CVE-2026-57393
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-p
CVSS
6.5
Medio
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 13 jul 2026 · Última mod.: 21 jul 2026 · CWE-497
0.3%EPSS · 30 días0.4%
2026-08-222026-09-19
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-331416.5 MED31.6%
——9IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.1dCVE-2026-275536.5 MED44.1%
——13A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.23hCVE-2026-380588.1 ALT27.3%
——8The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.1dCVE-2026-619114.3 MED12.5%
——4An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.3dCVE-2026-813945.5 MED33.3%
——10Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2dCVE-2026-813875.5 MED35.0%
——11Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.2d