NuytsTech Security

CVE-2026-0627

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file...

CVE-2026-21409

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by...

CVE-2026-0563

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgsv_map’ shortcode in all versions up to, and...

CVE-2026-22714

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – Monaco Skin allows Cross-Site Scripting (XSS).This issue affects Mediawiki – Monaco Skin: 1.45, 1.44, 1.43,...

CVE-2026-22713

Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in The Wikimedia Foundation Mediawiki – GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki – GrowthExperiments Extension: 1.45, 1.44, 1.43,...