Application Security Detections Published in May 2026
Table of Contents
In May, Qualys Web Application Scanning released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:
Apache, Drupal, GitHub, Grafana, Ivanti, Joomla, Langflow, Liferay, LiteLLM, Microsoft, NGINX, Next.js, N8n, Open WebUI, Palo Alto Networks, pgAdmin, PHP, SAP, Traefik, WordPress, Zabbix, and cPanel
Details about the following QIDs can be found in our knowledge base. Please review the reports for the scanned applications for these detections and, if any are identified, follow the steps in the knowledge base to ensure the applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. If left unaddressed, these vulnerabilities can pose security risks, including breaches, unauthorized access, and various malicious activities.
QIDs
| QID | Title |
| 531399 | Open WebUI Path Traversal Vulnerability (CVE-2026-44566) |
| 531400 | Open WebUI Authentication Bypass Vulnerability (CVE-2026-44551) |
| 151089 | Angular Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-41423) |
| 520152 | Liferay Portal Cross-Site Scripting Vulnerability (CVE-2025-62255) |
| 520153 | Liferay Portal Missing Authorization Vulnerability (CVE-2025-62256) |
| 520154 | Liferay Portal Missing Authorization Vulnerability (CVE-2025-62247) |
| 520155 | Liferay Portal Cross-Site Scripting Vulnerabilities (CVE-2025-62248, CVE-2025-62249) |
| 520156 | Liferay Portal Improper Authentication Vulnerability (CVE-2025-62250) |
| 520157 | Liferay Portal Improper Access Control Vulnerability (CVE-2025-62251) |
| 520158 | Liferay Portal Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2025-62252) |
| 520159 | Liferay Portal Cross-Site Scripting Vulnerabilities (CVE-2025-62246) |
| 520160 | Liferay Portal Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2025-62242) |
| 520161 | Liferay Portal Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2025-62243) |
| 520162 | Liferay Portal Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2025-62244) |
| 520163 | Liferay Portal Cross-Site Request Forgery Vulnerability (CVE-2025-62245) |
| 520164 | Liferay Portal Cross-Site Scripting (XSS) Vulnerabilities (CVE-2025-62239, CVE-2025-62238) |
| 520165 | Liferay Portal Cross-Site Scripting (XSS) Vulnerability (CVE-2025-62237) |
| 520166 | Liferay Portal Cross-Site Scripting Vulnerabilities (CVE-2025-62240) |
| 520167 | Liferay Portal Cross-Site Scripting Vulnerability (CVE-2025-43830) |
| 520168 | Liferay Portal Cross-Site Scripting Vulnerability (CVE-2025-43829) |
| 520169 | Liferay Portal Cross-Site Scripting Vulnerabilities (CVE-2025-43821, CVE-2025-43823) |
| 520170 | Liferay Portal Cross-Site Scripting Vulnerabilities (CVE-2025-43822) |
| 520171 | Liferay Portal Cross-Site Scripting Vulnerability (CVE-2025-43826) |
| 520172 | Liferay Portal HTTP Response Injection Vulnerability (CVE-2025-43824) |
| 520173 | Liferay Portal Sensitive Data Exposure Vulnerability (CVE-2025-43825) |
| 520183 | cPanel and WHM CRLF Injection Vulnerability (CVE-2026-32993) |
| 520184 | cPanel and WHM Arbitrary File Read Vulnerability (CVE-2026-29201) |
| 520185 | cPanel and WHM Incorrect Privileges Management Vulnerability (CVE-2026-29205) |
| 531303 | EOL/Obsolete Software: Apache Tomcat 8.5.X Detected |
| 531304 | EOL/Obsolete Software: Apache Tomcat 10.0.X Detected |
| 531318 | N8n SQL Injection Vulnerability (CVE-2026-42237) |
| 531319 | N8n Cross-Site Scripting Vulnerability (CVE-2026-42235) |
| 531320 | N8n Denial of Service Vulnerability (CVE-2026-42236) |
| 531330 | N8n Sandbox Escape Vulnerability (CVE-2026-42234) |
| 531331 | N8n SQL Injection Vulnerabilities (CVE-2026-42233, CVE-2026-42229) |
| 531332 | N8n Prototype Pollution Vulnerabilities (CVE-2026-42232, CVE-2026-42231) |
| 531333 | N8n Authorization Bypass Vulnerability (CVE-2026-42226) |
| 531336 | EOL/Obsolete Software: Zabbix 4.X Detected |
| 531337 | EOL/Obsolete Software: Zabbix 5.X Detected |
| 531338 | EOL/Obsolete Software: Zabbix 6.2.X Detected |
| 531339 | EOL/Obsolete Software: Zabbix 6.4.X Detected |
| 531340 | EOL/Obsolete Software: Zabbix 7.2.X Detected |
| 531341 | N8n MCP Server Server-Side Request Forgery Vulnerability (CVE-2026-42449) |
| 531342 | GitHub Enterprise Server HTML Injection Vulnerability (CVE-2026-8106) |
| 531362 | GitHub Enterprise Server Server-Side Request Forgery Vulnerability (CVE-2026-8034) |
| 531363 | GitHub Enterprise Server Denial of Service Vulnerability (CVE-2026-7541) |
| 531364 | GitHub Enterprise Server Authentication Bypass Vulnerability (CVE-2026-6736) |
| 531365 | GitHub Enterprise Server Server-Side Request Forgery Vulnerability (CVE-2026-5921) |
| 531366 | GitHub Enterprise Server Improper Authorization Vulnerabilities (CVE-2026-5845, CVE-2026-5512) |
| 531367 | GitHub Enterprise Server OS Command Injection Vulnerability (CVE-2026-4821) |
| 531368 | GitHub Enterprise Server OAuth Redirect URI Bypass Vulnerability (CVE-2026-4296) |
| 531369 | GitHub Enterprise Server Authorization Bypass Vulnerability (CVE-2026-3307) |
| 531380 | SAP S/4HANA (SAP Enterprise Search for ABAP) SQL Injection Vulnerability (CVE-2026-34260) |
| 531381 | SAP Commerce Cloud Missing Authentication Vulnerability (CVE-2026-34263) |
| 520144 | Apache HTTP Server HTTP/2 Double Free and Remote Code Execution Vulnerability (CVE-2026-23918) |
| 520145 | Apache HTTP Server mod_rewrite Privilege Escalation Vulnerability (CVE-2026-24072) |
| 520146 | Apache HTTP Server mod_proxy_ajp Memory Corruption Vulnerabilities (CVE-2026-28780, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059) |
| 520147 | Apache HTTP Server mod_md Unrestricted OCSP Response Vulnerability (CVE-2026-29168) |
| 520148 | Apache HTTP Server mod_dav_lock Denial-of-Service (DoS) Vulnerability (CVE-2026-29169) |
| 520149 | Apache HTTP Server mod_auth_digest Authentication Bypass Vulnerability (CVE-2026-33006) |
| 520150 | Apache HTTP Server mod_authn_socache NULL Pointer Dereference Vulnerability (CVE-2026-33007) |
| 520151 | Apache HTTP Server HTTP Response Splitting Vulnerability (CVE-2026-33523) |
| 520175 | NGINX ngx_http_proxy_module HTTP/2 Request Injection Vulnerability (CVE-2026-42926) |
| 520176 | NGINX ngx_http_rewrite_module Buffer Overflow Vulnerability (CVE-2026-42945) |
| 520177 | NGINX ngx_http_scgi_module and ngx_http_uwsgi_module Memory Over-read Vulnerability (CVE-2026-42946) |
| 520178 | NGINX ngx_http_charset_module Buffer Over-read Vulnerability (CVE-2026-42934) |
| 520179 | NGINX HTTP/3 Address Spoofing Vulnerability (CVE-2026-40460) |
| 520180 | NGINX Use After Free in OCSP Vulnerability (CVE-2026-40701) |
| 531309 | Ivanti Endpoint Manager Mobile (EPMM) Improper Access Control Vulnerability (CVE-2026-5786) |
| 531310 | Ivanti Endpoint Manager Mobile (EPMM) Improper Certificate Validation Vulnerability (CVE-2026-5787) |
| 531311 | Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Method Invocation Vulnerability (CVE-2026-5788) |
| 531312 | Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution (RCE) Vulnerability (CVE-2026-6973) |
| 531313 | Ivanti Endpoint Manager Mobile (EPMM) Improper Certificate Validation Vulnerability (CVE-2026-7821) |
| 531315 | LiteLLM Server-Side Template Injection (SSTI) Vulnerability (CVE-2026-42203) |
| 531316 | LiteLLM SQL Injection Vulnerability (CVE-2026-42208) |
| 531317 | LiteLLM Arbitrary Command Execution Vulnerability (CVE-2026-42271) |
| 531321 | Microsoft SharePoint Deserialization Remote Code Execution (RCE) Vulnerabilities |
| 531322 | Microsoft SharePoint Remote Code Execution (RCE) Vulnerability (CVE-2026-40365) |
| 531323 | Apache Tomcat Uncontrolled Resource Allocation Vulnerability (CVE-2026-41284) |
| 531324 | Apache Tomcat Improper Input Validation Vulnerability (CVE-2026-41293) |
| 531325 | Apache Tomcat HTTP Authentication Header Exposure Vulnerability (CVE-2026-42498) |
| 531326 | Apache Tomcat Authentication Bypass Vulnerability (CVE-2026-43512) |
| 531327 | Apache Tomcat LockOutRealm Improper Handling Vulnerability (CVE-2026-43513) |
| 531328 | Apache Tomcat AJP Secret Timing Discrepancy Vulnerability (CVE-2026-43514) |
| 531329 | Apache Tomcat Improper Authorization Vulnerability (CVE-2026-43515) |
| 531343 | pgAdmin Authorization Bypass Vulnerability (CVE-2026-7813) |
| 531344 | pgAdmin Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2026-7814) |
| 531345 | pgAdmin SQL Injection (SQLi) Vulnerability (CVE-2026-7815) |
| 531346 | pgAdmin OS Command Injection Vulnerability (CVE-2026-7816) |
| 531347 | pgAdmin Local File Inclusion and Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-7817) |
| 531348 | pgAdmin Deserialization Remote Code Execution (RCE) Vulnerability (CVE-2026-7818) |
| 531349 | pgAdmin Path Traversal Vulnerability (CVE-2026-7819) |
| 531350 | pgAdmin Authentication Rate Limiting Vulnerability (CVE-2026-7820) |
| 531376 | Ivanti Virtual Traffic Manager (vTM) OS Command Injection Vulnerability (CVE-2026-8051) |
| 531377 | Ivanti Endpoint Manager (EPM) Sensitive Credentials Exposure Vulnerability (CVE-2026-8109) |
| 531378 | Ivanti Endpoint Manager (EPM) Privilege Escalation Vulnerability (CVE-2026-8110) |
| 531379 | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability (CVE-2026-8111) |
| 151090 | Next.js Cache Poisoning Vulnerability (CVE-2026-44582) |
| 151091 | Next.js Cache Poisoning Vulnerability (CVE-2026-44576) |
| 151092 | Next.js Denial of Service Vulnerability (CVE-2026-44577) |
| 151093 | Next.js Cross-Site Scripting (XSS) Vulnerability (CVE-2026-44580) |
| 151094 | Next.js Cross-Site Scripting (XSS) Vulnerability (CVE-2026-44581) |
| 151095 | Next.js Middleware/Proxy Bypass Vulnerability (CVE-2026-44573) |
| 151096 | Next.js Server Side Request Forgery Vulnerability (CVE-2026-44578) |
| 151098 | Next.js Denial of Service Vulnerability (CVE-2026-44579) |
| 151099 | Next.js Middleware/Proxy Bypass Vulnerability (CVE-2026-44575) |
| 520174 | PHP Use-After-Free Vulnerability (CVE-2026-6722) |
| 531151 | Grafana Snapshot Authentication Bypass Vulnerability (CVE-2021-39226) |
| 531275 | Apache Airflow Authenticated Access Leakage Vulnerability (CVE-2026-38743) |
| 531276 | Apache Airflow Log Exposure Vulnerability (CVE-2026-31987) |
| 531277 | Apache Airflow SQL Error Exposure Vulnerability (CVE-2026-30912) |
| 531278 | Apache Airflow Unsanitized User Input Privilege Escalation Vulnerability (CVE-2026-30898) |
| 531279 | Apache Airflow XCom Payload Execution Vulnerability (CVE-2026-25917) |
| 531280 | Apache Airflow Secret Exposure Vulnerability (CVE-2026-32690) |
| 531281 | Apache Airflow UI / API Permission Bypass Vulnerability (CVE-2026-32228) |
| 531282 | Apache Airflow XCom Payload Execution Vulnerability (CVE-2026-33858) |
| 531283 | Apache Airflow Code Injection Vulnerability (CVE-2025-54550) |
| 531305 | Traefik Multiple Authentication Bypass Vulnerabilities (CVE-2026-40912, CVE-2026-35051, CVE-2026-39858) |
| 531314 | Palo Alto Networks (PAN-OS) Unauthenticated Buffer Overflow Vulnerability (CVE-2026-0300) |
| 531334 | Express Version Disclosed |
| 531335 | Authentication Bypass via SQL Injection |
| 531361 | Langflow Cross-Site Scripting (XSS) Vulnerability (CVE-2026-3346) |
| 531269 | WordPress ExactMetrics Plugin: Arbitrary Plugin Installation/Activation Vulnerability (CVE-2026-5464) |
| 531270 | WordPress WP Statistics Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-5231) |
| 531271 | WordPress Unlimited Elements For Elementor Plugin: Arbitrary File Read Vulnerability (CVE-2026-4659) |
| 531272 | WordPress Easy Appointments Plugin: Sensitive Information Exposure Vulnerability (CVE-2026-2262) |
| 531273 | WordPress LatePoint Plugin: Privilege Escalation Vulnerability (CVE-2026-6741) |
| 531274 | WordPress HTTP Headers Plugin: External Control of File Name or Path Vulnerability (CVE-2026-4132) |
| 531284 | WordPress Highland Software Custom Role Manager Plugin: Privilege Escalation Vulnerability (CVE-2026-7106) |
| 531285 | WordPress WP Customer Area Plugin: Arbitrary File Read/Deletion Vulnerability (CVE-2026-3464) |
| 531286 | WordPress Sendmachine Plugin: Authorization Bypass Vulnerability (CVE-2026-6235) |
| 531287 | WordPress Drag and Drop File Upload Plugin: Arbitrary File Upload Vulnerability (CVE-2026-5364) |
| 531288 | WordPress WP Editor Plugin: Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2026-3772) |
| 531289 | WordPress User Verification Plugin: Authentication Bypass Vulnerability (CVE-2026-7458) |
| 531291 | WordPress Import and Export Users and Customers Plugin: Privilege Escalation Vulnerability (CVE-2026-7641) |
| 531292 | WordPress Widget Options Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-2052) |
| 531293 | WordPress Salon Booking System Plugin: Arbitrary File Read Vulnerability (CVE-2026-6320) |
| 531294 | WordPress Brizy Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-5324) |
| 531295 | WordPress Otter Blocks Plugin: Purchase Verification Bypass Vulnerability (CVE-2026-2892) |
| 531297 | WordPress NEX-Forms Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-5063) |
| 531298 | WordPress Geo Mashup Plugin: SQL Injection Vulnerabilities (CVE-2026-4060, CVE-2026-4061, CVE-2026-4062) |
| 531299 | WordPress Gravity Forms Plugin: Cross-Site Scripting (XSS) Vulnerabilities (CVE-2026-5109, CVE-2026-5110, CVE-2026-5111, CVE-2026-5112, CVE-2026-5113) |
| 531300 | WordPress ARMember Plugin: SQL Injection Vulnerability (CVE-2026-7649) |
| 531301 | WordPress Temporary Login Plugin: Authentication Bypass Vulnerability (CVE-2026-7567) |
| 531302 | Joomla! Core Multiple Vulnerabilities (CVE-2026-21630, CVE-2026-21631, CVE-2026-21632, CVE-2026-23899) |
| 531306 | WordPress WP Mail Gateway Plugin: Missing Authorization Vulnerability (CVE-2026-6963) |
| 531307 | WordPress Paid Memberships Pro Plugin: Missing Authorization Vulnerability (CVE-2026-4100) |
| 531308 | WordPress PixelYourSite Pro Plugin: Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-7049) |
| 531351 | WordPress AI Engine Plugin: Privilege Escalation Vulnerability (CVE-2026-8719) |
| 531352 | WordPress Burst Statistics Plugin: Authentication Bypass Vulnerability (CVE-2026-8181) |
| 531353 | WordPress WP-Optimize Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-7252) |
| 531354 | WordPress Fluent Forms Plugin: Authorization Bypass Vulnerability (CVE-2026-5396) |
| 531355 | WordPress Fluent Forms Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-5395) |
| 531356 | WordPress OttoKit Plugin: SQL Injection Vulnerability (CVE-2026-4935) |
| 531357 | WordPress MonsterInsights Plugin: Missing Authorization Vulnerability (CVE-2026-5371) |
| 531370 | WordPress WP DB Backup Plugin: Missing Authorization Vulnerabilities (CVE-2026-4029, CVE-2026-4030, CVE-2026-4031) |
| 531371 | WordPress GeekyBot Plugin: Missing Authorization Vulnerability (CVE-2026-5294) |
| 531372 | WordPress GeekyBot Plugin: SQL Injection Vulnerability (CVE-2026-3456) |
| 531373 | WordPress FOX – Currency Switcher Plugin: Missing Authorization Vulnerability (CVE-2026-4094) |
| 531374 | WordPress User Frontend Plugin: PHP Object Injection Vulnerability (CVE-2026-5127) |
| 531375 | WordPress Royal Elementor Addons Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-4803) |
| 531382 | WordPress ManageWP Worker Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-3718) |
| 531383 | WordPress Forminator Forms Plugin: Path Traversal Vulnerability (CVE-2026-5192) |
| 531384 | WordPress Form Maker Plugin: SQL Injection Vulnerability (CVE-2026-3359) |
| 531385 | WordPress Custom Twitter Feeds Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-6177) |
| 531386 | WordPress ProfileGrid Plugin: Missing Authorization Vulnerability (CVE-2026-4609) |
| 531387 | WordPress Frontend Admin Plugin: Privilege Escalation Vulnerability (CVE-2026-6228) |
| 531388 | WordPress RTMKit Addons for Elementor Plugin: Local File Inclusion (LFI) Vulnerability (CVE-2026-3425) |
| 531389 | Drupal Core Multiple Security Vulnerabilities (CVE-2026-6365, CVE-2026-6366) |
| 531390 | Drupal Core SQL Injection Vulnerability (CVE-2026-9082) |
| 531391 | Drupal Core Cross-Site Scripting (XSS) Vulnerability (CVE-2026-6367) |
| 531263 | WordPress Breeze Cache Plugin: Arbitrary File Upload Vulnerability (CVE-2026-3844) |
| 531264 | WordPress Create DB Tables Plugin: Authorization Bypass Vulnerability (CVE-2026-4119) |
| 531265 | WordPress Drag and Drop Plugin: Multiple Vulnerabilities (CVE-2026-5718, CVE-2026-5710) |
| 531266 | WordPress CMP Coming Soon Maintenance Plugin: Arbitrary File Upload Vulnerability (CVE-2026-6518) |
| 531267 | WordPress Everest Forms Plugin: Arbitrary File Read and Deletion Vulnerability (CVE-2026-5478) |
| 531268 | WordPress WpForo Forum Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-6248) |
What’s Next
Leverage the QID list to guide your remediation efforts and strengthen your risk posture.
Looking for more context or remediation tips? Head to Qualys KnowledgeBase for detailed analysis, actionable guidance, and expert-backed support.