Known Vulnerabilities for WP Travel by Unknown
Listed below are 10 of the newest known vulnerabilities associated with "WP Travel" by "Unknown".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78255 json | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-62945 json | TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-59548 json | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | Not Provided | 2026-07-27 | 2026-07-27 |
| CVE-2026-56059 json | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-54808 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gut... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-54509 json | TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/rout... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-54508 json | TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following ... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-54505 json | TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped a... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-49770 json | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-49078 json | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | Not Provided | 2026-06-15 | 2026-06-15 |