<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/cvelistv5/10</id>
  <title>Most recent entries from cvelistv5</title>
  <updated>2026-10-03T21:22:22.320492+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-96451</id>
    <title>CVE-2026-96451 — WordPress Ultimate Member plugin &lt;= 2.13.1 - Privilege Escalation vulnerability</title>
    <updated>2026-10-03T15:08:13.855000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ultimate Member</p>
<p>Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-96451"/>
    <published>2026-10-03T15:08:13.855000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103342</id>
    <title>CVE-2026-103342 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin &lt;= 2.0.20 - Cross Site Scripting (X…</title>
    <updated>2026-10-03T15:12:23.526000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unlimited Elements For Elementor (Free Widgets, Addons, Templates)</p>
<p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103342"/>
    <published>2026-10-03T14:00:11.382000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103065</id>
    <title>CVE-2026-103065 — WordPress Kirki plugin &lt;= 6.3.1 - Arbitrary Code Execution vulnerability</title>
    <updated>2026-10-03T15:12:23.648000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Themeum Kirki</p>
<p>Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103065"/>
    <published>2026-10-03T14:00:11.348000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105122</id>
    <title>CVE-2026-105122 — OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri</title>
    <updated>2026-10-03T12:14:45.551000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105122"/>
    <published>2026-10-03T12:14:45.551000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105121</id>
    <title>CVE-2026-105121 — OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping</title>
    <updated>2026-10-03T12:14:44.905000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105121"/>
    <published>2026-10-03T12:14:44.905000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105120</id>
    <title>CVE-2026-105120 — OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint</title>
    <updated>2026-10-03T12:14:44.244000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105120"/>
    <published>2026-10-03T12:14:44.244000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105119</id>
    <title>CVE-2026-105119 — OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows</title>
    <updated>2026-10-03T12:14:43.643000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105119"/>
    <published>2026-10-03T12:14:43.643000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105118</id>
    <title>CVE-2026-105118 — OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession</title>
    <updated>2026-10-03T12:14:43.044000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105118"/>
    <published>2026-10-03T12:14:43.044000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105117</id>
    <title>CVE-2026-105117 — OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions</title>
    <updated>2026-10-03T12:14:42.310000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105117"/>
    <published>2026-10-03T12:14:42.310000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-105116</id>
    <title>CVE-2026-105116 — OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page</title>
    <updated>2026-10-03T12:14:41.631000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OpenIdentityPlatform OpenAM</p>
<p>OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-105116"/>
    <published>2026-10-03T12:14:41.631000+00:00</published>
  </entry>
</feed>
