A vulnerability was found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. It has been rated as critical. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection.
This vulnerability is tracked as CVE-2026-5558. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability was found in badlogic pi-mono up to 0.58.4. It has been declared as critical. This issue affects some unknown processing of the file packages/mom/src/slack.ts of the component pi-mom Slack Bot. The manipulation results in authentication bypass using alternate channel.
This vulnerability is identified as CVE-2026-5557. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in badlogic pi-mono up to 0.58.4. It has been classified as critical. This vulnerability affects the function discoverAndLoadExtensions of the file packages/coding-agent/src/core/extensions/loader.ts. The manipulation leads to code injection.
This vulnerability is referenced as CVE-2026-5556. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in code-projects Concert Ticket Reservation System 1.0 and classified as critical. This affects an unknown part of the file /ConcertTicketReservationSystem-master/login.php of the component Parameter Handler. Executing a manipulation of the argument Email can lead to sql injection.
The identification of this vulnerability is CVE-2026-5555. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in code-projects Concert Ticket Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /ConcertTicketReservationSystem-master/process_search.php of the component Parameter Handler. Performing a manipulation of the argument searching results in sql injection.
This vulnerability was named CVE-2026-5554. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-5553. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability, which was classified as problematic, has been found in wp-buy Visitor Traffic Real Time Statistics Plugin up to 8.4 on WordPress. Affected is an unknown function of the component Title Section. This manipulation of the argument page_title causes cross site scripting.
This vulnerability is handled as CVE-2026-2936. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as problematic was found in getwpfunnels WPFunnels Plugin up to 3.7.9 on WordPress. This impacts the function wpf_optin_form of the component Shortcode Handler. The manipulation of the argument button_icon results in cross site scripting.
This vulnerability is known as CVE-2026-0626. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as critical has been found in tomdever wpForo Forum Plugin up to 2.4.16 on WordPress. This affects an unknown function of the component Path Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-3666. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in mvirik Text to Speech Plugin up to 1.9.8 on WordPress. The impacted element is the function Mementor_TTS_Remote_Telemetry. Executing a manipulation can lead to hard-coded credentials.
This vulnerability appears as CVE-2026-1233. The attack may be performed from remote. There is no available exploit.
A vulnerability marked as critical has been reported in purethemes Listeo-Core Plugin up to 2.0.27 on WordPress. The affected element is the function listeo_core_handle_dropped_media of the component AJAX Endpoint. Performing a manipulation results in unrestricted upload.
This vulnerability is reported as CVE-2025-14938. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.