Export limit exceeded: 16098 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16098 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66639 | 2 Wordpress, Wpzoom | 2 Wordpress, Wpzoom Forms – Contact Form Plugin For Gutenberg | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | ||||
| CVE-2026-66640 | 2 Marcus (aka @msykes), Wordpress | 2 Login With Ajax, Wordpress | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | ||||
| CVE-2026-66643 | 2 Wordpress, Wronganswersonly | 2 Wordpress, Wufoo Shortcode | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. | ||||
| CVE-2026-66645 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Table Of Contents Block | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | ||||
| CVE-2026-66646 | 2 Mythemeshop, Wordpress | 2 Wp Tab Widget, Wordpress | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. | ||||
| CVE-2026-68567 | 2 Wordpress, Wp Grids | 2 Wordpress, Convert Pro | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | ||||
| CVE-2026-73181 | 2 Themecomplete, Wordpress | 2 Extra Product Options & Add-ons For Woocommerce, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | ||||
| CVE-2026-73338 | 2 Autopay, Wordpress | 2 Autopay, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | ||||
| CVE-2026-73342 | 2 Magazine3, Wordpress | 2 Wp Multilang, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. | ||||
| CVE-2026-73359 | 2 Wordpress, Wp Legal Pages | 2 Wordpress, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent | 2026-08-21 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. | ||||
| CVE-2026-73375 | 2 Supsystic, Wordpress | 2 Ultimate Maps By Supsystic, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73376 | 2 Supsystic, Wordpress | 2 Ultimate Maps By Supsystic, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73377 | 2 Supsystic, Wordpress | 2 Ultimate Maps By Supsystic, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73397 | 2 Wordpress, Youzify | 2 Wordpress, Youzify | 2026-08-21 | 9.8 Critical |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-73399 | 2 Flutterwave, Wordpress | 2 Flutterwave Woocommerce, Wordpress | 2026-08-21 | 6.5 Medium |
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | ||||
| CVE-2026-73994 | 2 Syed Balkhi, Wordpress | 2 Charitable, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | ||||
| CVE-2026-73997 | 2 Nexcess, Wordpress | 2 Starter Templates By Kadence Wp, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | ||||
| CVE-2026-74015 | 2 Merkulove, Wordpress | 2 Readabler, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||||
| CVE-2026-66602 | 2 Devitems, Wordpress | 2 Hashbar – Wordpress Notification Bar, Wordpress | 2026-08-21 | 8.8 High |
| Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | ||||
| CVE-2026-15421 | 2 Siteground, Wordpress | 2 Speed Optimizer – The All-in-one Performance-boosting Plugin, Wordpress | 2026-08-21 | 6.4 Medium |
| The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings. | ||||