PULSE
FEED
ransomakira reclama a The Official Collegeof Architects of León (COAL) · MX · Professional Servicesransomspirals reclama a seven seas group · GB · Otherransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcareransomakira reclama a The Official Collegeof Architects of León (COAL) · MX · Professional Servicesransomspirals reclama a seven seas group · GB · Otherransomqilin reclama a Thai Lion Air · TH · Transportationransomrhysida reclama a Mat Bao Corporation · VN · Technologyransompanzer reclama a Paessolucoes · BR · Otherransomrhysida reclama a Electro Heat Sweden AB · SE · Energy & Utilitiesransomqilin reclama a Sports Events365 · GB · Hospitalityransomauditteam reclama a Ad***ng · AE · Technologyransomakira reclama a The Official College of Architects of León (COAL) · MX · Professional Servicesransomakira reclama a Jampac Alimentos · BR · Agriculture and Food Productionransomakira reclama a Pacific Tank Lines · US · Transportationransomqilin reclama a Inova Semiconductors GmbH · DE · Manufacturingransombooba project reclama a Raleigh Family Medicine · US · Healthcareransombooba project reclama a EdgeEndo® USA · US · Healthcare
← Todos los CVEs
CVE Watch1 oct 2026

CVE-2026-62058

Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensi

CVSS

5.3

Medio

EPSS

0.2%

p9

KEV

—

Exploit Today

3

0-100

Publicado: 1 oct 2026 · Última mod.: 1 oct 2026 · CWE-201

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1039576.2 MED
—
——0Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication. To remediate this issue, users should upgrade to version 1.7.0 or later.14h
CVE-2026-325845.3 MED
—
——0Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import & Export: from n/a through 1.4.3.17h
CVE-2026-101322—
21.9%
——7In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924.2d
CVE-2026-1033455.3 MED
8.5%
——3Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a through 3.8.4.13.2d
CVE-2026-1033365.3 MED
8.5%
——3Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.2d
CVE-2026-1032815.4 MED
4.1%
——1Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege staff user can read API keys returned by the Admin API, which are intended to be available only to higher-privileged users.2d