NVD disclosure day

Published threat advisories for August 16, 2026

CVE advisoryCRITICAL

CVE-2026-74791

Scriban Template Cache Stale Data Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Scriban template engine allows cached templates to persist across reused contexts, potentially enabling attackers to access previously rendered content. This occurs when a template context is reset but its cache is not cleared, especially if a request-dependent template loader is used. The risk o

CVE advisoryCRITICAL

CVE-2026-74790

Scriban TemplateContext Cache Bypass Allows Member Exposure

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Scriban templating engine allows attackers to bypass security policies by reusing a `TemplateContext` to access hidden members. This could lead to unauthorized disclosure of sensitive information if the affected technology is used and reachable.

CVE advisoryCRITICAL

CVE-2026-73061

Scriban Access Modifier Bypass Vulnerability Affects Template Engine

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Scriban's TypedObjectAccessor allows template code to bypass access controls, enabling unauthorized modification of object properties, including those with private setters. This could lead to the permanent alteration of live application data if user-supplied templates are processed. Uncertainty exist

CVE advisoryCRITICAL

CVE-2026-72887

Net::OAuth::Client Downgrades OAuth 1.0a to 1.0 Enabling Session Fixation

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in Net::OAuth::Client for Perl where a service provider can silently downgrade OAuth 1.0a to OAuth 1.0, potentially enabling session fixation attacks. This occurs when the provider omits the callback confirmation, causing the `oauth_verifier` to be dropped and allowing an attacker to hijack a use

CVE advisoryCRITICAL

CVE-2026-19349

LemonLDAP NG Authentication Bypass via OAuth2 State Parameter

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Lemonldap::NG::Portal allows authentication bypass via its OAuth2 state parameter when using GitHub or LinkedIn for login, potentially granting unauthenticated access to the portal. This issue affects only configurations with the GitHub or LinkedIn authentication modules enabled, and the impact depends on specific acce

CVE advisoryCRITICAL

CVE-2026-74251

Phoca Cart Unauthenticated SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated SQL injection vulnerability exists in the Phoca Cart Joomla extension, allowing attackers to extract all data from the site's database. This issue is reachable via the public shop items page by exploiting the `a[]` and `s[]` GET parameters without proper sanitization.

CVE advisoryCRITICAL

CVE-2024-13784

ARForms PHP Object Injection Allows File Deletion Data Retrieval or Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A PHP Object Injection vulnerability in the ARForms WordPress plugin allows unauthenticated attackers to inject a PHP Object via form submissions. If a vulnerable component is also present, this could lead to arbitrary file deletion, data retrieval, or code execution.

CVE advisoryCRITICAL

CVE-2026-19725

WPvivid Backup Plugin Log File Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the WPvivid WordPress plugin allows an attacker with a site transfer key to create a log file in any writable directory. This could result in the attacker controlling the location of files on the site, potentially impacting site integrity. The issue arises from a failure to sanitize input used for lo

CVE advisoryCRITICAL

CVE-2026-19714

Simple JWT Login WordPress Plugin Google Token Validation Flaw

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in the Simple JWT Login WordPress plugin, allowing unauthenticated users to bypass authentication by using forged Google identity tokens. This could enable an attacker to log in as any user, including administrators, on affected websites where Google sign-in is enabled. The primary conce

CVE advisoryCRITICAL

CVE-2026-18316

Solace Extra WordPress Plugin Data Corruption Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Solace Extra WordPress plugin has a vulnerability allowing authenticated users to modify or delete site data by exploiting the import_zip() function. This could result in the loss of navigation menus, widgets, theme modifications, or Elementor templates, impacting website content and configuration. The issue is rea

CVE advisoryCRITICAL

CVE-2026-18432

Frontend Admin for WordPress Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability exists in the Frontend Admin plugin for WordPress. This flaw allows unauthenticated attackers to gain administrator privileges by sending a crafted request that bypasses authorization checks. Exploitation can lead to unauthorized control of the website and data.

CVE advisoryCRITICAL

CVE-2026-16098

ProSolution WP Client Arbitrary File Upload Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The ProSolution WP Client plugin for WordPress has a critical arbitrary file upload vulnerability. Unauthenticated attackers can exploit this by uploading and executing arbitrary files, leading to potential remote code execution. The vulnerability is reachable by unauthenticated users on front-end pages using the job p

CVE advisoryCRITICAL

CVE-2026-14524

ProSolution WP Client File Deletion Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the ProSolution WP Client WordPress plugin allows unauthenticated attackers to delete arbitrary files on the server, which could lead to remote code execution. The issue stems from insufficient validation in the file deletion function. This threat is externally exposed and reachable by unauthenticate