CVE-2026-39516
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block
CVSS
5.3
Medio
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Publicado: 8 abr 2026 · Última mod.: 24 jul 2026 · CWE-497
0.2%EPSS · 30 días0.2%
2026-07-292026-08-26
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through <= 4.7.0.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-782687.5 ALT16.2%
——5Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.2dCVE-2026-759285.3 MED31.9%
——10The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.6dCVE-2026-672675.5 MED1.0%
——0Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.6dCVE-2026-740075.3 MED14.9%
——4Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.7dCVE-2026-324687.5 ALT22.4%
——7Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.7dCVE-2024-583757.5 ALT16.7%
——5OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.10d