PatchSiren

BoldGrid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM BoldGrid CVE published 2026-07-13

CVE-2026-57418

A Missing Authorization vulnerability was found in BoldGrid Client Invoicing by Sprout Invoices. This issue, tracked as CVE-2026-57418, allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability affects Client Invoicing by Sprout Invoices versions from n/a through <= 20.8.13. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It is caused by a M [truncated]

HIGH boldgrid CVE published 2026-07-11

CVE-2026-9282

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability exists due to insufficient validation of user-supplied input, allowing attackers to acces [truncated]

MEDIUM BoldGrid CVE published 2026-06-17

CVE-2026-39595

CVE-2026-39595 is a medium-severity vulnerability (CVSS score of 4.7) affecting the W3 Total Cache plugin for WordPress, specifically versions up to 2.9.1. The issue is classified as 'Author Broken Access Control,' indicating a problem with access control mechanisms that could allow unauthorized users to perform actions they shouldn't be able to. This vulnerability was made public on June 17, 2026. Given [truncated]