Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 8 April 2026
RSS714 vulnerabilities published on 8 April 2026
Severity:
VK All in One Expansion Unit allows hackers to inject malicious code
CVE-2026-39483
A security issue in VK All in One Expansion Unit allows hackers to inject malicious code into the website, which can cause problems for users. This issue affects all versions of VK All in One Expansio...
PublishPress Post Expirator allows hackers to inject malicious code into web pages
CVE-2026-39482
A security flaw in PublishPress Post Expirator allows hackers to inject malicious code into web pages, potentially allowing them to steal data or take control of your website. This affects all version...
Brainstorm Force OttoKit suretriggers: Blind SQL Injection Risk
CVE-2026-39479
The Brainstorm Force OttoKit suretriggers feature is vulnerable to a type of hacking attack that can reveal sensitive information. This vulnerability affects versions of OttoKit from unknown to 1.1.20...
CartFlows Missing Access Control Security Puts Sensitive Data at Risk
CVE-2026-39477
An outdated version of CartFlows has a security weakness that allows unauthorized access to sensitive data. If not updated, this could lead to an attacker accessing sensitive data, potentially causing...
User Feedback: Unauthorized Access to User Data
CVE-2026-39476
A security issue in User Feedback allows unauthorized users to access sensitive data. This is a problem because it means that sensitive user information could be accessed without permission. To fix th...
User Feedback software vulnerable to hacking through user input
CVE-2026-39475
A serious security flaw in User Feedback software allows attackers to access sensitive data by manipulating user input. This could lead to unauthorized access to user information and potentially compr...
Simple History Allows Access to Sensitive Data
CVE-2026-39473
The Simple History plugin for WordPress allows sensitive information to be embedded in data sent to users. If not handled properly, this can lead to sensitive data being accessed by unauthorized users...
PageLayer: Sensitive System Info Leaked to Unauthorized Users
CVE-2026-39469
A security weakness in PageLayer versions 2.0.8 and earlier allows unauthorized users to access sensitive system information. This could potentially allow attackers to gain more information about your...
WPMU DEV Broken Link Checker SQL Injection Risk
CVE-2026-39466
A security flaw in WPMU DEV's Broken Link Checker plugin on WordPress platforms could allow hackers to access sensitive data. This affects versions 2.4.7 and earlier, so update to the latest version t...
SeedProd Coming Soon Page allows hackers to make unauthorized requests
CVE-2026-39464
A security issue in SeedProd's Coming Soon Page plugin allows hackers to make fake requests to any website, potentially stealing sensitive information or taking control of other sites. This affects ve...
CGA-7gjr-qqqx-hw42
CGA-7gjr-qqqx-hw42
CGA-7gjr-qqqx-hw42
lodash for Root:npm allows arbitrary code execution
ROOT-APP-NPM-CVE-2026-4800
The lodash library for Root's npm package has been patched to prevent malicious code from being executed. This library is used by various Root applications, so it's essential to update to the latest v...
Nix Package Manager Allows Malicious Files to be Overwritten on Linux Systems
DEBIAN-CVE-2026-39860
A bug in the Nix package manager for Linux allows malicious users to overwrite files on the system. This could give them root access to the system if the Nix daemon is running as root. To fix this, up...
WordPress ActivityPub Plugin Allows Access to Private Posts
CVE-2026-4338
The WordPress ActivityPub plugin has a security issue that allows anyone, even without a login, to view posts that are not yet published. This means sensitive or draft content might be exposed. Update...
rootio-linux: Unpatched Root Access via Unrestricted File Creation
ROOT-OS-UBUNTU-2204-CVE-2025-38377
A security issue in rootio-linux could allow an attacker with certain privileges to create arbitrary files, potentially leading to root access on a system running rootio-linux. This vulnerability was ...
rootio-linux: Unpatched Root Access via Exploit Possible
ROOT-OS-UBUNTU-2204-CVE-2023-53383
A critical security patch has been released for rootio-linux, which allows an attacker to potentially gain unauthorized root access to your system if not updated. You should update to the latest versi...
rootio-linux: Unauthenticated Command Injection via SFTP
ROOT-OS-UBUNTU-2204-CVE-2026-22979
The rootio-linux package has a security issue that allows an attacker to execute unauthorized commands over a network connection. This could lead to unauthorized access to the system. The issue has be...
rootio-linux: Unauthorized Access via Malicious Network Requests
ROOT-OS-UBUNTU-2204-CVE-2025-39693
The rootio-linux package for Ubuntu 22.04 has a security issue that could allow an attacker to access your system without permission. This means an unauthorized person could gain control over your sys...
rootio-linux: Unauthorized Access to System Configuration
ROOT-OS-UBUNTU-2204-CVE-2023-54323
An update has been released to fix a security issue in the rootio-linux package on Ubuntu 22.04. This issue could allow unauthorized access to system configuration, potentially leading to unintended c...
CVE-2023-53421 in rootio-linux - Patched by Root
ROOT-OS-UBUNTU-2204-CVE-2023-53421
Root has patched CVE-2023-53421 in the rootio-linux package for Root:Ubuntu:22.04. Multiple fixed versions available.
CVE-2025-68794 in rootio-linux - Patched by Root
ROOT-OS-UBUNTU-2204-CVE-2025-68794
Root has patched CVE-2025-68794 in the rootio-linux package for Root:Ubuntu:22.04. Multiple fixed versions available.
rootio-linux: Unauthorized access to sensitive data possible
ROOT-OS-UBUNTU-2204-CVE-2025-21927
If exploited, a hacker might gain access to sensitive data on a Root:Ubuntu:22.04 system. Root has released a patch to fix this issue. Update your rootio-linux installation to the latest version to pr...
rootio-linux: Unpatched Linux System May Be Compromised
ROOT-OS-UBUNTU-2204-CVE-2022-49533
A security patch has been released for an issue in the rootio-linux package. This affects Linux systems running Root:Ubuntu:22.04. If left unpatched, it could potentially allow unauthorized access to ...
rootio-linux: Unauthenticated Access to Sensitive Data on Ubuntu 22.04
ROOT-OS-UBUNTU-2204-CVE-2025-39715
A security patch has been released for the rootio-linux package on Ubuntu 22.04. This patch fixes an issue where an attacker could potentially access sensitive data without being authenticated. To sta...