Home Embedded Vulns General Vulns
CVE ID Description Severity Published Type
CVE-2026-39527 Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions. Medium (5.4) 2026-06-15 General Purpose
CVE-2026-39499 Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. High (7.2) 2026-06-15 General Purpose
CVE-2026-39491 Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions. Medium (6.5) 2026-06-15 General Purpose
CVE-2026-39481 Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. High (7.2) 2026-06-15 General Purpose
CVE-2026-39468 Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions. Medium (6.8) 2026-06-15 General Purpose