,

Vulnerability Watch No19

🔓 Xendit Payment Access-Control Flaw Exposes Unauthenticated Attack Surface
Organizations running Xendit Payment 7.1.0 or earlier should update promptly and review exposed payment endpoints for unauthorized access.
CVE-2026-66473 is an unauthenticated broken access-control vulnerability affecting Xendit Payment versions through 7.1.0. It is rated HIGH with a CVSS score of 7.5 and may allow remote attackers to access functionality or resources without proper authorization.
🔗 Read more 🔗
Source: NVD

🖼️ Contest Gallery Hit by Unauthenticated XSS Vulnerability
Administrators using Contest Gallery 30.0.6 or earlier should patch quickly, especially on public-facing sites that accept untrusted input.
CVE-2026-65447 is an unauthenticated cross-site scripting vulnerability in Contest Gallery versions through 30.0.6. It carries a HIGH severity rating and a CVSS score of 7.1, indicating that attackers may be able to inject scripts that execute in visitors’ browsers.
🔗 Read more 🔗
Source: NVD

📝 Kali Forms Vulnerable to Unauthenticated Script Injection
Sites running Kali Forms 2.4.18 or earlier should upgrade promptly and inspect form submissions or pages for suspicious injected content.
CVE-2026-65446 is an unauthenticated cross-site scripting vulnerability affecting Kali Forms versions through 2.4.18. The issue is rated HIGH with a CVSS score of 7.1 and could let attackers inject browser-executed scripts through vulnerable form functionality.
🔗 Read more 🔗
Source: NVD

💾 BackWPup XSS Flaw Threatens WordPress Administrators
WordPress administrators using BackWPup 5.7.4 or earlier should patch promptly and prioritize internet-facing sites with multiple privileged users.
CVE-2026-65443 is an unauthenticated cross-site scripting vulnerability in BackWPup versions through 5.7.4. It has a HIGH severity rating and a CVSS score of 7.1, potentially allowing malicious scripts to run in the browsers of users who interact with affected content.
🔗 Read more 🔗
Source: NVD

🌐 FormCraft SSRF Flaw Could Reach Internal Services
FormCraft users should update urgently, restrict outbound server access where possible, and review logs for requests targeting internal addresses or cloud metadata services.
CVE-2026-65442 is an unauthenticated server-side request forgery vulnerability affecting FormCraft versions through 3.9.15. It is rated HIGH with a CVSS score of 7.2 and may allow remote attackers to make the server send requests to internal or otherwise restricted destinations.
🔗 Read more 🔗
Source: NVD

📨 Contact Form 7 Add-On Exposes Unauthenticated XSS
Administrators running version 1.6.3.9 or earlier should patch promptly and check contact-form content for unexpected markup or scripts.
CVE-2026-65438 is an unauthenticated cross-site scripting vulnerability in Message Filter for Contact Form 7 versions through 1.6.3.9. The vulnerability is rated HIGH with a CVSS score of 7.1 and could enable attackers to inject scripts that execute in a user’s browser.
🔗 Read more 🔗
Source: NVD

🛡️ CleanTalk Security Plugin Affected by Unauthenticated XSS
CleanTalk users on version 6.82 or earlier should upgrade promptly, particularly on high-traffic public sites where attackers can reach exposed inputs.
CVE-2026-65437 is an unauthenticated cross-site scripting vulnerability affecting Spam protection, AntiSpam, FireWall by CleanTalk versions through 6.82. It is classified as HIGH severity with a CVSS score of 7.1 and may permit malicious script execution in the browsers of affected users.
🔗 Read more 🔗
Source: NVD

🔢 miniOrange OTP Verification Plugin Contains High-Severity XSS
Sites using miniOrange OTP Verification 5.5.1 or earlier should patch promptly and review authentication-related pages for injected content.
CVE-2026-61957 is an unauthenticated cross-site scripting vulnerability in miniOrange OTP Verification versions through 5.5.1. It has a HIGH severity rating and a CVSS score of 7.1, creating a risk that attacker-controlled scripts could execute in users’ browsers.
🔗 Read more 🔗
Source: NVD

🔗 Simple Link Directory Pro SSRF Opens Path to Internal Resources
Administrators should update Simple Link Directory Pro urgently, limit outbound requests from the web server, and investigate access to private IP ranges or metadata endpoints.
CVE-2026-61953 is an unauthenticated server-side request forgery vulnerability in Simple Link Directory Pro versions through 15.0.6. The issue is rated HIGH with a CVSS score of 7.2 and could allow attackers to direct server-side requests toward internal systems or protected network locations.
🔗 Read more 🔗
Source: NVD

🚦 React Router Manifest Endpoint Enables Server Resource Exhaustion
Teams running affected React Router configurations should upgrade to 7.18.0 immediately, especially for internet-facing services where repeated requests could disrupt availability.
CVE-2026-55685 affects React Router versions 7.0.0 through 7.17.0 and allows targeted unauthenticated requests to the manifest endpoint to place heavy load on a server and slow responses. The vulnerability is rated HIGH with a CVSS score of 8.7 and is a follow-up to CVE-2026-42342. Applications using Declarative Mode with BrowserRouter or Data Mode with createBrowserRouter and RouterProvider are not affected, and the issue is fixed in version 7.18.0.
🔗 Read more 🔗
Source: NVD

💥 Critical Stored XSS in Capture Tree Visualization
Operators of the affected application should deploy the patch immediately and treat previously captured untrusted web content as potentially malicious. Review privileged-user sessions and capture records for signs of injected scripts.
CVE-2026-66824 is a stored cross-site scripting vulnerability in an application’s capture tree visualization page, where serialized capture data was embedded directly into inline JavaScript using the Jinja safe filter. Attacker-controlled content could terminate the surrounding script element and inject arbitrary HTML or JavaScript that executes when a user views the affected capture tree. Rated CRITICAL with a CVSS score of 9.2, successful exploitation could abuse the victim’s authenticated session, expose accessible information, or modify data within the victim’s permissions.
🔗 Read more 🔗
Source: NVD

🍎 Apple File-Processing Buffer Overflow May Enable Code Execution
Apple users and managed-device fleets should install the listed operating-system updates promptly and avoid opening untrusted files until systems are patched.
CVE-2026-43776 is a buffer-overflow vulnerability affecting Apple platforms when processing a maliciously crafted file. It is rated HIGH with a CVSS score of 7.8 and may cause unexpected application termination or arbitrary code execution. Apple addressed the issue with improved bounds checking in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6.
🔗 Read more 🔗
Source: NVD