Application Security Detections Published in April 2026

Hitesh Kadu

Table of Contents

In April, Qualys Web Application Scanning released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:

OpenSSL, Apache Traffic Server, Liferay, WordPress, Apache Airflow, NetScaler, F5, Apache Camel, vLLM, MLflow, DNN, Qwik, Fortinet, Grafana, GitLab, Zabbix, Apache ActiveMQ, Apache Tomcat, Microsoft SharePoint, Adobe, Nginx, Oracle, Apache APISIX, JetBrains, Joomla

Details about the following QIDs can be found in our knowledge base. Please review the reports for the scanned applications for these detections and, if any are identified, follow the steps in the knowledge base to ensure the applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities upon detection should be a priority for all organizations. If left unaddressed, these vulnerabilities can pose security risks, including breaches, unauthorized access, and various malicious activities.

QIDTitle
520129OpenSSL TLS Key Exchange Negotiation Failure (CVE-2026-2673)
520130OpenSSL Uninitialized Memory Leak via Cryptographic Key Encapsulation (CVE-2026-31790)
520131Apache Traffic Server Request Smuggling Vulnerability (CVE-2025-65114)
520132Liferay Portal Improper Access Control Vulnerability (CVE-2025-62276)
520133Liferay Portal Multiple Cross-Site Scripting Vulnerabilities (CVE-2025-62267)
520134Liferay Portal Cross-Site Scripting Vulnerability (CVE-2025-62264)
520135Liferay Portal Improper Access Control Vulnerability (CVE-2025-62259)
520136Liferay Portal Cross-Site Request Forgery Vulnerability (CVE-2025-62258)
520137Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2025-62261)
520138Liferay Portal Denial of Service Vulnerability (CVE-2025-62260)
520139Liferay Portal Information Exposure Vulnerability (CVE-2025-62262)
520140Liferay Portal Multiple Cross-Site Scripting Vulnerabilities (CVE-2025-62263)
520141Liferay Portal Open Redirect Vulnerability (CVE-2025-62253)
520142Liferay Portal Denial of Service Vulnerability (CVE-2025-62254)
531065WordPress Handyman Theme: PHP Object Injection Vulnerability (CVE-2026-22451)
531066WordPress Kali Forms Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-3584)
531067WordPress Equestrian Centre Theme: PHP Object Injection Vulnerability (CVE-2026-22474)
531068WordPress Estate Theme: PHP Object Injection Vulnerability (CVE-2026-22475)
531072Apache Airflow Session Hijacking Vulnerability (CVE-2026-28779)
531073Apache Airflow Missing Authorization Vulnerability (CVE-2026-26929)
531074Apache Airflow Authorization Bypass Vulnerability (CVE-2026-28563)
531075WordPress Mounthood Theme: PHP Object Injection Vulnerability (CVE-2026-22501)
531076WordPress Contact Form Entries Plugin: PHP Object Injection Vulnerability (CVE-2026-2599)
531077WordPress Tutor LMS Pro Plugin: Authentication Bypass Vulnerability (CVE-2026-0953)
531078WordPress WowOptin Plugin: Missing Authorization Vulnerability (CVE-2026-1720)
531079NetScaler Application Delivery Controller (ADC) and NetScaler Gateway Memory Overread Vulnerability (CVE-2026-3055)
531080F5 BIG-IP APM Remote Code Execution (RCE) Vulnerability (CVE-2025-53521)
531081NetScaler Application Delivery Controller (ADC) and NetScaler Gateway Race Condition Vulnerability (CVE-2026-4368)
531082WordPress ExactMetrics Plugin: Improper Privilege Management Vulnerability (CVE-2026-1993)
531083WordPress ExactMetrics Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-1992)
531084WordPress Royal Elementor Addons Plugin: Arbitrary File Upload Vulnerability (CVE-2025-13067)
531085WordPress Dental Clinic Theme: PHP Object Injection Vulnerability (CVE-2026-22473)
531086Apache Camel Improper JWT Issuer Validation Vulnerability (CVE-2026-23552)
531087vLLM Remote Code Execution (RCE) Vulnerability (CVE-2026-27893)
531088MLflow Path Traversal Vulnerability (CVE-2025-15036)
531089WordPress Secudeal Payments for Ecommerce Plugin: PHP Object Injection Vulnerability (CVE-2026-22471)
531090WordPress Prowess Theme: Local File Inclusion Vulnerability (CVE-2026-22446)
531091WordPress Grand Wedding Theme: PHP Object Injection Vulnerability (CVE-2026-22417)
531092WordPress Askka Theme: Local File Inclusion Vulnerability (CVE-2026-22456)
531093WordPress FormGent Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-22460)
531094DNN Cross-Site Scripting Vulnerabilities (CVE-2025-48378, CVE-2025-48377)
531095DNN Denial of Service Vulnerability (CVE-2025-32374)
531096DNN Improper Access Control Vulnerability (CVE-2025-32373)
531097WordPress Don Peppe Theme: Local File Inclusion Vulnerability (CVE-2026-22449)
531098WordPress ProfilePress Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-3453)
531099WordPress Drag and Drop Plugin: Arbitrary File Upload Vulnerability (CVE-2026-3459)
531100WordPress Membership Plugin: Privilege Escalation Vulnerability (CVE-2026-1321)
531101DNN Server-Side Request Forgery Vulnerability (CVE-2025-32372)
531102DNN Improper Input Handling Vulnerability (CVE-2025-32371)
531103DNN Captcha Bypass Vulnerability (CVE-2025-32036)
531104DNN File Upload Bypass Vulnerability (CVE-2025-32035)
531106WordPress Everest Forms Pro Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-3300)
531107WordPress WP DSGVO Tools Plugin: Missing Authorization Vulnerability (CVE-2026-4283)
531108WordPress Contact Form Plugin: Server-Side Template Injection (SSTI) Vulnerability (CVE-2026-4257)
531109WordPress Pix for WooCommerce Plugin: Arbitrary File Upload Vulnerability (CVE-2026-3891)
531110MLflow Command Injection Vulnerability (CVE-2025-15379)
531111Qwik Remote Code Execution Vulnerability (CVE-2026-27971)
531112Fortinet FortiClientEMS Improper Access Control Vulnerability (CVE-2026-35616)
531113WordPress NextGEN Gallery Plugin: Local File Inclusion Vulnerability (CVE-2026-1463)
531114WordPress Ultimate Member Plugin: Account Takeover Vulnerability (CVE-2026-4248)
531115WordPress Import and Export Users Plugin: Privilege Escalation Vulnerability (CVE-2026-3629)
531116Grafana Remote Code Execution Vulnerability (CVE-2026-27876)
531117GitLab CE/EE Server-Side Request Forgery Vulnerability (CVE-2021-22175)
531118Zabbix API SQL Injection Vulnerability (CVE-2026-23921)
531119WordPress MW WP Form Plugin: Arbitrary File Move Vulnerability (CVE-2026-4347)
531120WordPress WC Frontend Manager Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-4896)
531121WordPress Jupiter X Core Plugin: File Upload Vulnerability (CVE-2026-3533)
531122Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2026-34197)
531123WordPress WP Job Portal Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-4758)
531124WordPress Contest Gallery Plugin: Account Takeover Vulnerability (CVE-2026-4021)
531125WordPress CMS Commander Plugin: SQL Injection Vulnerability (CVE-2026-3334)
531126DNN Path Traversal Vulnerability (CVE-2022-2922)
531127DNN Cross-Site Scripting Vulnerability (CVE-2021-31858)
531128WordPress Everest Forms Plugin: PHP Object Injection Vulnerability (CVE-2026-3296)
531129WordPress Masteriyo LMS Plugin: Privilege Escalation Vulnerability (CVE-2026-4484)
531130Apache Airflow JWT Tokens Remain Valid After Logout Vulnerability (CVE-2025-57735)
531131Apache Airflow Authorization Bypass Vulnerability (CVE-2026-34538)
531132React Server Components Remote Code Execution (RCE) Vulnerability (CVE-2025-55182) (Error Digest Detection)
531133Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2026-24880)
531134WordPress MimeTypes Link Icons Plugin: Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-1313)
531135WordPress KiviCare Plugin: Privilege Escalation Vulnerability (CVE-2026-2992)
531136Apache Tomcat OCSP Validation Bypass Vulnerability (CVE-2026-34500)
531137DNN Server-Side Request Forgery Vulnerability (CVE-2021-40186)
531138DNN Multiple Vulnerabilities (CVE-2020-5186, CVE-2020-5187, CVE-2020-5188)
531139WordPress Expire Users Plugin: Privilege Escalation Vulnerability (CVE-2026-4261)
531140WordPress WP Extended Plugin: Privilege Escalation Vulnerability (CVE-2026-4314)
531141WordPress Quick Playground Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-1830)
531142WordPress W3 Total Cache Plugin: Sensitive Information Exposure Vulnerability (CVE-2026-5032)
531143WordPress Formidable Forms Plugin: Payment Integrity Bypass Vulnerability (CVE-2026-2890)
531144DNN Cross-Site Scripting Vulnerability (CVE-2019-12562)
531145DNN Multiple Vulnerabilities (CVE-2018-18326, CVE-2018-18325)
531146DNN Multiple Vulnerabilities (CVE-2018-15812, CVE-2018-15811)
531147DNN Cross-Site Scripting Vulnerability (CVE-2018-14486)
531148DNN Server-Side Request Forgery Vulnerability (CVE-2017-0929)
531149DNN Information Disclosure Vulnerability (CVE-2020-11585)
531150Microsoft SharePoint Server Spoofing Vulnerability (CVE-2026-32201)
531152Apache ActiveMQ Denial of Service Vulnerability (CVE-2026-39304)
531153Apache ActiveMQ Integer Overflow Vulnerability (CVE-2026-40046)
531154WordPress Query Monitor Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-4267)
531155WordPress Post SMTP Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-3090)
531156WordPress SlimStat Analytics Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-1238)
531157WordPress Download Monitor Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-3124)
531158WordPress WP Maps Plugin: SQL Injection Vulnerability (CVE-2026-2580)
531159WordPress Appointment Booking Calendar Plugin: Sensitive Information Exposure Vulnerability (CVE-2026-3045)
531160WordPress Appointment Booking Calendar Plugin: SQL Injection Vulnerability (CVE-2026-3658)
531161WordPress SureForms Plugin: Payment Amount Validation Bypass Vulnerability (CVE-2026-4987)
531162WordPress LearnPress Plugin: Missing Authorization Vulnerability (CVE-2026-4365)
531163WordPress Visa Acceptance Solutions Plugin: Authentication Bypass Vulnerability (CVE-2026-3461)
531164Adobe Connect Insecure Deserialization Vulnerabilities
531165Adobe Connect Cross-Site Scripting Vulnerabilities
531166WordPress Barcode Scanner Plugin: Privilege Escalation Vulnerability (CVE-2026-4880)
531167WordPress DSGVO Google Web Fonts Plugin: Arbitrary File Upload Vulnerability (CVE-2026-3535)
531168WordPress ProSolution WP Client Plugin: Arbitrary File Upload Vulnerability (CVE-2026-2942)
531169WordPress Riaxe Product Customizer Plugin: Privilege Escalation Vulnerability (CVE-2026-3596)
531170WordPress Users Manager Plugin: Privilege Escalation Vulnerability (CVE-2026-4003)
531171WordPress Addons for Elementor Plugin: Local File Inclusion Vulnerability (CVE-2026-1620)
531172Apache Tomcat Open Redirect Vulnerability (CVE-2026-25854)
531173Apache Tomcat Cipher Misconfiguration Vulnerability (CVE-2026-29129)
531174Apache Tomcat Client Certificate Authentication Flaw Vulnerability (CVE-2026-29145)
531175Apache Tomcat Padding Oracle Attack Vulnerability (CVE-2026-29146)
531176Apache Tomcat Improper Input Validation Vulnerability (CVE-2026-32990)
531177Apache Tomcat Improper Output Encoding Vulnerability (CVE-2026-34483)
531178Apache Tomcat Missing Encryption Vulnerability (CVE-2026-34486)
531179Apache Tomcat Sensitive Info Logging Vulnerability (CVE-2026-34487)
531180Nginx UI Improper Integrity Verification Vulnerability (CVE-2026-33026)
531181Nginx UI Missing Authentication Vulnerability (CVE-2026-33032)
531182Nginx UI Insecure Direct Object Reference Vulnerability (CVE-2026-33030)
531183Nginx UI Improper Input Validation Vulnerability (CVE-2026-33029)
531184Nginx UI Race Condition Vulnerability (CVE-2026-33028)
531185Nginx UI Improper Path Validation Vulnerability (CVE-2026-33027)
531186WordPress Product Feed PRO for WooCommerce Plugin: Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2026-3499)
531187WordPress MW WP Form Plugin: Arbitrary File Move Vulnerability (CVE-2026-5436)
531188WordPress Amelia Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-5465)
531189WordPress AcyMailing Plugin: Privilege Escalation Vulnerability (CVE-2026-3614)
531190WordPress BuddyPress Groupblog Plugin: Privilege Escalation Vulnerability (CVE-2026-5144)
531191WordPress Visitor Traffic Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-2936)
531192WordPress JetFormBuilder Plugin: Arbitrary File Read Vulnerability (CVE-2026-4373)
531193Fortinet FortiSandbox OS Command Injection Vulnerability (CVE-2026-39808)
531194Fortinet FortiSandbox Path Traversal Vulnerability (CVE-2026-39813)
531195Fortinet FortiWeb Out-Of-Bounds Write Vulnerability (CVE-2026-40688)
531196Apache HTTP CGI Environment Variable Override Vulnerability (CVE-2025-65082)
531197WordPress RegistrationMagic Plugin: Authentication Bypass Vulnerability (CVE-2026-24373)
531198WordPress Post Snippets Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-25001)
531199WordPress WeForms Plugin: PHP Object Injection Vulnerability (CVE-2026-32484)
531200WordPress EventPrime Plugin: PHP Object Injection Vulnerability (CVE-2026-24378)
531201WordPress BackWPup Plugin: Local File Inclusion Vulnerability (CVE-2026-6227)
531202WordPress ProfilePress Plugin: Membership Payment Bypass Vulnerability (CVE-2026-3445)
531203DNN Improper Authorization Vulnerability (CVE-2026-40305)
531204DNN Cross-Site Scripting Vulnerability (CVE-2026-40321)
531205Microsoft SharePoint Server Spoofing Vulnerability (CVE-2026-20945)
531206Oracle WebLogic Server Multiple Vulnerabilities (CPU-APR2026)
531207Apache APISIX Header Injection Vulnerability (CVE-2026-31908)
531208WordPress Optimole Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-5217)
531209WordPress Form Maker Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-4388)
531210WordPress Tutor LMS Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-3360)
531211WordPress WpForo Forum Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-3666)
531212WordPress WpForo Forum Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-5809)
531213WordPress Popup Box Plugin: Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2025-15611)
531214WordPress Visual Portfolio Plugin: Local File Inclusion Vulnerability (CVE-2026-32537)
531215WordPress SMTP Mailer Plugin: Sensitive Information Exposure Vulnerability (CVE-2026-32538)
531216Adobe ColdFusion Arbitrary Code Execution Vulnerability (CVE-2026-27304)
531217Adobe ColdFusion Path Traversal Vulnerability (CVE-2026-27305)
531218Adobe ColdFusion Improper Input Validation Vulnerability (CVE-2026-27282)
531219Adobe ColdFusion Arbitrary Code Execution Vulnerability (CVE-2026-27306)
531220Adobe ColdFusion Path Traversal Vulnerability (CVE-2026-34619)
531221Adobe ColdFusion Uncontrolled Resource Consumption (DoS) Vulnerabilities (CVE-2026-27307, CVE-2026-27308)
531222WordPress WPBot Plugin: SQL Injection Vulnerability (CVE-2026-32499)
531223WordPress Frontend Admin Plugin: PHP Object Injection Vulnerability (CVE-2026-3328)
531224WordPress Blackhole Bad Bots Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-4329)
531225WordPress Lead Form Builder Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-32532)
531226WordPress PublishPress Revisions Plugin: SQL Injection Vulnerability (CVE-2026-32539)
531227WordPress Smart Post Show Plugin: PHP Object Injection Vulnerability (CVE-2026-3017)
531228WordPress ReviewX Plugin: Arbitrary Method Call Vulnerability (CVE-2025-10679)
531229Apache APISIX Cleartext Transmission of Sensitive Information Vulnerability (CVE-2026-31923)
531230F5 BIG-IP IKEv1 Pre-Shared Key Offline Dictionary Attack Vulnerability (CVE-2018-5389)
531231WordPress WPJAM Basic Plugin: Arbitrary File Upload Vulnerability (CVE-2026-32523)
531232WordPress Booking Calendar Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-25435)
531233WordPress JS Help Desk Plugin: SQL Injection Vulnerability (CVE-2026-2511)
531234WordPress WP Job Portal Plugin: SQL Injection Vulnerability (CVE-2026-4306)
531235WordPress NEX-Forms Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-1947)
531236WordPress Nelio A/B Testing Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-32573)
531237WordPress WP REST Cache Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-25347)
531238JetBrains YouTrack Remote Code Execution Vulnerability (CVE-2026-33392)
531239JetBrains YouTrack Missing Authorization Vulnerability (CVE-2026-28193)
531240JetBrains YouTrack Access Token Exposure Vulnerability (CVE-2026-25846)
531241Grafana Server-Side Request Forgery Vulnerability (CVE-2020-13379)
531242Joomla! Core Arbitrary File Deletion Vulnerability (CVE-2026-23898)
531243WordPress WowStore Plugin: SQL Injection Vulnerability (CVE-2026-2579)
531244WordPress WooCommerce Redsys Gateway Light Plugin: Improper Verification of Cryptographic Signature Vulnerability (CVE-2026-5050)
531245WordPress Photo Engine Plugin: Arbitrary File Upload Vulnerability (CVE-2026-32524)
531246WordPress OOPSpam Anti-Spam Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-32544)
531247WordPress WC Ajax Product Filter Plugin: SQL Injection Vulnerability (CVE-2026-3396)
531248Adobe Magento Cross-Site Scripting Vulnerabilities
531249Adobe Magento Incorrect Authorization Vulnerabilities
531250Adobe Magento Server-Side Request Forgery (SSRF) Vulnerabilities (CVE-2026-21293, CVE-2026-21294)
531251Adobe Magento Path Traversal Vulnerability (CVE-2026-21360)
531252Adobe Magento Improper Input Validation Vulnerabilities (CVE-2026-21282, CVE-2026-21310)
531253Adobe Magento Open Redirect Vulnerability (CVE-2026-21295)
531256WordPress Abandoned Cart Recovery Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-32526)
531257WordPress Fluent Booking Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-2231)
531258WordPress Fraud Prevention Plugin: Missing Authorization Vulnerability (CVE-2026-25443)
531259WordPress JS Archive List Plugin: PHP Object Injection Vulnerability (CVE-2026-32513)
531260WordPress Prismatic Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-3876)
531261WordPress KiviCare Plugin: Authentication Bypass Vulnerability (CVE-2026-2991)
531262WordPress Widgets for Social Photo Feed Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-5425)
580944OTP Bypass via NoSQL Injection
580945NoSQL Injection in Password Reset Token Verification
580946CAPTCHA Answer Disclosure via API
580947Password Change Bypass via Missing Current Password Parameter
580948Password Change Bypass via Empty String as Current Password
580949Authentication Header Confusion via Alternate Headers

What’s Next

Leverage the QID list to guide your remediation efforts and strengthen your risk posture.

Looking for more context or remediation tips? Head to Qualys KnowledgeBase for detailed analysis, actionable guidance, and expert-backed support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *