CVE-2026-61948 - Unauthenticated SQL Injection in Mini Cart Coupon REST Endpoint
Unauthenticated SQL injection in WPDM Premium Packages <= 6.2.0 exposes the public Mini Cart coupon REST endpoint to blind time-based database extraction.
Unauthenticated SQL injection in WPDM Premium Packages <= 6.2.0 exposes the public Mini Cart coupon REST endpoint to blind time-based database extraction.
Unauthenticated webhook forgery in Peach Payments Gateway <= 4.0.2 lets attackers mark pending WooCommerce orders as paid by submitting a forged successful payment result.
Stored XSS in reCAPTCHA for Asgaros Forum <= 1.1.0 lets a low-privilege Subscriber inject JavaScript through the reCAPTCHA site key rendered in the forum editor.
Broken authentication in Colissimo Officiel <= 2.9.0 exposes shipping-rate import/export actions to unauthenticated visitors via the shared admin-ajax dispatcher.
CTF writeup - web/Ganzir (OmniCTF 2026)
CTF writeup - web/StayWild (OmniCTF 2026)
CTF writeup - web_<_w+ (SekaiCTF 2026)
CTF writeup - web/migurimental (SekaiCTF 2026)
IDOR in SupportCandy <= 3.4.6 lets a low-privilege user reassign and download another user's private ticket attachments via the thread-creation endpoint.
Broken access control in Newsletters <= 4.13 lets an unauthenticated attacker take over any subscriber's management account via a predictable md5(id) token.
Broken authentication in Melhor Envio <= 2.16.3 lets a low-privilege Subscriber read and overwrite the store's Melhor Envio API tokens.
Broken authentication in Masteriyo LMS 2.1.8 allows unauthenticated attackers to forge Lemon Squeezy webhooks and mark pending orders as paid.
CTF writeup - cookoff (GPNCTF 2026)
CTF writeup - Fancy Food Notifications (GPNCTF 2026)
CTF writeup - Pharry (GPNCTF 2026)
CTF writeup - recipeloader (GPNCTF 2026)
CTF writeup - restaurant-builder (GPNCTF 2026)
CTF writeup - SecretPickle (GPNCTF 2026)
CTF writeup - Secure Secretpickle (GPNCTF 2026)
CTF writeup - Simple food notifications (GPNCTF 2026)
CTF writeup - web/chained (TJCTF 2026)
CTF writeup - web/free-cloud-storage (TJCTF 2026)
CTF writeup - web/paper-trail (TJCTF 2026)
CTF writeup - web/treasure-hunt (TJCTF 2026)
CTF writeup - web/Vibed Intranet Part 1&2 (TJCTF 2026)
CTF writeup - web/vibecoded (TJCTF 2026)
CTF writeup - Brick by Brick (UMassCTF 2026)
CTF writeup - BrOWSER BOSS FIGHT (UMassCTF 2026)
CTF writeup - ORDER66 (UMassCTF 2026)
CTF writeup - Break the Bank (UTCTF 2026)
CTF writeup - Crab Mentality (UTCTF 2026)
CTF writeup - Time to Pretend (UTCTF 2026)