Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 8 April 2026

RSS

689 vulnerabilities published on 8 April 2026

Severity:
rfc3161-client Fails to Properly Verify Digital Signatures
GHSA-3xxc-pwj6-jgrj CVE-2026-33753
An attacker can impersonate a trusted TimeStamping Authority by manipulating digital certificates, allowing them to bypass authorization checks. This can lead to unauthorized access or actions. Update...
6.2
WordPress Gravity Forms plugin exposes sensitive data to attackers
CVE-2026-4394
The Gravity Forms plugin for WordPress has a security flaw that allows attackers to inject malicious code into form entries. This can lead to unauthorized access to sensitive information when an admin...
6.1
Brecht Visual Link Preview allows hackers to access internal servers
CVE-2026-39670
A bug in Brecht Visual Link Preview's preview feature lets attackers access internal servers and data. This affects versions of the software up to 2.3.0. Update to the latest version to fix the issue.
6.0
Axios HTTP/2 Session Crash via Malicious Server
CVE-2026-39865 GHSA-qj83-cq47-w5f8
Using Axios with HTTP/2 before version 1.13.2 can cause a client crash if a malicious server closes multiple sessions at the same time. To fix this, update Axios to version 1.13.2 or later. If you can...
5.9
NiceGUI: Malicious Files Can Be Written to Wrong Folders on Windows
GHSA-w8wv-vfpc-hw2w CVE-2026-39844
Some NiceGUI applications on Windows may allow attackers to write files to unintended locations, potentially leading to data loss, data corruption, or even code execution. This happens when malicious ...
5.9
CoolerControl: Unauthenticated Data Exposure and Modification
CVE-2026-5300
The CoolerControl software allows anyone to access and change sensitive information without needing a password. This means unauthorized users can view and alter data that might be meant for authorized...
5.9
AWS SDK for Go v2 Crashes from Malformed EventStream Response
GHSA-xmrv-pmrh-hhx2
A malicious response from AWS can cause the Go SDK to crash, potentially disrupting services. This issue affects older versions of the AWS SDK for Go v2. To fix it, update to the latest version of the...
5.9
AWS SDK for Go v2 Can Crash from Malformed Response
GHSA-xmrv-pmrh-hhx2
The AWS SDK for Go v2 can crash if it receives a malformed response from a server. This can happen if a malicious actor sends a specially crafted response. To fix this, update to the latest version of...
5.9
Hono: Malicious Files Can Be Written Outside the Output Directory
GHSA-xf4j-xp2r-rqqx CVE-2026-39408
A security issue affects the Hono framework, allowing attackers to write files outside the intended output directory during static site generation. This could lead to unintended files being overwritte...
5.9
GitLab EE: Authenticated User Can Leak Viewer IP Addresses
CVE-2026-1516
A security issue was found in older versions of GitLab EE that could have allowed an authenticated user to see the IP addresses of others who viewed certain reports. If you're using one of these affec...
5.7
monetr: Protected Transactions Can Be Deleted via PUT Request
GHSA-hqxq-hwqf-wg83 CVE-2026-39901
An attacker can delete protected transactions by updating them via a PUT request, bypassing the intended protection. This allows them to hide transactions from normal views. To fix this, organizations...
5.7
InvenTree Inventory Management System: Malicious Template Injection
CVE-2026-35477
An attacker with staff permissions can craft a malicious template that executes arbitrary code when rendered. Affected are InvenTree versions 1.2.3 to 1.2.6. Update to 1.2.7 or 1.3.0 to fix this issue...
5.5
CodeIgniter CMS Skeleton: Unsanitized User Input in Page Content
CVE-2026-39392 GHSA-fjpj-6qcq-6pw2
An attacker with admin privileges can inject malicious JavaScript into page content, which will be executed on all visitors' browsers. This can lead to unauthorized access to sensitive information or ...
5.5
CodeIgniter CMS Skeleton Exposes Admins to Frontend JavaScript Injection
CVE-2026-39390 GHSA-x3hr-cp7x-44r2
An attacker with admin access can inject malicious JavaScript code into a Google Maps iframe, which executes when non-admin users visit the site. This allows the attacker to steal user data or take co...
5.5
Pretix 2025 API endpoint returns sensitive data
CVE-2026-5600 GHSA-wr8q-c73g-m7gp
A new API endpoint in Pretix 2025 exposes sensitive data about all events managed by the same organizer, allowing unauthorized users to access information they shouldn't have. This includes check-in e...
5.5
SourceCodester Pharmacy Management System: Uncontrolled Sales Quantity
CVE-2026-5812
The SourceCodester Pharmacy Product Management System 1.0 has a security issue that can be exploited remotely. An attacker can manipulate sales quantities, potentially causing unintended business logi...
5.3
SourceCodester Online Food Ordering System allows malicious price changes
CVE-2026-5811
A security issue in the SourceCodester Online Food Ordering System's save_product function could allow an attacker to manipulate product prices, potentially causing business logic errors. This vulnera...
5.3
GitLab EE: Unauthenticated users can execute malicious code in dashboards
CVE-2026-4332
GitLab has fixed a security issue in its Enterprise Edition that could have allowed users to inject malicious code into other users' browsers. This was possible in customizable analytics dashboards, a...
5.4
Hayabusa versions before 3.8.0 allow attackers to inject code into reports
CVE-2026-40028
If you use Hayabusa, an attacker could potentially inject malicious code into reports generated from exported logs, allowing them to steal sensitive information or take control of the examiner's sessi...
5.1
RT-Theme 18 Extension CSRF Attack Risk
CVE-2026-39710
A security weakness in the RT-Theme 18 Extensions allows hackers to trick users into performing unintended actions on your website. This could lead to unauthorized changes or data theft. To protect yo...
5.4
Grand Magazine allows attackers to make unauthorized changes
CVE-2026-39635
A security issue in Grand Magazine allows an attacker to trick users into performing actions on a website without their knowledge or consent. This means that an attacker could make changes to a user's...
5.4
WordPress Attendance Manager plugin leaks sensitive data due to SQL attack
CVE-2026-3781
The Attendance Manager plugin for WordPress, used in all versions up to 0.6.2, allows an attacker with a Subscriber account or higher to access sensitive information from the database. This is a serio...
5.4
AM LottiePlayer WordPress Plugin Allows Attackers to Inject Malicious Scripts in Uploaded SVG Files
CVE-2025-1794
The AM LottiePlayer plugin for WordPress is not properly checking some user-uploaded files, which means attackers with certain levels of access can inject malicious code into certain pages on your sit...
5.4
MATCHA SNS versions 1.3.9 and earlier allow malicious scripts to run in user's browser
CVE-2026-27787
MATCHA SNS users may be at risk of having malicious scripts executed on their web browsers if they visit a compromised website. This could potentially lead to unauthorized actions or data theft. Users...
5.1
pyLoad WebUI Allows Unauthorized Access to Actions
GHSA-rfgh-63mg-8pwm
An authenticated user with 'ADD' or 'DELETE' permission can execute actions meant for 'MODIFY' permission. This can lead to unintended changes to the system. To fix this, update the WebUI JSON endpoin...
5.4