Skip to content
Multiple Critical Vulnerabilities Disclosed Affecting Various Products

Multiple Critical Vulnerabilities Disclosed Affecting Various Products

First seen 16 Jun 2026, 18:14 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 18:13 UTC
  • Six critical vulnerabilities disclosed, all with CVSS scores of 9.8 or higher.
  • CVE-2026-25775 allows unauthorized firmware updates on SenseLive X3050 devices.
  • CVE-2026-8935 enables the creation of admin accounts in WP MAPS PRO without authentication.

A series of critical vulnerabilities (CVEs) have been disclosed affecting multiple products, all with a CVSS score of 9.8. CVE-2026-25775 allows unauthorized firmware operations on SenseLive X3050. CVE-2026-8935 enables unauthenticated admin account creation in WP MAPS PRO. CVE-2026-50890 features a SQL injection flaw in grocy v4.6.0, exposing sensitive data. CVE-2026-49105 involves unauthenticated PHP Object Injection in several WordPress plugins. CVE-2026-50886 presents incorrect access control in Project Firefly III. These vulnerabilities could lead to severe breaches if exploited. All vulnerabilities were validated by three independent sources before publication.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 95d ago How this analysis works

Timeline

2026-04-24
CVE-2026-25775 published
Vulnerability in SenseLive X3050 allows unauthorized firmware operations without authentication.
Lyrie.Ai
2026-06-15
CVE-2026-8935 published
WP MAPS PRO plugin allows unauthenticated admin account creation via AJAX action.
Lyrie.Ai
2026-06-15
CVE-2026-50890 published
SQL injection vulnerability in grocy v4.6.0 allows access to sensitive database information.
Lyrie.Ai
2026-06-15
CVE-2026-50886 published
Incorrect access control in Project Firefly III allows internal resource scanning.
Lyrie.Ai
2026-06-15
CVE-2026-49105 published
Unauthenticated PHP Object Injection vulnerability affects multiple WordPress plugins.
Lyrie.Ai
2026-06-15
CVE-2026-39530 published
Vulnerability details not specified, but confirmed by multiple sources.
Lyrie.Ai

More articles in this cluster (18)

Following this threat?

Track CVE-2026-25775 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed