CVEs

Browse and track CVEs by technology, product and vulnerability type. Find the latest vulnerabilities for WordPress, NGINX, APIs and more.

Latest

  1. CVE-2026-76606 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

  2. CVE-2026-76605 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

  3. CVE-2026-76604 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.

  4. CVE-2026-76603 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

  5. CVE-2026-76602 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

  6. CVE-2026-76601 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.

  7. CVE-2026-76600 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.

  8. CVE-2026-76599 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.

  9. CVE-2026-76598 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.

  10. CVE-2026-76597 Published Aug 22, 2026

    Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.

Categories