CVE-2026-27060 is a Deserialization of Untrusted Data vulnerability in ARMember Premium, allowing for Object Injection. The issue affects ARMember Premium from n/a before 7.6. The CVSS score is 8.8 with a severity of HIGH. Administrators and users of ARMember Premium, especially those with sensitive data or high-security requirements, should be aware of this vulnerability and take necessary actions to mit [truncated]
CRITICALRepute InfosystemsCVE published 2026-05-21
CVE-2026-6960 is a critical arbitrary file upload issue in the BookingPress Pro WordPress plugin. The flaw stems from missing file type validation in the bookingpress_validate_submitted_booking_form_func function, and it affects all versions up to and including 5.6. Because the upload path is reachable without authentication, attackers could upload arbitrary files to the server; the public description not [truncated]