Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 17 April 2026
RSS76 vulnerabilities published on 17 April 2026
Severity:
WP Statistics Plugin Leaks Sensitive Analytics Data on WordPress
CVE-2026-3488
The WP Statistics plugin on WordPress websites has a flaw that allows attackers to access sensitive data, such as user information and analytics, by exploiting a lack of proper security checks. This a...
6.5
Royal Addons for Elementor plugin: Malicious code injection via Instagram widget
CVE-2026-5162
The Royal Addons for Elementor plugin for WordPress contains a security flaw that allows attackers to inject malicious code into website pages. This could potentially allow an attacker to take control...
6.4
CubeCart versions before 6.6.0 allow code injection through user input
CVE-2026-34018
If not updated, CubeCart stores can be compromised by malicious input, allowing an attacker to alter data or disrupt the site. Update to version 6.6.0 or later to fix this issue. This is a high priori...
5.1
Sparx Enterprise Architect Exposes Sensitive OAuth2 Credentials
CVE-2025-15622
Sensitive credentials for Sparx Enterprise Architect's OAuth2 integration are not properly protected, allowing an attacker to access the system with elevated privileges. This could lead to unauthorize...
6.2
Unauthenticated access to private note assets on Note app
GHSA-p5w6-75f9-cc2p
CVE-2026-40265
Unauthenticated users can access private note assets on the Note app if they know the note and asset IDs. This allows them to view sensitive information without needing to log in. To fix this, the app...
5.9
AAP MCP Server Log Injection Vulnerability - Unauthorized Access and Deception Possible
CVE-2026-6494
An attacker can send malicious input to the AAP MCP server, allowing them to hide or fake log entries. This could trick operators into running bad commands or visiting bad websites. Update the server ...
5.3
The Quiz And Survey Master plugin for WordPress allows attackers to access quiz answers
CVE-2026-5797
The Quiz And Survey Master plugin for WordPress, used to create quizzes and surveys, is vulnerable to a security issue that allows hackers to access other users' quiz answers without permission. This ...
5.3
Tutor LMS plugin for WordPress allows unauthorized course content changes
CVE-2026-5502
This vulnerability in Tutor LMS plugin for WordPress allows attackers with subscriber-level access to manipulate course content, such as detaching lessons, moving them between topics, and changing the...
5.3
Kubio Plugin for WordPress Allows Malicious File Uploads
CVE-2026-5427
The Kubio plugin for WordPress is vulnerable to a security issue that allows authorized users to upload files from external URLs to the site's media library, potentially leading to malicious content b...
5.3
LatePoint WordPress Plugin Exposes Financial Data via Public API
CVE-2026-5234
The LatePoint WordPress plugin for managing Stripe payments is at risk because an attacker can access sensitive financial information, including invoices, orders, and customer details, without needing...
5.3
Vault's ACME Challenge Sends Sensitive Requests to Local Network Targets
CVE-2026-5052
A bug in Vault's PKI engine can cause it to send sensitive requests to internal network targets, potentially exposing information. This issue has been fixed in certain versions of Vault, so make sure ...
5.3
SiYuan versions 3.6.1-3.6.3 allow malicious code to run on users' computers
CVE-2026-40922
Versions 3.6.1 through 3.6.3 of SiYuan contain a security weakness that could let an attacker inject malicious code into the personal knowledge management system. This could allow them to take control...
5.3
Red Magic 11 Pro allows non-privileged apps to access sensitive areas
CVE-2026-40002
The Red Magic 11 Pro smartphone has a security flaw that lets malicious apps access areas of the phone they shouldn't be able to. This means an attacker could potentially write files to areas of the p...
5.0
JetBackup Plugin for WordPress: Unauthorized Directory Deletion
CVE-2026-4853
The JetBackup plugin for WordPress allows an attacker with admin access to delete any directory on the server, potentially disabling all plugins and causing site disruption. This is due to a weakness ...
4.9
Form Maker by 10Web plugin for WordPress: SQL Injection via User Search Parameters
CVE-2026-3330
The Form Maker plugin for WordPress has a security weakness that allows an attacker with administrator access to potentially access sensitive information from the database. This can be done by trickin...
4.9
VideoZen Plugin for WordPress Allows Malicious Code Injection
CVE-2026-6439
The VideoZen plugin for WordPress is vulnerable to a type of attack where attackers can inject malicious code into the plugin settings page. This can happen when an attacker with Administrator-level a...
4.4
WordPress cms-fuer-motorrad-werkstaetten Plugin Can Be Tricked into Deleting Data
CVE-2026-6451
The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to a type of attack that could allow an attacker to delete important data by tricking a logged-in user into clicking on a maliciou...
4.3
Canto Plugin for WordPress: Unauthorized Access to Settings
CVE-2026-6441
The Canto plugin for WordPress has a security issue in versions up to 3.1.1 that allows anyone with a subscriber account or higher to change or delete important settings, including those related to sc...
4.3
WordPress Users Exposed through Login Timing Attack
GHSA-w6m9-39cv-2fwp
CVE-2026-40263
An attacker can determine if a WordPress username exists by sending requests to the login endpoint and measuring response times. This makes it easier to launch targeted attacks against valid accounts....
3.7
CubeCart Access to Sensitive Data via Misleading URLs
CVE-2026-35496
A security weakness in CubeCart versions older than 6.6.0 allows administrators to potentially access files they shouldn't. This could lead to unauthorized access to sensitive data. Update to version ...
5.1
CGA-55qm-vfpv-pfvr
CGA-55qm-vfpv-pfvr
CGA-pqxr-g3q3-977c
CGA-pqxr-g3q3-977c
Ruby's zlib interface allows attackers to corrupt memory
DEBIAN-CVE-2026-27820
Old versions of the zlib Ruby interface can be tricked into overwriting memory with attacker-controlled data, causing unpredictable behavior. This issue affects Ruby applications using zlib for compre...
fio v3.41 Crashes When Parsing Malformed Job Files
DEBIAN-CVE-2026-30656
A security issue in fio v3.41 can cause the program to crash if it encounters a specific type of malformed job file. This could potentially be exploited by an attacker to disrupt fio operations. To pr...
CGA-665p-g3m9-mmwv
CGA-665p-g3m9-mmwv