Tag
#Code Injection
Critical Code Injection Vulnerability in Customer Support Ticket System & Helpdesk Plugin for WordPress (CVE-2026-15011)
A critical vulnerability (CVE-2026-15011, CVSS score: 9.8) exists in the Customer Support Ticket System & Helpdesk plugin for WordPress, allowing unauthenticated attackers to inject arbitrary PHP code. This vulnerability affects all versions up to and including 6.0.5. Immediate action is required to prevent potential site disruption and data exposure.
CVE-2026-16204: Remote Code Injection in zevorn rt-claw
A code injection vulnerability has been discovered in zevorn rt-claw up to 0.2.0, affecting the Telegram-to-AI Tool Execution Flow. The vulnerability has a CVSS score of 6.3 and can be exploited remotely. Affected versions include 0.1 and 0.2.0.
AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin
A high-severity vulnerability (CVE-2026-47252) exists in the AnyQuery plugin, allowing an authenticated user to inject arbitrary AppleScript statements via an unescaped URL in the macOS Chrome plugin, leading to OS-level command execution.