weakness that lets hackers access sensitive data if the access control settings are not correctly set. This means that sensitive information could...
Getty Images Getty Images allows attackers to make unauthorized requests on your behalf
CVE-2026-39630
Getty Images has a security issue that allows attackers to trick your server into making requests to unintended websites. This could lead to data theft or other malicious activity. Update Getty Images...
Uminex: Malicious Code Can Be Injected into Uminex Web Pages
CVE-2026-39629
A security weakness in Uminex allows hackers to inject malicious code into web pages, potentially compromising user data and security. This issue affects all versions of Uminex up to and including 1.0...
DukaMarket: Hackers can inject malicious code into your website
CVE-2026-39628
A security issue in DukaMarket allows hackers to inject code into your website, potentially stealing sensitive information or taking control of your site. This issue affects DukaMarket versions up to ...
Ashe: Unauthorized Access Due to Incorrect Security Settings
CVE-2026-39627
A missing security feature in Ashe can let attackers access sensitive areas of your website or application without permission. This affects Ashe software versions up to 2.266. To fix, update to a newe...
Armania Theme Allows Malicious Code to Run
CVE-2026-39626
A security issue in the Armania theme allows hackers to inject malicious code into web pages, potentially stealing user data or taking control of the site. This issue affects the Armania theme for web...
TechOne Website May Inject Malicious Code
CVE-2026-39625
A security issue in TechOne, a website theme, could allow an attacker to inject malicious code into TechOne websites. This could happen when a user visits a specially crafted website, potentially allo...
Biolife Theme Missing Authorization Risk
CVE-2026-39624
A misconfigured access control setting in Biolife theme versions 3.2.3 and earlier allows unauthorized access. This means that users may be able to access or modify sensitive data without proper permi...
PHP Files Can Be Accessed Without Permission on Biolife Websites
CVE-2026-39623
A security issue in Biolife, a theme for websites, allows unauthorized access to files on the website. This could allow attackers to view or modify sensitive information. To protect your website, upda...
Education Base: Unsecured Access to Important Data Possible
CVE-2026-39622
The Education Base software has a security weakness that allows unauthorized access to sensitive information. This means that if not set up correctly, users might be able to access data they shouldn't...
SpicePress: Unsecured Upload Allows Malicious File Upload
CVE-2026-39621
An attacker can trick users into uploading a malicious file to a SpicePress website, potentially allowing them to take control of the server. This issue affects all versions of SpicePress up to 2.3.2....
Appointment <= 3.5.5 allows attackers to upload malicious files to the server
CVE-2026-39620
A security weakness in Appointment software allows hackers to upload unauthorized files to a web server. This could lead to the server being taken over or used to spread malware. Update to Appointment...
Busiprof Web Shell Upload Risk: Unsecured File Upload
CVE-2026-39619
An attacker can upload malicious files to a Busiprof web server, potentially allowing them to take control of the server. This is a serious risk because it allows an attacker to execute arbitrary code...
NewsExo allows hackers to trick users into performing actions
CVE-2026-39618
A security issue in NewsExo allows an attacker to trick users into performing unintended actions on the website. This could lead to unauthorized changes or data loss. To protect against this, update N...
Incorrect Access Control in dFactory Download Attachments
CVE-2026-39616
A security issue in dFactory Download Attachments allows unauthorized access to sensitive files if access controls are not properly set. This affects all versions up to 1.4.0. Update to the latest ver...
JW Player for WordPress: Unsecured Access to Videos
CVE-2026-39614
Some settings in JW Player for WordPress are not properly locked down, which means an attacker could potentially access unauthorized videos. This affects JW Player for WordPress versions up to 2.3.6. ...
KuteShop 4.2.9 and earlier: Insecure Access Control
CVE-2026-39612
KuteShop, an e-commerce platform, has a security issue that could allow unauthorized access to sensitive areas of the website. This could happen if access control settings are not properly configured,...
Unrestricted Access to WpXmas-Snow with Incorrect Security Settings
CVE-2026-39610
An outdated version of WpXmas-Snow may allow an attacker to access sensitive areas of the system without proper permission. This could lead to unauthorized changes or data breaches. Update WpXmas-Snow...
iPOSpays Gateway WC: Incorrect Access Control Exposes Sensitive Data
CVE-2026-39608
The iPOSpays Gateway WC has a security weakness that could allow unauthorized access to sensitive information. If not configured properly, users may be able to view or manipulate data they shouldn't b...
BizReview fails to check user access levels, allowing unauthorized access
CVE-2026-39606
A bug in BizReview means that users with incorrect access settings can access areas they shouldn't. This could lead to unauthorized changes or data access. Upgrade to the latest version of BizReview t...
MyBookTable Bookstore allows hackers to inject malicious code
CVE-2026-39604
A security issue in MyBookTable Bookstore software allows hackers to inject malicious code into the website, which can be used to steal user data or take control of accounts. This affects versions 1 t...
Rustaurius Order Tracking: Incorrect Access Control Exposes Order Data
CVE-2026-39602
The Rustaurius Order Tracking software has a security issue that could allow unauthorized access to order data. This is because the access control settings are not properly configured, which means tha...