Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-92609

Publication date:
25/09/2026
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication.<br /> <br /> This issue affects Apache Qpid Broker-J: through 10.1.0.<br /> <br /> Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-92713

Publication date:
25/09/2026
The Modula Image Gallery – Photo Grid &amp; Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server. The path restriction to wp-content/uploads is not an effective ownership boundary, as all user attachment files reside within that tree, and Authors trivially satisfy the edit_post check on their own galleries.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-93656

Publication date:
25/09/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles &amp; User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable via a nonce-free GET request to /wp-admin/profile.php, requiring no profile-form submission; a Subscriber can plant the malicious attachment URL, which then executes when an administrator opens that user&amp;#39;s Edit User screen.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-93747

Publication date:
25/09/2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &amp;#39;telegram&amp;#39; profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action — the raw $_POST[&amp;#39;data&amp;#39;] array is copied into a $custom_fields variable before validate() and sanitize() run, both of which operate only on a parallel $user reference, leaving $custom_fields unsanitized when it is persisted via update_custom_fields(); on render, wpforo_decode() reverses the entity encoding and the value is echoed without escaping in field_wrap_profile(). This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-93901

Publication date:
25/09/2026
The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain `iHomefinderAjaxHandler::clearCache()` → `activateAuthenticationToken()` → `getAuthenticationInfo()` → `provisionBlogCredentials()` — with no capability check, nonce verification, or ownership validation, and the function unconditionally calling `$user-&gt;set_role(&amp;#39;author&amp;#39;)` on whichever WordPress account matches the hard-coded login `optima-express` via `get_user_by(&amp;#39;login&amp;#39;, &amp;#39;optima-express&amp;#39;)`. This makes it possible for unauthenticated attackers to escalate a pre-registered `optima-express` account to the Author role, gaining `publish_posts`, `upload_files`, and `edit_published_posts` capabilities, including access to the plugin&amp;#39;s own `/wp-json/optima-express/v1/blog-post` REST endpoint. Exploitation requires open user registration to be enabled on the target site, and the attacker must register the `optima-express` username before the plugin has had the opportunity to provision that login for its own integration account.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-92608

Publication date:
25/09/2026
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly.<br /> <br /> This issue affects Apache Qpid Broker-J: through 10.1.0.<br /> <br /> Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-93654

Publication date:
25/09/2026
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via &amp;#39;cart_items[][product_name]&amp;#39; Parameter in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The checkout REST route uses permission_callback set to __return_true and the invoice loader performs no order ownership check, meaning an unauthenticated attacker can both persist the payload and ensure it is renderable to any logged-in user who accesses the invoice.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-17602

Publication date:
25/09/2026
The SSL Zen — SSL Certificate Installer &amp; HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the &amp;#39;file_name&amp;#39; parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-19804

Publication date:
25/09/2026
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the &amp;#39;first_name&amp;#39; parameter parameter. This is due to insufficient sanitization of the first_name parameter via esc_refs(), which strips only regex backreferences and not PHP tags, before substitution into the eval&amp;#39;d Signup Tracking Codes template, combined with disclosure of the site-global proxy verification key that allows PayPal postback verification to be bypassed. This makes it possible for unauthenticated attackers to execute code on the server. Successful exploitation requires that the site administrator has configured a Signup Tracking Codes template containing the %%first_name%% placeholder (a documented, GUI-supported feature) and that the attacker has obtained the site-global proxy verification key, which is exposed in plaintext in the JSON response of any PayPal Checkout AJAX request on the target site.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-84280

Publication date:
25/09/2026
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order &amp;#39;elements[].title&amp;#39; Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is written to the DOM via innerHTML within the beforeElementAdd JavaScript event handler when processing the elements[].title field from the stored order JSON, meaning execution occurs specifically when an administrator reviews shortcode orders in the WordPress admin panel.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-89406

Publication date:
25/09/2026
The Modula Image Gallery – Photo Grid &amp; Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via get_post( $_GET[&amp;#39;modula_gallery_id&amp;#39;] ) without verifying the gallery&amp;#39;s post_status or the requester&amp;#39;s capability to read it — the gallery-side input guard is bugged (empty(&amp;#39;modula_gallery_id&amp;#39;) tests a nonempty string literal instead of the GET parameter, so it is always false), the only object validation is a post_type === &amp;#39;modula-gallery&amp;#39; check, and no is_user_logged_in()/current_user_can(&amp;#39;read_post&amp;#39;, $gallery_id) check is performed. This makes it possible for unauthenticated attackers to enumerate private modula-gallery posts and their member attachments and recover the image&amp;#39;s title, description, dimensions, and original upload URL via Open Graph/Twitter meta tags emitted in the response, which then allows direct unauthenticated download of the original private image bytes.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026

CVE-2026-89426

Publication date:
25/09/2026
The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target role directly from an attacker-controlled Gravity Forms entry field — configured via the feed&amp;#39;s `user_role_field_id` — and passing it to `WP_User::set_role()` without validating the supplied value against an allowlist of permitted roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to administrator by tampering with the hidden role field value at form submission time. Exploitation is further enabled by the fact that $0 orders are synchronously marked as SUCCESS during form submission without requiring a real payment, and when no GF User Registration user can be resolved, the role assignment target falls back to `$lead[&amp;#39;created_by&amp;#39;]` — the currently authenticated submitter&amp;#39;s own user ID — making any authenticated form submitter an eligible exploitation target.
Severity CVSS v4.0: Pending analysis
Last modification:
25/09/2026