Export limit exceeded: 400137 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400137 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94082 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. | ||||
| CVE-2026-94081 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | ||||
| CVE-2026-94078 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | ||||
| CVE-2026-94077 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. | ||||
| CVE-2026-94076 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. | ||||
| CVE-2026-94074 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | ||||
| CVE-2026-93771 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | ||||
| CVE-2026-93770 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | ||||
| CVE-2026-93651 | 2026-09-30 | 7.2 High | ||
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | ||||
| CVE-2026-93624 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | ||||
| CVE-2026-93621 | 2026-09-30 | 8.2 High | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | ||||
| CVE-2026-93514 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | ||||
| CVE-2026-93512 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | ||||
| CVE-2026-92424 | 2026-09-30 | 6.8 Medium | ||
| The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content. | ||||
| CVE-2026-91832 | 2026-09-30 | 7.1 High | ||
| The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting. | ||||
| CVE-2026-91072 | 2026-09-30 | 4.4 Medium | ||
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to. | ||||
| CVE-2026-91051 | 2026-09-30 | 6.6 Medium | ||
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or . | ||||
| CVE-2026-89193 | 2026-09-30 | 7.5 High | ||
| The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators. | ||||
| CVE-2026-88797 | 2026-09-30 | 7.1 High | ||
| The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository. | ||||
| CVE-2026-88791 | 2026-09-30 | 3.4 Low | ||
| The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path. | ||||