Nuclei Templates v10.4.5 - Release Notes
New Templates Added: 86 | CVEs Added: 64 | First-time contributions: 22 🔥 Release Highlights 🔥 [ CVE-2026-50751 ] Check Point IKEv1 Remote-Access VPN - Certificate Auth Bypass ( @watchtowr , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-49777 ] WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCE ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-48907 ] Joomla! JCE extension < 2.9.99.5 Unauth RCE ( @ywh-jfellus ) [critical] (vKEV) 🔥 [ CVE-2026-48710 ] Starlette - Improper Validation of Unsafe Equivalence in Input ( @ritikchaddha ) [critical] 🔥 [ CVE-2026-44551 ] Open WebUI 'LDAP Empty Password' - Auth Bypass ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-44338 ] PraisonAI - Auth Bypass ( @jnoza ) [high] (vKEV) 🔥 [ CVE-2026-44262 ] Scramble Laravel - Remote Code Execution ( @joshuavanderpoll ) [critical] 🔥 [ CVE-2026-42647 ] JoomSport <= 5.7.7 - SQL Injection ( @theamanrawat ) [critical] (vKEV) 🔥 [ CVE-2026-42589 ] Gotenberg - Command Injection ( @fineman999 ) [critical] (vKEV) 🔥 [ CVE-2026-42271 ] LiteLLM - Command Injection ( @ritikchaddha ) [critical] (vKEV) 🔥 [ CVE-2026-42208 ] LiteLLM - SQL Injection ( @HAERIN-L ) [critical] (vKEV) 🔥 [ CVE-2026-35273 ] Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-34910 ] UniFi OS Server - Command Injection (@Kazgangap) [critical] (vKEV) 🔥 [ CVE-2026-31431 ] Copy Fail - Linux Kernel Local Privilege Escalation via AF_ALG ( @ritikchaddha ) [high] (vKEV) 🔥 [CVE-2026-29059] Windmill/Nextcloud Flow < 1.603.3 - Unauth Path Traversal (@0x_Akoko) [critical] 🔥 [ CVE-2026-27760 ] OpenCATS - Command Injection ( @theamanrawat ) [high] (vKEV) 🔥 [ CVE-2026-26190 ] Milvus - Unauth Metrics API Access ( @WRG-11 ) [critical] 🔥 [ CVE-2026-22557 ] UniFi Network Application - Path Traversal ( @Aryu-RU ) [critical] 🔥 [ CVE-2026-20253 ] Splunk Enterprise & Cloud Platform - Unrestricted File Upload ( @watchtowrlabs , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-10795 ] UpdraftPlus WP Backup & Migration Plugin - Auth Bypass ( @theamanrawat , @s4e-io ) [high] (vKEV) 🔥 [ CVE-2026-10520 ] Ivanti Sentry - OS Command Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-5073 ] WordPress ARMember Premium <= 7.3.1 - Unauth SQL Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-5027 ] Langflow <= 1.8.4 - Path Traversal to RCE via File Upload ( @pussycat0x ) [high] (vKEV) 🔥 [ CVE-2026-4480 ] Samba Printing Subsystem - Remote Code Execution ( @projectdiscovery ) [critical] 🔥 [ CVE-2026-3300 ] Everest Forms Pro <= 1.9.12 - Unauth RCE via Calculation Formula Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-3018 ] WordPress Newsletters <= 4.13 - Unauth SQL Injection ( @pussycat0x ) [high] (vKEV) 🔥 [ CVE-2026-0257 ] Palo Alto Networks PAN-OS - Auth Bypass ( @dhiyaneshdk , @sfewer-r7 ) [critical] (vKEV) 🔥 [CVE-2025-49001] DataEase < 2.10.10 - JWT Auth Bypass ( @YunSeoJo , @Aryu-RU ) [critical] 🔥 [ CVE-2025-13773 ] WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code Execution ( @PikaJuna-ops ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed invalid double-port URL construction in hpe-autopass-panel where {{Hostname}} was used instead of {{Host}}, producing malformed URLs like hostname:6274:5814/autopass (PR #16316 , Issue #16315 ). Fixed incorrect CVE assignment in a contributed template, correcting the CVE ID to match the actual vulnerability (PR #16397 , Issue #16388 ). Fixed username variable syntax error in CVE-2026-44551 .yaml causing broken authentication attempts (PR #16341 ). Corrected broken reference links in CVE-2020-27361 .yaml (PR #16403 ). Fixed typo in tags field of wp-jetpack-ssrf.yaml (PR #16347 ). Moved CVE-2020-14644 .yaml to the correct folder in the repository structure (PR #16432 ). False Negatives Fixed a broken regex in the waf-detect BIG-IP ASM matcher that used start-of-response anchors (\A, ^) against a blob beginnin