CVE-2026-63359
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a spec
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-89
Not enough EPSS history yet.
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-167657.3 HIG—
———A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.5hCVE-2026-65761——
———Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.7hCVE-2026-655327.6 HIG—
——0Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.11hCVE-2026-655268.5 HIG—
——0Contributor SQL Injection in Visualizer <= 4.0.6 versions.11hCVE-2026-654947.1 HIG—
——0Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.13hCVE-2026-654627.6 HIG—
——0Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.12h