Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 16 April 2026
RSS927 vulnerabilities published on 16 April 2026
Severity:
Froxlor Allows Reseller to Bypass Domain Quota
GHSA-jvx4-xv3m-hrj4
A vulnerability in Froxlor allows resellers to attribute domains to other admins, potentially exhausting another admin's domain quota. This can happen when a reseller creates a domain for another admi...
5.4
Weak Encryption on TP-Link Archer C7 Routers Exposes Admin Passwords
CVE-2026-5363
A security weakness in TP-Link Archer C7 routers (models v5 and v5.8) makes it possible for hackers with access to network traffic to guess or crack the admin password, giving them control over the ro...
5.4
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
GHSA-qqvm-66q4-vf5c
### Summary
Flowise introduced SSRF protections through a centralized HTTP security wrapper (`httpSecurity.ts`) that implements deny-list validation and IP pinning logic.
However, multiple tool impl...
5.3
Flowise: Unauthenticated Access to Sensitive OAuth Credentials
GHSA-6pcv-j4jx-m4vx
Sensitive OAuth credentials can be accessed by anyone, putting organizations at risk of unauthorized access. This vulnerability allows unauthorized users to retrieve full SSO configurations, including...
5.3
Flowise: Unauthenticated Access to OAuth Secrets via GET Request
GHSA-6pcv-j4jx-m4vx
If an attacker knows an organization ID, they can access sensitive login information, including passwords and security codes, without needing a password. This is a security risk because it allows unau...
5.3
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
GHSA-3jpj-v3xr-5h6g
CVE-2026-40304
Summary
The unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NULL (the marker for admin-created global frontends),...
5.3
Silverstripe Framework: Image Access Bypass in Older Versions
CVE-2026-24749
GHSA-jgcf-rf45-2f8v
Older versions of Silverstripe Framework allow unauthorized access to images, potentially compromising security. This issue has been fixed in versions 2.4.5 and 3.1.3. Developers should update to the ...
5.3
Fastify Static versions 8.0.0-9.1.0: Directory listings exposed
CVE-2026-6410
GHSA-pr96-94w5-mx2h
Using Fastify Static versions 8.0.0 through 9.1.0 and directory listing enabled, an attacker can see the names of files and directories outside your website's designated area. This is a security risk ...
5.3
Fluent Forms plugin allows attackers to change payment status on pending submissions
CVE-2026-4160
The Fluent Forms plugin for WordPress has a security flaw that allows unauthorized users to change the payment status of pending submissions. This could allow attackers to trick people into thinking a...
5.3
PostX plugin for WordPress lets attackers change post sharing counts
CVE-2026-0718
The PostX plugin for WordPress allows attackers to change how many times posts are shared, even if they're private or in draft mode. This could be used to manipulate post popularity or spread misinfor...
5.3
Riaxe Product Customizer plugin allows attackers to delete any WordPress user account
CVE-2026-3595
The Riaxe Product Customizer plugin for WordPress has a security flaw that allows anyone to delete any user account, including administrators, without needing a password. This could lead to a site bei...
5.3
Basic Google Maps Placemarks Plugin for WordPress Allows Unauthorized Map Changes
CVE-2026-3581
Versions of the Basic Google Maps Placemarks plugin for WordPress up to 1.10.7 are vulnerable to unauthorized changes to maps. This means anyone can modify map settings without permission. To fix this...
5.3
LangSmith SDK: Sensitive LLM Output Leaked in Streaming Events
GHSA-rr7j-v2q5-chgv
LangSmith SDK's streaming output can expose sensitive LLM results if output redaction is enabled. This happens because the redaction controls don't apply to streaming token events. If you're using Lan...
5.3
LangSmith SDK: Unredacted streaming token events stored in LangSmith
The LangSmith SDK's output redaction feature doesn't work for streaming output, allowing sensitive information to be stored in LangSmith. This means that any data streamed from a Large Language Model ...
5.3
LangSmith SDK: Sensitive data leaked in streaming token events
GHSA-rr7j-v2q5-chgv
LangSmith SDK's output redaction controls don't apply to streaming token events, which can leak sensitive data. This affects both JavaScript and Python SDKs. To protect sensitive data, review your usa...
5.3
DOMPurify: Forbidden tags can be added due to unexpected behavior
GHSA-39q2-94rc-95cp
DOMPurify, a library used to sanitize user input in web applications, has a bug that allows certain tags to be added to the output even if they are supposed to be forbidden. This can happen when both ...
5.3
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
GHSA-f3g8-9xv5-77gv
### Summary
Saltcorn validates the post-login `dest` parameter with a string check that only blocks `:/` and `//`. Because all WHATWG-compliant browsers normalise backslashes (`\`) to forward slashes ...
5.1
Dell Client Platform BIOS: Unauthenticated Access via Weak Password Recovery
CVE-2025-36579
If an attacker has physical access to a Dell computer, they may be able to bypass the password protection and gain unauthorized access to the system. This is a concern because it means someone could p...
5.1
wger: Malicious Links Can Steal User Data
GHSA-6f54-qjvm-wwq3
CVE-2026-40353
Authenticated users can create a malicious link on a wger page that can steal user data or perform actions as other users when viewed by anyone, including unauthenticated visitors. This is a high-risk...
5.1
Istio: Sensitive Data Leaked to Envoy Proxies via Internal Service Request
GHSA-fgw5-hp8f-xfhc
Istio's internal service request feature can leak sensitive data to Envoy proxies if an internal service is used as a JWT key source. This happens when Istio makes an unauthenticated request to the in...
5.0
Istio: Sensitive Data Exposed via Misconfigured Authentication Settings
GHSA-fgw5-hp8f-xfhc
A configuration mistake in Istio's authentication settings can allow sensitive data to be shared with Envoy proxies. This happens when a specific setting is used to point to an internal service withou...
5.0
ONLYOFFICE DocumentServer XLS File Processing Error
CVE-2026-41034
If a malicious XLS file is processed, it could potentially leak sensitive information and allow an attacker to bypass security protections. This affects ONLYOFFICE DocumentServer before version 9.3.0....
5.0
Froxlor Email Spoofing via Wrong Email Address Parsing
GHSA-vmjj-qr7v-pxm6
A software bug in Froxlor allows any authenticated customer to send emails pretending to be from other customers' email addresses. This is a security risk because it could be used to send spam or phis...
5.0
Froxlor Allows Cross-Customer Email Spoofing
GHSA-vmjj-qr7v-pxm6
Froxlor, a web hosting control panel, has a security flaw that lets one customer send emails as another customer's email addresses. This happens when a customer adds a full email address as an allowed...
5.0
Valtimo: Sensitive data exposed in application logs
GHSA-hfrg-mcvw-8mch
CVE-2026-34164
Valtimo's inbox feature logs sensitive information in logs, making it accessible to people with logging access or admin permissions. This could lead to unauthorized access to personal data. To resolve...
4.9