Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Threat Lab
CVE-2026-9282 – Unauthenticated Arbitrary File Read – W3 Total Cache WordPress Plugin ≤ 2.9.4

CVE-2026-9282 is a high-severity Directory Traversal vulnerability in the W3 Total Cache WordPress plugin (by BoldGrid), affecting all versions up to and including 2.9.4. The flaw resides in the setupSources function and allows unauthenticated remote attackers to read the contents of arbitrary files on the server, with a CVSS v3.1 base score of 7.5 (HIGH). With over 900,000 active installations, the plugin represents a significant attack surface across the WordPress ecosystem.

Created Date
Source IONIX Threat Lab
CVE-2026-56261 – SSRF via Unvalidated Webhook URLs – Crawl4AI before 0.8.7

CVE-2026-56261 is a critical Server-Side Request Forgery (SSRF) vulnerability in the Crawl4AI Docker API server, affecting all versions prior to 0.8.7. The /crawl/job and /llm/job endpoints accept webhook callback URLs as parameters without validating the destination address, enabling unauthenticated remote attackers to force the server to make HTTP requests to internal networks, private IP ranges, Docker-internal hosts, or cloud metadata endpoints. With a CVSS 4.0 score of 9.2 (Critical), this vulnerability poses a severe risk of cloud credential theft and internal network exposure.

Created Date
Source IONIX Threat Lab
CVE-2026-56292 – Unauthenticated SQL Injection – AcyMailing extension for Joomla versions prior t…

CVE-2026-56292 is a critical unauthenticated SQL injection vulnerability (CWE-89) in the AcyMailing email marketing extension for Joomla, affecting all versions prior to 10.11.1. Carrying a CVSS v4.0 score of 9.2 (Critical), the flaw allows a remote, unauthenticated attacker to perform unauthorized database access and exfiltrate sensitive data with no user interaction required. A patch was released by the vendor on July 9, 2026; no public proof-of-concept exploit has been published at this time.

Created Date
Source IONIX Threat Lab
CVE-2026-5955 – Unauthenticated SQL Injection – BiEticaret before v3.3.57

CVE-2026-5955 is a critical SQL injection vulnerability (CWE-89) in BiEticaret, a PHP-based e-commerce platform developed by Inrove Software and Internet Services. Affecting all versions prior to v3.3.57, the flaw carries a CVSS v3.1 score of 9.8 (Critical) and requires no authentication and no user interaction, making it exploitable by any remote attacker over the internet. The vulnerability was assigned advisory TR-26-0519 by TR-CERT, the Turkish Cybersecurity Authority, and was discovered by security researcher Ferit ÖZNER.

Created Date
Source IONIX Threat Lab
CVE-2026-11404 – Denial of Service (Out-of-Bounds Read) – Cesanta Mongoose before 7.22

CVE-2026-11404 is a high-severity out-of-bounds read vulnerability (CWE-125) in Cesanta Mongoose, a widely-deployed embedded C networking library used in IoT devices, industrial controllers, microcontrollers, and embedded appliances. The flaw resides in the built-in TLS server function mg_tls_server_recv_hello(), where an attacker-controlled session_id_len byte from a TLS ClientHello is used as a buffer index without bounds validation. A single crafted packet sent by a remote, unauthenticated attacker is sufficient to crash any HTTPS, MQTTS, or WSS service built on Mongoose's built-in TLS implementation, scoring CVSS 4.0 8.7 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-58122 – Authentication Bypass – Hermes WebUI before 0.51.307

CVE-2026-58122 is a critical authentication bypass vulnerability in Hermes WebUI (nesquena/hermes-webui), an AI agent web interface commonly deployed internet-facing. By supplying a spoofed loopback address in the X-Forwarded-For HTTP header, unauthenticated remote attackers can circumvent local-origin IP restrictions enforced on onboarding endpoints, enabling server-side request forgery, LLM configuration hijacking, and persistent OAuth token theft. All versions prior to 0.51.307 are affected, and the vulnerability carries a CVSS 4.0 score of 9.3 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-14261 – Authentication Bypass and RCE – Xerte Online Tools before 3.14.6 / 3.15.5

CVE-2026-14261 is a critical authentication bypass and remote code execution vulnerability in Xerte Online Tools (Xerte Online Toolkits), an open-source web-based e-learning authoring platform widely deployed by universities and educational institutions. The flaw, classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel), carries a CVSS v3.1 base score of 9.1 (Critical) and is exploitable by unauthenticated remote attackers with no user interaction required. Patches are available in versions 3.14.6 and 3.15.5.

Created Date
Source IONIX Threat Lab
CVE-2026-11571 – Unauthenticated Sensitive Information Exposure – Everest Forms WordPress Plugin …

CVE-2026-11571 is a high-severity sensitive information exposure vulnerability affecting the Everest Forms WordPress plugin in all versions prior to 3.5.0. The flaw stems from the plugin's failure to reliably delete temporary CSV files generated during email-notification processing, leaving those files publicly accessible in the WordPress uploads directory under predictable, enumerable paths. Any unauthenticated remote attacker can enumerate and download other users' form submission records containing personal and potentially sensitive data.

Created Date
Source IONIX Threat Lab
CVE-2026-14894 – Unauthenticated RCE via Arbitrary File Upload – Super Forms – Drag & Drop Form B…

CVE-2026-14894 is a critical unauthenticated arbitrary file upload vulnerability in the Super Forms – Drag & Drop Form Builder WordPress plugin by WebRehab, affecting all versions up to and including 6.3.313. Due to missing file type validation and the complete absence of any capability check on a public-facing AJAX endpoint, unauthenticated attackers can upload executable files and achieve remote code execution (RCE) on the host server. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), and a patch was released in version 6.3.314 on July 7, 2026.

Created Date
Source IONIX Threat Lab
CVE-2026-15290 – Unauthenticated Blind SQL Injection – Ultimate Member WordPress Plugin ≤ 2.10.1

CVE-2026-15290 is a high-severity blind SQL injection vulnerability in the Ultimate Member WordPress plugin, affecting all versions up to and including 2.10.1. The flaw allows unauthenticated remote attackers to extract sensitive data from the WordPress database with no privileges and no user interaction required, earning a CVSS v3.1 score of 7.5. With over 200,000 active installations, the potential attack surface is significant.

Created Date
Source IONIX Threat Lab
CVE-2026-15291 – Sensitive Information Exposure – Chat Help WordPress Plugin ≤ 3.1.3

CVE-2026-15291 is a high-severity sensitive information exposure vulnerability affecting the Chat Help – Click to Chat Button & Form WordPress plugin (by ThemeAtelier), in all versions up to and including 3.1.3. The flaw stems from missing authorization checks (CWE-862) on two REST API endpoints, allowing any unauthenticated, internet-accessible attacker to retrieve collected lead data including customer PII and WordPress account credentials. The vulnerability carries a CVSS v3.1 base score of 7.5 (HIGH) with a full confidentiality impact and no authentication requirement.

Created Date
Source IONIX Threat Lab
CVE-2026-15300 – Unauthenticated SQL Injection – GEO my WP WordPress Plugin ≤ 4.5.4

CVE-2026-15300 is a critical unauthenticated SQL Injection vulnerability in the GEO my WP WordPress plugin, affecting all versions up to and including 4.5.4, with a CVSS v3.1 base score of 9.1. The flaw allows any remote, unauthenticated attacker to inject arbitrary SQL into the WordPress database by manipulating proximity-search query parameters, requiring no credentials and no user interaction. A patch is available in version 4.5.5.

Created Date
Source IONIX Threat Lab
CVE-2026-56291 – Unauthenticated File Upload Leading to RCE – Balbooa Forms extension for Joomla …

CVE-2026-56291 is a critical unauthenticated arbitrary file upload vulnerability in the Balbooa Forms extension for Joomla (com_baforms), affecting all versions up to and including 2.4.0. The flaw allows any remote, unauthenticated attacker to upload executable PHP files directly to the server and achieve full Remote Code Execution (RCE), earning a maximum CVSS 4.0 score of 10.0. Active exploitation of this vulnerability has been observed in the wild prior to the availability of a patch.

Created Date
Source IONIX Threat Lab
CVE-2026-59834 – SQL Injection / Unauthorized Disclosure of Private Documents – SiYuan prior to 3…

CVE-2026-59834 is a high-severity SQL injection vulnerability (CWE-89) in SiYuan, an open-source self-hosted personal knowledge management system. The flaw exists in the block search endpoint POST /api/search/fullTextSearchBlock, where user-supplied paths[] values are concatenated directly into SQL predicates, enabling an unauthenticated publish visitor to inject a UNION SELECT statement and exfiltrate content from documents that are hidden from public access. The issue is fixed in version 3.7.1, and all prior versions are affected.

Created Date
Source IONIX Threat Lab
CVE-2026-44787 – Unauthenticated Privilege Escalation – Discourse prior to 2026.6.0, 2026.5.1, 20…

CVE-2026-44787 is a high-severity privilege escalation vulnerability in Discourse, the open-source community discussion platform, affecting all versions prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. During the public account registration (signup) flow, a newly registering user can supply a crafted primary_group_id parameter to assign themselves membership in a whisper-enabled group, bypassing legitimate group enrollment entirely. On instances where the whispers_allowed_groups site setting is configured, this grants the unauthenticated attacker read and write access to whisper posts — private, restricted-visibility messages typically reserved for staff or privileged community members.

Created Date
Source IONIX Threat Lab
CVE-2026-55471 – XXE / SSRF – HAPI FHIR (org.hl7.fhir.core) prior to 6.9.10

CVE-2026-55471 is a high-severity XML External Entity (XXE) injection vulnerability in HAPI FHIR's org.hl7.fhir.utilities library, affecting all versions prior to 6.9.10. The flaw resides in XsltUtilities.saxonTransform() overloads, which instantiate an unrestricted Saxon TransformerFactoryImpl and thereby allow an attacker who controls or can tamper with transformed XML to read arbitrary files from the server and conduct blind XXE/Server-Side Request Forgery (SSRF) attacks against internal and external URLs reachable from the host. The vulnerability carries a CVSS 3.1 base score of 8.6 (HIGH) and requires no authentication or user interaction.

Created Date
Source IONIX Threat Lab
CVE-2026-59731 – Authentication Bypass – Astro 6.4.7

CVE-2026-59731 is a high-severity authentication bypass vulnerability in the Astro web framework (withastro/astro), affecting version 6.4.7. The flaw stems from a URL canonicalization mismatch between middleware-level authorization logic and the rewrite route-matching stage, enabling unauthenticated remote attackers to access middleware-protected routes by supplying a sufficiently encoded URL path. It carries a CVSS v3.1 base score of 8.2 (High) and is classified under CWE-647 (Use of Non-Canonical URL Paths for Authorization Decisions).

Created Date
Source IONIX Threat Lab
CVE-2026-60105 – Unauthenticated SSRF Leading to Cloud Credential Theft – Monsta FTP before 2.14.5

CVE-2026-60105 is a high-severity server-side request forgery (SSRF) vulnerability affecting Monsta FTP in all versions before 2.14.5, published July 8, 2026 (CVSS v3.1: 8.6 HIGH). The flaw enables fully unauthenticated remote attackers to bypass the application's internal IP blocklist via IPv4-mapped IPv6 addresses and force the server to issue HTTP requests to internal services — including cloud instance metadata endpoints — with responses exfiltrated to an attacker-controlled FTP destination.

Created Date
Source IONIX Threat Lab
CVE-2026-15158 – Unauthenticated Arbitrary File Upload leading to RCE – Blocksy Companion Pro ≤ 2…

CVE-2026-15158 is a critical-severity (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in the Blocksy Companion Pro WordPress plugin, affecting all versions up to and including 2.1.46. A flaw in the plugin's MIME type validation logic allows unauthenticated attackers to upload PHP-executable files disguised as font files, enabling Remote Code Execution (RCE) on the underlying web server. A patched version (2.1.47) has been released, and immediate upgrade is strongly recommended.

Created Date
Source IONIX Threat Lab
CVE-2026-59822 – Authentication Bypass – LiteLLM prior to v1.84.0

CVE-2026-59822 is a high-severity authentication bypass vulnerability in LiteLLM (AI Gateway/proxy server by BerriAI) affecting all versions prior to 1.84.0. The flaw resides in LiteLLM's MCP Streamable HTTP endpoint, where a faulty OAuth2 passthrough fallback mechanism allows an unauthenticated attacker to craft a fabricated Authorization header and gain access to MCP tooling without a valid LiteLLM key. The vulnerability carries a CVSS 4.0 score of 8.8 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-12378 – PHP Object Injection / RCE – Appointment Booking Calendar Plugin and Scheduling …

CVE-2026-12378 is a PHP Object Injection vulnerability affecting the Appointment Booking Calendar Plugin and Scheduling Plugin for WordPress (by codepeople), in all versions through 1.1.28. The flaw arises from the plugin passing user-supplied data to a PHP deserialization function without any validation, allowing unauthenticated, network-based attackers to inject arbitrary PHP objects. Where a suitable gadget chain is available on the target site, this vulnerability can be leveraged to achieve Remote Code Execution (RCE).

Created Date
Source IONIX Threat Lab
CVE-2026-6230 – Unauthenticated SQL Injection – Tainacan WordPress Plugin ≤ 1.0.3

CVE-2026-6230 is a time-based blind SQL injection vulnerability in the Tainacan plugin for WordPress, affecting all versions up to and including 1.0.3. The flaw resides in the plugin's geocoordinate query builder and is exploitable by unauthenticated, remote attackers via the geoquery parameter, requiring no privileges or user interaction. It carries a CVSS v3.1 base score of 7.5 (HIGH) and enables extraction of sensitive data from the underlying WordPress database.

Created Date
Source IONIX Threat Lab
CVE-2026-3144 – Authentication Bypass via Default Credentials – IBM API Connect 12.1.0.0 through …

CVE-2026-3144 is a high-severity authentication bypass vulnerability in IBM API Connect versions 12.1.0.0 through 12.1.0.3, caused by the use of default credentials (CWE-1392) that the application does not enforce changing until after initial access has already been granted. An unauthenticated remote attacker can exploit this flaw to gain unauthorized access to the platform before the system triggers a mandatory credential update. The vulnerability carries a CVSS v3.1 base score of 8.1 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-44840 – Unauthenticated DQL Injection Enabling Database Exfiltration in Dgraph (prior to…

CVE-2026-44840 is a high-severity DQL (Dgraph Query Language) injection vulnerability in Dgraph, an open-source distributed GraphQL database, affecting all releases prior to version 25.3.4. The flaw allows unauthenticated remote attackers to inject arbitrary DQL query blocks through the checkUserPassword GraphQL query, enabling full exfiltration of database contents without any credentials. A patch is available in version 25.3.4.

Created Date
Source IONIX Threat Lab
CVE-2026-9700 – Unauthenticated SQL Injection – Eventer WordPress Plugin ≤ 4.4.2

CVE-2026-9700 is a high-severity, unauthenticated time-based SQL injection vulnerability in the Eventer WordPress plugin, affecting all versions up to and including 4.4.2. The flaw allows any remote, unauthenticated attacker to extract sensitive data from the underlying WordPress database with no privileges or user interaction required. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-59705 – Unauthenticated Memory Exposure and Denial of Service – mem0 OpenMemory API (all…

CVE-2026-59705 is a critical missing authentication vulnerability (CWE-306) in mem0's OpenMemory API component (openmemory/api), carrying a CVSS v3.1 score of 9.8 (Critical). The flaw allows unauthenticated network attackers to read, modify, and delete any user's private AI memories, or trigger a global denial-of-service condition affecting all users of a deployment. All versions of the OpenMemory API prior to patch commit a3154d5 are affected.

Created Date
Source IONIX Threat Lab
CVE-2026-55418 – Cross-Tenant Unauthorized File Disclosure (IDOR) – FastGPT prior to v4.15.0-beta5

CVE-2026-55418 is a high-severity broken object-level authorization (IDOR) vulnerability in FastGPT, the open-source AI knowledge base and RAG platform developed by labring. Two file handler endpoints — the chat-file presign endpoint and the dataset preview endpoint — accept an S3 object key directly from the request without verifying that the key belongs to the requesting caller's team, enabling any unauthenticated network attacker to read files belonging to other tenants. The vulnerability carries a CVSS v3.1 score of 8.6 (HIGH) and requires no authentication, no privileges, and no user interaction to…

Created Date
Source IONIX Threat Lab
CVE-2026-46354 – PKCS#7 Signature Bypass Leading to Unauthenticated Agent Token Theft – Coder pri…

CVE-2026-46354 is a critical PKCS#7 signature verification bypass in Coder, a self-hosted remote development environment platform, affecting all versions prior to the patched releases listed below. The flaw resides in the azureidentity.Validate() function, which verifies that a signer certificate chains to a trusted Azure certificate authority but never validates the cryptographic signature on the PKCS#7 envelope itself. An unauthenticated remote attacker who can supply a forged PKCS#7 payload to an unprotected API endpoint can obtain valid workspace agent session tokens and exfiltrate developer credentials.

Created Date
Source IONIX Threat Lab
CVE-2026-59706 – Unauthenticated Secret Disclosure and SSRF – mem0 OpenMemory (all versions throu…

CVE-2026-59706 is a critical vulnerability (CVSS 9.2) caused by missing authentication on configuration API endpoints in mem0's OpenMemory self-hosted REST API server. Two distinct unauthenticated attack paths allow remote attackers to retrieve stored LLM API keys in plaintext and conduct server-side request forgery (SSRF) against internal infrastructure — including cloud metadata services. No authentication or user interaction is required to exploit either path.

Created Date
Source IONIX Threat Lab
CVE-2026-55592 – Reflected XSS – Dashy ≤ 4.3.6

CVE-2026-55592 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting Dashy, a self-hosted web dashboard application, in all versions up to and including 4.3.6. The flaw resides in the Workspace component, where the url query parameter is passed directly to an iframe src attribute without scheme validation, enabling injection of javascript: URIs. With a CVSS v3.1 score of 6.1 (Medium), successful exploitation requires no authentication and allows an attacker to execute arbitrary JavaScript within the victim's browser in the context of the Dashy origin.

Created Date
Source IONIX Threat Lab
CVE-2026-59708 – Unauthenticated Portfolio Data Exposure – Ghostfolio up to 3.6.0

CVE-2026-59708 is a Missing Authorization vulnerability (CWE-862) in Ghostfolio, an open-source self-hosted wealth management web application built with Angular, NestJS, and Prisma. The flaw exists in the GET /api/v1/public/:accessId/portfolio endpoint, which fails to enforce granteeUserId filtering, allowing unauthenticated access to private portfolio data when a private access ID is known. The CVSS 4.0 score is 8.7 (HIGH) and CVSS 3.1 score is 7.5 (HIGH), reflecting a fully network-accessible, unauthenticated, high-confidentiality-impact vulnerability.

Created Date
Source IONIX Threat Lab
CVE-2026-59800 – Unauthenticated OS Command Injection (RCE) – 9Router before v0.4.44

CVE-2026-59800 is a critical OS command injection vulnerability in 9Router (decolua/9router), an AI coding proxy designed for internet-facing VPS and cloud deployments, affecting all versions before 0.4.44. The vulnerability exists in the POST /api/tunnel/tailscale-install endpoint, which is absent from the application's authentication middleware matcher, allowing any unauthenticated remote attacker to reach it and inject arbitrary shell commands. Rated 9.8 Critical (CVSS v3.1) and 9.2 Critical (CVSS v4.0), this vulnerability has been confirmed as actively exploited in the wild since July 4, 2026.

Created Date
Source IONIX Threat Lab
CVE-2026-13019 – Authentication Bypass – Esri Portal for ArcGIS 12.1 and Earlier

CVE-2026-13019 is a critical missing authentication for critical function vulnerability (CWE-640) in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes. A remote, unauthenticated attacker can directly access an unprotected API endpoint with no privileges or user interaction required, earning a CVSS v3.1 score of 9.8 (Critical). Esri released the Portal for ArcGIS Security 2026 Update 2 Patch on June 23, 2026, and strongly urges all affected customers to apply it within two weeks.

Created Date
Source IONIX Threat Lab
CVE-2026-12277 – Unauthenticated Arbitrary File Deletion Leading to Full Site Takeover – Frontend…

CVE-2026-12277 is a high-severity unauthenticated arbitrary file deletion vulnerability in the Frontend File Manager Plugin for WordPress, affecting all versions through 23.6, with a CVSS v3.1 score of 8.7. The flaw allows unauthenticated, network-based attackers to delete any file on the server — including WordPress's critical configuration file wp-config.php — when the plugin's guest upload mode is enabled. Deleting wp-config.php forces the WordPress installation wizard to relaunch, which an attacker can exploit to achieve full site takeover.

Created Date
Source IONIX Threat Lab
CVE-2026-58656 – Cross-Origin Admin Account Takeover via JWT Leakage and CORS Misconfiguration – …

CVE-2026-58656 is a high-severity vulnerability in the Grav CMS API plugin (getgrav/grav-plugin-api) affecting all versions before v1.0.0-rc.16, carrying a CVSS 4.0 score of 8.7 (High). The flaw combines two compounding weaknesses — the plugin exposes JWT authentication tokens via the ?token= URL query parameter, leaking credentials into server access logs, browser history, and HTTP Referrer headers; and every API response includes a wildcard Access-Control-Allow-Origin: * header, permitting any website to read authenticated API responses from a browser context. An attacker who obtains a leaked JWT token through any of these…

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge