CVE-2026-66463
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
CVSS
7.5
High
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Aug 13, 2026 · Last modified: Aug 14, 2026 · CWE-201
0.3%EPSS · 30 days0.3%
2026-08-142026-08-19
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-63481——
———Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but it carries RequestSpec.cookies created from the dedicated [Cookies] section into the redirected request. An attacker-controlled redirect can therefore receive authentication or session cookies that should remain scoped to the original host. Cookies supplied through a raw Cookie header are stripped and are not affected by this specific path. This issue is reported as fixed in version 8.1.0.3hCVE-2026-75953——
——0Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.1dCVE-2026-733867.5 HIG—
——0Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.8hCVE-2026-733847.5 HIG—
——0Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.4hCVE-2026-740085.3 MED15.4%
——5Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.8hCVE-2026-664437.5 HIG33.1%
——10Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.6d