Known Vulnerabilities for WP Activity Log by Melapress
Listed below are 2 of the newest known vulnerabilities associated with "WP Activity Log" by "Melapress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56772 json | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private notific... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-56694 json | NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleCha... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-56005 json | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-54806 json | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-53674 json | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-52795 json | Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository ... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-50128 json | Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has ... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-49139 json | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler th... | Not Provided | 2026-06-01 | 2026-06-01 |
| CVE-2026-48518 json | MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the need for local instances... | Not Provided | 2026-06-15 | 2026-06-16 |
| CVE-2026-47693 json | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CS... | Not Provided | 2026-06-23 | 2026-06-24 |