MikeTrendsTrends right now

search

CVSS

Trends

  1. 1
    GitLab patches critical CVSS 9.9 AI Gateway vulnerabilityโ—๐Ÿšจ GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI GatMmastodonTechnologyCybersecurity19 h ago

    GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.

  2. 2
    YesWiki hit by nine vulnerabilities including SQL injection flawโ—๐Ÿšจ YesWiki 9 CVEs โ€” CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requirMmastodonTechnologyCybersecurity19 h ago

    Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.

  3. 3
    Medium-severity vulnerability flagged in Burst Statistics WordPress pluginโ–ผ๐Ÿšจ EUVD-2026-91950 ๐Ÿ“Š Score: 4.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Burst Statistics โ€“ Simple WordPress Analytics (Google AnalyticsMmastodonTechnologyCybersecurity014 h ago

    A new vulnerability listing, EUVD-2026-91950, has been published for the Burst Statistics WordPress analytics plugin by vendor burstbv, an alternative to Google Analytics. The flaw carries a CVSS v3.1 score of 4.3 out of 10, indicating moderate severity. Administrators running the plugin on WordPress sites are advised to check for updates and patch promptly.

  4. 4
    WordPress app builder plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91951 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPMobile.App โ€“ Android and iOS App Builder ๐Ÿข Vendor: amauric ๐Ÿ“…MmastodonTechnologyCybersecurity014 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ€“ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.

  5. 5
    WPC Product Options plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91952 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPC Product Options for WooCommerce ๐Ÿข Vendor: WPClever ๐Ÿ“… UpdateMmastodonTechnologyCybersecurity014 h ago

    A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.

  6. 6
    GitLab patches critical AI Gateway flaw allowing command executionโ—๐Ÿค– GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform accessMmastodonTechnologyCybersecurity118 h ago

    GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.