CVE-2026-74002
5.3 MEDIUM 5.3Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window …
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.