Security Risk Severity

Medium Security Risks — Page 24

Published vulnerability pages grouped by medium severity. Use this page to review risks that need similar prioritization.

969 published medium risks

Medium severity

Showing 829–864 of 969 published risks.

Clear
mediumEPSS 0.002

ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion

The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the 'thrivedesk_clear_cache' AJAX action in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache.

CVE-2026-1832wordpressauthorization-bypass

Updated Jul 13, 2026

mediumEPSS 0.003

Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation

The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned. The nonce required to authenticate the cancellation request is printed on the Appointments admin page, which is itself gated only by the edit_posts capability that Authors possess, making the nonce readily accessible to low-privileged users.

CVE-2026-11992wordpressauthorization-bypass

Updated Jul 13, 2026

mediumEPSS 0.003

KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary pending appointments as Confirmed and forge an associated completed payment record in wp_kc_payments_appointment_mappings using an attacker-supplied payment ID, bypassing payment entirely. This exploit is achievable on a default installation because the gateway resolution logic returns all registered gateways regardless of admin-enabled status, making the manual (KCPayLater) gateway always selectable.

CVE-2026-11990wordpressnetwork-securityauthorization-bypass

Updated Jul 13, 2026

mediumEPSS 0.002

bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional Fields feature. This is due to insufficient input sanitization in bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directly to post meta via update_post_meta() with no filtering) and missing output escaping in bsp_topic_content_append_topic_fields() (which concatenates the stored meta value into an HTML <span> and echoes it via apply_filters/echo without esc_html()). This makes it possible for authenticated attackers, with Subscriber-level access and above (who have bbPress topic-creation privileges), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, including unauthenticated visitors.

CVE-2026-15010wordpressxss

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-59212 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only checked read access while file write and delete routes later trusted object-derived access through writable model meta.knowledge entries, allowing a user with read-only knowledge file access to upgrade to file write or delete operations. This issue is fixed in version 0.10.0.

CVE-2026-59212api-securityweb-applicationauthorization-bypassfile-write

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-59217 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write-access check used by /api/v1/knowledge//file/add, allowing read-only knowledge-base users to add arbitrary files. This issue is fixed in version 0.10.0.

CVE-2026-59217api-securityweb-applicationauthorization-bypassfile-upload

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-59218 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcrypt password verification when a credential existed, making registered-account attempts measurably slower than missing-email attempts and allowing unauthenticated account enumeration. This issue is fixed in version 0.10.0.

CVE-2026-59218api-securityweb-applicationinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-59220 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions with overlapping quantifiers, allowing an authenticated chat message containing <$ without a closing > to trigger quadratic backtracking and block the asyncio event loop. This issue is fixed in version 0.10.0.

CVE-2026-59220web-applicationdenial-of-service

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-59222 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returned full UserModelResponse objects for channel members, including settings.ui.toolServers[].key and webhook configuration, allowing a normal channel participant to retrieve other users’ sensitive settings. This issue is fixed in version 0.10.0.

CVE-2026-59222api-securityweb-applicationinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-59223 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_LIST matching compared configured host entries against URL strings and non-label-boundary suffixes, allowing path-based blocklist bypasses such as !internal.example.com in a URL path and sibling-domain matches that did not reflect the intended hostname policy. This issue is fixed in version 0.10.0.

CVE-2026-59223api-securityweb-applicationinput-validationssrf

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-59225 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as /api/v1/tasks/moa/completions. The normal chat route resolves arena models before the final chat dispatch and therefore re-checks the selected underlying model. The task routes call utils.chat.generate_chat_completion() directly. In that direct path, arena fallback resolution happens after the wrapper access check and then recurses with bypass_filter=True, skipping the selected submodel's access check. This issue is fixed in version 0.10.0.

CVE-2026-59225api-securityweb-applicationauthorization-bypass

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-59227 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user image-generation permission, allowing a non-admin user to invoke server-side image editing with administrator-configured provider credentials. This issue is fixed in version 0.10.0.

CVE-2026-59227api-securityweb-applicationauthorization-bypass

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-43752 Claris FileMaker Server vulnerability

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

CVE-2026-43752web-applicationremote-code-executionfile-upload

Updated Jul 12, 2026

mediumEPSS 0.001

CVE-2026-59857 Vim vulnerability

Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.

CVE-2026-59857linuxdenial-of-servicememory-corruption

Updated Jul 12, 2026

mediumEPSS 0.004

CVE-2026-59193 Grav CMS vulnerability

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.0.

CVE-2026-59193phpweb-applicationdenial-of-service

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-55464 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2.

CVE-2026-55464phpweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-55472 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in version 8.6.2.

CVE-2026-55472phpapi-securityweb-applicationauthorization-bypass

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-55476 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim user ID and silently cancel that user’s pending asset requests. This issue is fixed in version 8.6.0.

CVE-2026-55476phpweb-applicationauthorization-bypass

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-55478 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a license they should not be able to access or manage into a kit. This issue is fixed in version 8.6.2.

CVE-2026-55478phpapi-securityweb-applicationauthorization-bypass

Updated Jul 12, 2026

medium

CVE-2026-13356 Firefox for iOS vulnerability

A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.

CVE-2026-13356browser

Updated Jul 12, 2026

mediumEPSS 0.001

CVE-2026-14867 PcVue vulnerability

Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials. Active Directory accounts are not affected by this vulnerability.

CVE-2026-14867industrial-controlinformation-disclosurecryptography

Updated Jul 12, 2026

mediumEPSS 0.007

CVE-2026-48828 Apache Airflow vulnerability

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).

CVE-2026-48828pythonapi-securitydevopsinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.004

CVE-2026-48891 Apache Airflow vulnerability

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read permission on some Dags could enumerate the identifiers of other Dags they were not authorized to read by inspecting the dependency graph for trigger / sensor references. Affects deployments that rely on per-Dag read scoping to keep Dag identifiers private across teams. This is a residual gap in the fix for CVE-2026-28563, which filtered the top-level Dag key but did not propagate the filter into the trigger / sensor dep-source / dep-target fields. Users who already upgraded for CVE-2026-28563 should additionally upgrade to `apache-airflow` 3.3.0 or later to cover the residual trigger / sensor dependency leak.

CVE-2026-48891pythonapi-securitydevopsinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.004

CVE-2026-48892 Apache Airflow vulnerability

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API output. Affects deployments that configure secrets backends via per-key environment overrides. Users are advised to upgrade to `apache-airflow` 3.3.0 or later.

CVE-2026-48892pythonapi-securitydevopsinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.006

CVE-2026-49296 Apache Airflow vulnerability

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DAG read authorization. Deployments that co-locate multiple Dags in a single file and rely on per-DAG access control to limit source visibility are affected; single-Dag-per-file deployments are not. Upgrade to apache-airflow 3.3.0 or later.

CVE-2026-49296pythonapi-securitydevopsauthorization-bypass

Updated Jul 12, 2026

mediumEPSS 0.004

CVE-2026-49487 Apache Airflow vulnerability

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-instance read access for that DAG could read that secret in clear text while the task was deferred. Users should upgrade to apache-airflow 3.3.0 or later, which masks sensitive values in trigger kwargs returned by the API.

CVE-2026-49487pythonapi-securitydevopsinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-53877 Django vulnerability

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVE-2026-53877pythonweb-applicationinformation-disclosuredenial-of-service

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-53878 Django vulnerability

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVE-2026-53878pythonweb-applicationinput-validation

Updated Jul 12, 2026

mediumEPSS 0.004

CVE-2026-56812 Phoenix Framework vulnerability

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic. This vulnerability is associated with program files assets/js/phoenix/presence.js and program routines Presence.syncState and Presence.syncDiff. The Phoenix JavaScript presence client checks whether a presence already exists with a bare truthiness test (state[key]) instead of an own-property check. Presence keys can be attacker-controlled, because applications track presences under a username or id supplied by the client. A user who joins a channel choosing a key that is an Object.prototype member name (__proto__, constructor, toString, hasOwnProperty, and similar) makes that lookup return JavaScript's built-in Object.prototype instead of undefined. Because the prototype is truthy, the code treats it as an existing presence and reads .metas.map(...) off it, which throws an uncaught TypeError. The exception propagates out of the presence message handler, so the local state is never updated and onSync() never fires. Because the malicious key is tracked on the server, it is re-pushed on every presence update and keeps re-throwing, so presence sync stays broken for every viewer of that channel topic until the attacker leaves. Both syncState and syncDiff use the same unsafe existence-check pattern. The impact is limited to the affected topic and is a read-time confusion of the prototype object, not a mutation of Object.prototype (it is not prototype pollution). This issue affects phoenix: from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.

CVE-2026-56812web-applicationinput-validationdenial-of-service

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48947 Joomla CMS vulnerability

An improper access check allows privileged users to overwrite media files without editing permissions.

CVE-2026-48947joomlaapi-securityauthorization-bypassfile-write

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48948 Joomla CMS vulnerability

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

CVE-2026-48948joomlaauthorization-bypassinformation-disclosure

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48949 Joomla CMS vulnerability

Lack of validation leads to an XSS vulnerability in the MFA management views.

CVE-2026-48949joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48950 Joomla CMS vulnerability

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

CVE-2026-48950joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48951 Joomla CMS vulnerability

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

CVE-2026-48951joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48952 Joomla CMS vulnerability

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

CVE-2026-48952joomlaweb-applicationxss

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-48953 Joomla CMS vulnerability

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

CVE-2026-48953joomlaweb-applicationxss

Updated Jul 12, 2026