Export limit exceeded: 15883 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15883 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65541 | 2 Solutioned, Wordpress | 2 Staff Training, Wordpress | 2026-08-07 | 7.3 High |
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | ||||
| CVE-2026-65542 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 8.8 High |
| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65543 | 2 Vimeodev, Wordpress | 2 Vimeo, Wordpress | 2026-08-07 | 7.5 High |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||||
| CVE-2026-65544 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65546 | 2 Qode, Wordpress | 2 Qode Tours, Wordpress | 2026-08-07 | 9.3 Critical |
| Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | ||||
| CVE-2026-65553 | 2 Wbolt.com, Wordpress | 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress | 2026-08-07 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | ||||
| CVE-2026-65554 | 2 Lattepress, Wordpress | 2 Anspress – Question And Answer, Wordpress | 2026-08-07 | 7.1 High |
| Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | ||||
| CVE-2026-65556 | 2 Mihche, Wordpress | 2 Wpbruiser {no- Captcha Anti-spam}, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | ||||
| CVE-2026-65571 | 2 Axiomthemes, Wordpress | 2 69 Clothing, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | ||||
| CVE-2026-65572 | 2 Axiomthemes, Wordpress | 2 A.williams, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | ||||
| CVE-2026-66665 | 2 Brandexponents, Wordpress | 2 Type Hub, Wordpress | 2026-08-07 | 10 Critical |
| Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | ||||
| CVE-2026-66681 | 2 Jeff Farthing, Wordpress | 2 Theme My Login, Wordpress | 2026-08-07 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions. | ||||
| CVE-2026-66683 | 2 Wordpress, Wp Zone | 2 Wordpress, Custom Css And Javascript | 2026-08-07 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | ||||
| CVE-2026-66685 | 2 Alex, Wordpress | 2 Featured Video Plus, Wordpress | 2026-08-07 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66686 | 2 Vladimir Garagulya, Wordpress | 2 Plugins Garbage Collector (database Cleanup), Wordpress | 2026-08-07 | 6.5 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. | ||||
| CVE-2026-66696 | 2 Nexcess, Wordpress | 2 Gutenberg Blocks By Kadence Blocks, Wordpress | 2026-08-07 | 4.3 Medium |
| Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | ||||
| CVE-2026-15209 | 2 Jshelpdesk, Wordpress | 2 Jshelpdesk, Wordpress | 2026-08-07 | 6.5 Medium |
| The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | ||||
| CVE-2026-14817 | 2 Bdthemes, Wordpress | 2 Element Pack Addons For Elementor, Wordpress | 2026-08-07 | 6.8 Medium |
| The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content. | ||||
| CVE-2026-16540 | 2 Nsqua, Wordpress | 2 Simply Schedule Appointments, Wordpress | 2026-08-07 | 7.5 High |
| The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. | ||||
| CVE-2026-16532 | 2 Link Library Project, Wordpress | 2 Link Library, Wordpress | 2026-08-07 | 9.1 Critical |
| The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||