Export limit exceeded: 16032 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16032 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84781 | 2 Wordpress, Wpchill | 2 Wordpress, Gallery Photoblocks | 2026-09-03 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. | ||||
| CVE-2026-84772 | 2 Wordpress, Wpmudev | 2 Wordpress, Broken Link Checker | 2026-09-03 | 5.5 Medium |
| Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions. | ||||
| CVE-2026-84759 | 2 Elementor, Wordpress | 2 Activity Log, Wordpress | 2026-09-03 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions. | ||||
| CVE-2026-84217 | 2 Mamunur Rashid, Wordpress | 2 Classified Listing, Wordpress | 2026-09-03 | 5.4 Medium |
| Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Classified Listing: from n/a through 6.1.1. | ||||
| CVE-2026-82883 | 2 Marcus, Wordpress | 2 Login With Ajax, Wordpress | 2026-09-03 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1. | ||||
| CVE-2026-81772 | 2 Saturday Drive, Wordpress | 2 Ninja Forms - Layout & Styles, Wordpress | 2026-09-03 | 8.8 High |
| Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions. | ||||
| CVE-2026-3852 | 2 Elegant Themes, Wordpress | 2 Divi, Wordpress | 2026-09-03 | 6.4 Medium |
| The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist in `class-et-builder-element.php`, so it never invokes `esc_url_raw()` during shortcode processing, (2) the render code in `SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()` is applied, which preserves single and double quote characters allowing attribute breakout. The unsanitized value is interpolated directly into a single-quoted `href` attribute (`href='{$social_network_link_url}'`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user interacts with the injected element. | ||||
| CVE-2026-14326 | 2 Timetics, Wordpress | 2 Timetics, Wordpress | 2026-09-03 | 3.8 Low |
| The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members. | ||||
| CVE-2026-77793 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-03 | 5.3 Medium |
| The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account. | ||||
| CVE-2026-77794 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-09-03 | 5.3 Medium |
| The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants. | ||||
| CVE-2026-81571 | 2 Brave, Wordpress | 2 Brave, Wordpress | 2026-09-03 | 4.8 Medium |
| The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have arbitrary shortcodes registered on the site executed server-side. | ||||
| CVE-2026-84771 | 2 Publishpress, Wordpress | 2 Publishpress Permissions, Wordpress | 2026-09-02 | 5.3 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. | ||||
| CVE-2026-82182 | 2 Wordpress, Wpvividplugins | 2 Wordpress, Wpvivid — Backup, Migration & Staging | 2026-09-02 | 4.1 Medium |
| The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks. | ||||
| CVE-2026-81289 | 2 Sonaar, Wordpress | 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | ||||
| CVE-2026-81294 | 2 Paul Ryan, Wordpress | 2 Authorizer, Wordpress | 2026-09-02 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions. | ||||
| CVE-2026-81770 | 2 Mapgeo, Wordpress | 2 Interactive Geo Maps, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | ||||
| CVE-2026-81771 | 2 Trustedsite, Wordpress | 2 Trustedsite, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. | ||||
| CVE-2026-81774 | 2 Dotstore, Wordpress | 2 Woocommerce Product Attachment, Wordpress | 2026-09-02 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | ||||
| CVE-2026-84835 | 2 Dimafreund, Wordpress | 2 Rentsyst, Wordpress | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2. | ||||
| CVE-2026-84770 | 2 Kitae-park, Wordpress | 2 Mang Board Wp, Wordpress | 2026-09-02 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | ||||