View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical Icollect flaws enable unauthenticated file read and SSRF

🔓 CVEs & KEV

  • CVE-2026-77012 — CVSS 9.3 — Icollect through 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traver...

  • CVE-2026-76548 — CVSS 8.2 — Profile Builder before 4.0.1 - Unauthenticated Unpublished Content and Media Modif...

  • CVE-2026-77007 — CVSS 7.5 — HEL Online Classroom: AI-powered Online Classrooms through 1.0.3 - Unauthenticated...

  • CVE-2026-76586 — CVSS 7.5 — BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via P...

  • CVE-2026-76546 — CVSS 6.8 — Profile Builder before 4.0.1 - Contributor+ Stored XSS via Format Date ShortcodeTh...

  • CVE-2026-76547 — CVSS 6.6 — Profile Builder before 4.0.1 - Admin+ PHP Object Injection via Import/ExportThe Us...

  • CVE-2026-77010 — CVSS 6.5 — HEL Online Classroom: AI-powered Online Classrooms through 1.0.3 - Unauthenticated...

  • CVE-2026-77008 — CVSS 6.5 — HEL Online Classroom: AI-powered Online Classrooms through 1.0.3 - Unauthenticated...

  • CVE-2026-18234 — CVSS 6.5 — MStore API before 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via WalletTh...

  • CVE-2026-18233 — CVSS 6.5 — MStore API before 4.21.1 - Subscriber+ Arbitrary Order CompletionThe MStore API Wo...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check