search
CVSS
Trends
- 1GitLab patches critical CVSS 9.9 AI Gateway vulnerabilityโ๐จ GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI Gat
GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.
- 2YesWiki hit by nine vulnerabilities including SQL injection flawโ๐จ YesWiki 9 CVEs โ CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requir
Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.
- 3Medium-severity vulnerability flagged in Burst Statistics WordPress pluginโผ๐จ EUVD-2026-91950 ๐ Score: 4.3/10 (CVSS v3.1) ๐ฆ Product: Burst Statistics โ Simple WordPress Analytics (Google Analytics
A new vulnerability listing, EUVD-2026-91950, has been published for the Burst Statistics WordPress analytics plugin by vendor burstbv, an alternative to Google Analytics. The flaw carries a CVSS v3.1 score of 4.3 out of 10, indicating moderate severity. Administrators running the plugin on WordPress sites are advised to check for updates and patch promptly.
- 4WordPress app builder plugin hit by stored XSS flawโผ๐จ EUVD-2026-91951 ๐ Score: 5.4/10 (CVSS v3.1) ๐ฆ Product: WPMobile.App โ Android and iOS App Builder ๐ข Vendor: amauric ๐
A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.
- 5WPC Product Options plugin hit by stored XSS flawโผ๐จ EUVD-2026-91952 ๐ Score: 7.2/10 (CVSS v3.1) ๐ฆ Product: WPC Product Options for WooCommerce ๐ข Vendor: WPClever ๐ Update
A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.
- 6GitLab patches critical AI Gateway flaw allowing command executionโ๐ค GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access
GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.