Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "ajax.php"
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18322: CWE-269 Improper Privilege Management in supsysticcom Smart Popup by SupsysticCVE-2026-18322 0 The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials. Join the discussion | CVE Database V5 | 08/05/2026, 04:25:25 UTC Added: 08/05/2026, 05:41:47 UTC |
CVE-2026-70552: Missing Authentication for Critical Function in MaxSite MaxSite CMSCVE-2026-70552 0 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials, enabling actions such as manipulating poll states and vote counts, and amplifying the impact of any dangerous operation performed by admin-only ajax files across the plugin tree. Join the discussion | CVE Database V5 | 08/04/2026, 19:28:27 UTC Added: 08/04/2026, 20:12:03 UTC |
CVE-2026-65049: Incorrect Authorization in Saturday Drive Ninja FormsCVE-2026-65049 0 Ninja Forms plugin for WordPress Multisite versions 3.14.8 and earlier contains an incorrect authorization vulnerability. This flaw allows a subsite Administrator to delete all Ninja Forms data network-wide by exploiting improper capability checks and unsafe multisite migration defaults. An attacker can send a crafted POST request to the admin-ajax.php endpoint to trigger deletion routines that affect every subsite without needing super-admin privileges. The vulnerability has a high severity rating with a CVSS score of 8.4. Join the discussion | CVE Database V5 | 07/21/2026, 14:22:08 UTC Added: 07/21/2026, 14:42:54 UTC |
CVE-2026-16331: Unrestricted Upload in D-Link DNS-320CVE-2026-16331 0 A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 07/21/2026, 00:45:35 UTC Added: 07/21/2026, 00:57:20 UTC |
CVE-2026-34239: CWE-285: Improper Authorization in chamilo chamilo-lmsCVE-2026-34239 0 Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a course (student, teacher, DRH) can reach it. Join the discussion | CVE Database V5 | 07/20/2026, 17:11:01 UTC Added: 07/20/2026, 17:57:38 UTC |
Showing 1 to 5 of 5 results