[vulnfeed] 9 critical CVEs — 2026-08-25 00:00 UTC
vulnfeed
Critical alert — 2026-08-25 01:57 UTC
9 new critical CVEs
in the last 5 hours — 9 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-32559CRITICAL
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVSS 9.9
CVE-2026-32563CRITICAL
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVSS 9.8
CVE-2026-78262CRITICAL
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVSS 9.8
CVE-2026-78265CRITICAL
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVSS 9.8
CVE-2026-78267CRITICAL
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVSS 9.8
CVE-2026-32554CRITICAL
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVSS 9.3
CVE-2026-32555CRITICAL
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVSS 9.3
CVE-2026-77635CRITICAL
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respect
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL
CVSS 9.2
CVE-2026-77337CRITICAL
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applicatio
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow a
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: