CVE-2026-11267
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a
CVSS
4.3
Medio
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 5 jun 2026 · Última mod.: 23 jul 2026 · CWE-602
0.1%EPSS · 30 días0.1%
2026-06-302026-07-25
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium security severity: Low)
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-6481310.0 CRÍ31.9%
——10In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session3dCVE-2026-650516.5 MED20.5%
——6Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.4dCVE-2026-137244.3 MED10.3%
——3Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation.
This issue affects Corporate Training Management System: before dd1a9df64.6dCVE-2026-464858.2 ALT22.7%
——7Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.7dCVE-2026-151304.3 MED6.8%
——2Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)18dCVE-2026-141099.6 CRÍ17.9%
——5Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)25d