Export limit exceeded: 20583 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15834 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2016-20081 | 3 Bestwebsoft, Husain, Wordpress | 3 Gallery, Hb Audio Gallery Lite, Wordpress | 2026-07-28 | 7.5 High |
| WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access sensitive files like wp-config.php outside the intended gallery directory. | ||||
| CVE-2016-20078 | 3 Henrique Dias, Imdb-widget Project, Wordpress | 3 Imdb Profile Widget, Imdb-widget, Wordpress | 2026-07-28 | 6.2 Medium |
| WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.php containing database credentials and configuration data. | ||||
| CVE-2016-20074 | 3 10web, Leethompson, Wordpress | 3 Slider, Lazy Content Slider Plugin, Wordpress | 2026-07-28 | 4.3 Medium |
| WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify plugin configuration parameters like lzcs_color and lzcs_count. | ||||
| CVE-2016-20071 | 3 404-redirection-manager, Redirection, Wordpress | 3 404 Redirection Manager, Redirection, Wordpress | 2026-07-28 | 8.2 High |
| The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database. | ||||
| CVE-2026-59531 | 2 Anh Tran, Wordpress | 2 Falcon – Wordpress Optimizations & Tweaks, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | ||||
| CVE-2026-59536 | 2 Cocart Headless, Wordpress | 2 Cocart – Headless Ecommerce, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | ||||
| CVE-2026-59537 | 2 Sender, Wordpress | 2 Sender – Newsletter, Sms And Email Marketing Automation For Woocommerce, Wordpress | 2026-07-27 | 7.6 High |
| Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | ||||
| CVE-2026-59548 | 2 Byteflows, Wordpress | 2 Byteflows Travel & Hotel Booking, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | ||||
| CVE-2026-59552 | 2 Shahadat Hossain, Wordpress | 2 3d Flipbook Pdf Viewer & Embedder, Wordpress | 2026-07-27 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | ||||
| CVE-2026-59557 | 2 Franky, Wordpress | 2 Events Made Easy, Wordpress | 2026-07-27 | 6.5 Medium |
| Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | ||||
| CVE-2026-59559 | 2 Themewant, Wordpress | 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||||
| CVE-2026-65433 | 2 Themewant, Wordpress | 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||||
| CVE-2026-65435 | 2 Thrive Themes Coupon, Wordpress | 2 Thrive Leads Version, Wordpress | 2026-07-27 | 6.5 Medium |
| Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | ||||
| CVE-2026-65558 | 2 Wordpress, Wpcenter | 2 Wordpress, Affiliatex | 2026-07-27 | 5.4 Medium |
| Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | ||||
| CVE-2026-65561 | 2 Miniorange, Wordpress | 2 Wordpress Social Login And Register, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | ||||
| CVE-2026-65563 | 2 Themeisle, Wordpress | 2 Orbit Fox By Themeisle, Wordpress | 2026-07-27 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | ||||
| CVE-2026-65567 | 2 Nexcess, Wordpress | 2 Event Tickets, Wordpress | 2026-07-27 | 5.3 Medium |
| Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | ||||
| CVE-2026-66434 | 2 Sayontan Sinha, Wordpress | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | ||||
| CVE-2026-66437 | 2 Themeisle, Wordpress | 2 Feedzy, Wordpress | 2026-07-27 | 4.9 Medium |
| Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions. | ||||
| CVE-2026-66442 | 2 Wordpress, Yaycommerce | 2 Wordpress, Yaypricing | 2026-07-27 | 5.4 Medium |
| Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. | ||||