Security Advisory: CVE-2026-49954 - High - Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory

Severity: High (CVSS 8.6) Affected Systems: Affected products listed by OpenCVE and the vendor advisory Overview Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory A high vulnerability identified as CVE-2026-49954 has been disclosed. Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion ... Read More »

16th Jun 2026
Security Advisory: CVE-2026-49952 - Critical - Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle

Severity: Critical (CVSS 9.3) Affected Systems: Affected products listed by OpenCVE and the vendor advisory Overview Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle A critical vulnerability identified as CVE-2026-49952 has been disclosed. Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass ... Read More »

16th Jun 2026
Security Advisory: CVE-2026-12225 - High - syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent

Severity: High (CVSS 8.7) Affected Systems: Affected products listed by OpenCVE and the vendor advisory Overview syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent A high vulnerability identified as CVE-2026-12225 has been disclosed. syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket ... Read More »

16th Jun 2026
Security Advisory: CVE-2026-5513 - High - Online Scheduling and Appointment Booking System – Bookly

Severity: High (CVSS 7.2) Affected Systems: Ladela Online Scheduling And Appointment Booking System – Bookly; Wordpress Wordpress Overview Online Scheduling and Appointment Booking System – Bookly A high vulnerability identified as CVE-2026-5513 has been disclosed. The Online Scheduling and Appointment Booking System – Bookly plugin for ... Read More »

13th Jun 2026