Lyrie.Ai
Multiple Critical Vulnerabilities Disclosed Affecting Various Products
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A series of critical vulnerabilities (CVEs) have been disclosed affecting multiple products, all with a CVSS score of 9.8. CVE-2026-25775 allows unauthorized firmware operations on SenseLive X3050. CVE-2026-8935 enables unauthenticated admin account creation in WP MAPS PRO. CVE-2026-50890 features a SQL injection flaw in grocy v4.6.0, exposing sensitive data. CVE-2026-49105 involves unauthenticated PHP Object Injection in several WordPress plugins. CVE-2026-50886 presents incorrect access control in Project Firefly III. These vulnerabilities could lead to severe breaches if exploited. All vulnerabilities were validated by three independent sources before publication.
Key Points: • Six critical vulnerabilities disclosed, all with CVSS scores of 9.8 or higher. • CVE-2026-25775 allows unauthorized firmware updates on SenseLive X3050 devices. • CVE-2026-8935 enables the creation of admin accounts in WP MAPS PRO without authentication.