Search Results (8844 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-61972 2 Woolentor, Wordpress 2 Shoplentor Pro, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61973 2 Woolentor, Wordpress 2 Shoplentor Pro, Wordpress 2026-07-23 4.3 Medium
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-65457 2 Wordpress, Yoomoney 2 Wordpress, Юkassa Для Woocommerce 2026-07-23 4.3 Medium
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
CVE-2026-65472 2 Kit, Wordpress 2 Kit (formerly Convertkit), Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
CVE-2026-65479 2 Mvp Themes, Wordpress 2 Reviewer, Wordpress 2026-07-23 5.4 Medium
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-65485 2 Daniel Iser, Wordpress 2 Content Control, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65486 2 Bastien Ho, Wordpress 2 Event Post, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65500 2 Pixelacehq, Wordpress 2 Manual - Documentation, Knowledge Base & Education Wordpress Theme, Wordpress 2026-07-23 7.5 High
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-65524 2 Themefusion, Wordpress 2 Avada Custom Branding, Wordpress 2026-07-23 4.3 Medium
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65525 2 Uxper, Wordpress 2 Civi Framework, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65537 2 Themeisle, Wordpress 2 Cyr To Lat Reloaded – Transliteration Of Links And File Names, Wordpress 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-13078 1 Mongodb 1 Mongodb Server 2026-07-23 7.7 High
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.
CVE-2026-65050 2 Ninjaforms, Wordpress 2 Ninja Forms, Wordpress 2026-07-23 6.5 Medium
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.
CVE-2026-65452 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-47755 2026-07-23 6.5 Medium
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.
CVE-2026-64814 1 Jetbrains 1 Intellij Idea 2026-07-23 8.6 High
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
CVE-2026-65506 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
CVE-2026-27418 2 Epsiloncool, Wordpress 2 Wp Fast Total Search, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
CVE-2026-57717 2026-07-23 6.5 Medium
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
CVE-2026-57808 2 Saad Iqbal, Wordpress 2 Wp Easypay, Wordpress 2026-07-23 6.5 Medium
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.