CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-107459 — The SecuShare Pro developed by Openfind has an OS Command Injection vulnerabilit...

·Source: NIST NVD

Updated:

Executive Summary

The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

Analysis

The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. CVSS Score: 9.8. Published: 2026-10-08T06:16:42.000.

Indicators of Compromise (1)

CVE (1)
CVE-2026-107459
Source Attribution

Originally published by NIST NVD on Oct 8, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-85097 — The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary ...

The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including, 3.1.8.9. This is due to insufficient validation of the attacker-controlled URL field in the 'temporaryFileUploads' parameter during form submission. An unauthenticated attacker can first obtain a valid nonce via the bricksforge_regenerate_nonce AJAX endpoint, then upload a

CVE-2026-85097
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-17609 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the t

CVE-2026-17609
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-17196 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. Thi

CVE-2026-17196
NIST NVD