Retour à la veille

CVE-2026-15402

Publié : 15 septembre 2026
Modifié : 15 septembre 2026
Lien officiel NVD
Score CVSS
6.4
MEDIUM

Description détaillée

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Références et Patchs

https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/base/post-model.php#L202https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/AccessControl/Permission.php#L297https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/schedule/Api/ScheduleController.php#L253https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/core/schedule/Api/ScheduleController.php#L516https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/templates/event/schedule-list.php#L115https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/utils/functions.php#L47https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.15/utils/helper.php#L78https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/base/post-model.php#L202https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/core/AccessControl/Permission.php#L297https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/core/schedule/Api/ScheduleController.php#L253https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/core/schedule/Api/ScheduleController.php#L516https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/templates/event/schedule-list.php#L115https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/utils/functions.php#L47https://plugins.trac.wordpress.org/browser/wp-event-solution/tags/4.1.16/utils/helper.php#L78https://plugins.trac.wordpress.org/changeset?reponame=&old=3689867%40wp-event-solution&new=3689867%40wp-event-solutionhttps://www.wordfence.com/threat-intel/vulnerabilities/id/a07070b6-37d2-4ccf-ae81-a08ac7b76241?source=cve

Dernières Vulnérabilités

CVE-2026-91819

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and DELETE, CakePHP also clears the parsed request body. MISP’s security component then determines whether to perform _validatePost() and _validateCsrf() based on whether request data remains. With a value such as: _method=GET the body becomes empty before those checks run, so both protections are skipped. A cross-site form containing only that override can therefore reach actions whose parameters are taken from the URL rather than the request body Version affected: ≤2.5.45

VOIR DÉTAILS

CVE-2026-91778

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the user possessing the required authorisation.

VOIR DÉTAILS

CVE-2026-91091

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.

VOIR DÉTAILS