General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-39527 | Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions. | Medium (5.4) | 2026-06-15 | General Purpose |
| CVE-2026-39499 | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | High (7.2) | 2026-06-15 | General Purpose |
| CVE-2026-39491 | Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions. | Medium (6.5) | 2026-06-15 | General Purpose |
| CVE-2026-39481 | Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | High (7.2) | 2026-06-15 | General Purpose |
| CVE-2026-39468 | Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions. | Medium (6.8) | 2026-06-15 | General Purpose |