tag
Account-Takeover
Critical
WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390·
WP Directory Kit (WordPress plugin)
unpatched
Critical
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580·
quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro)
patched
Critical
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209·
RestroPress – Online Food Ordering System (WordPress plugin)
unpatched
Critical
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922·
PrestaShop Checkout module (ps_checkout)
unpatched
Critical
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
CVE-2025-58434·
FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints)
unpatched
Critical
Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912·
V2Board / Xboard (VPN/proxy subscription management panels)
unpatched
High
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415·
WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA)
unpatched
Critical
WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417·
SignUp & SignIn WordPress plugin (CVE-2026-12417); Invoice Generator WordPress plugin (CVE-2026-12416)
unpatched
Critical
Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072·
Veno File Manager Project
unpatched
Medium
Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
CVE-2026-7671·
Tornet Scooter Mobile App backend (/TwoFactor endpoint), Android app v4.75
unpatched
Critical
Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886·
Strapi CMS (Content API)
unpatched
Critical
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)
CVE-2026-23760·
SmarterTools SmarterMail
patched
High
Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459·
Simple History (WordPress plugin)
unpatched
High
Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
CVE-2026-40487 / GHSA-44wg-r34q-hvfx·
Postiz (open-source social media management platform, gitroomhq/postiz-app)
patched
Medium
PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w)·
[PocketBase](https://github.com/pocketbase/pocketbase) (Go backend / BaaS)
unpatched
High
LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741·
LatePoint – Calendar Booking Plugin for Appointments and Events (WordPress plugin, slug latepoint)
patched
Critical
Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206·
Kirki (WordPress Customizer framework plugin) — CompLibFormHandler REST API endpoint
unpatched
Critical
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580·
Hippoo Mobile App for WooCommerce (WordPress plugin)
unpatched
Not disclosed
Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813·
Gogs (self-hosted Git service), organization creation feature
patched
Moderate
FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646)·
FOSSBilling (open-source billing/client management platform)
patched
Critical
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229·
Form Notify WordPress plugin, LINE Login OAuth 2.0 integration (src/APIs/Line/Login/Route.php, User.php)
patched
Critical
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11)·
Discuz! X5.0 (PHP-based forum/CMS software)
unpatched
Critical
Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)
CVE-2026-8181·
Burst Statistics – Privacy-Friendly WordPress Analytics (burst-statistics plugin)
patched
Critical
Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551·
Branda White Label & Branding WordPress plugin
patched
High
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415·
Azuriom CMS
patched
Critical
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074)·
ARMember – Membership Plugin & Content Restriction (WordPress plugin)
patched