Export limit exceeded: 14888 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14888 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65520 | 2 Miniorange, Wordpress | 2 Wp Oauth Server, Wordpress | 2026-08-06 | 9.3 Critical |
| Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | ||||
| CVE-2026-65547 | 2 Constantcontact, Wordpress | 2 Creative Mail, Wordpress | 2026-08-06 | 8.5 High |
| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | ||||
| CVE-2026-65552 | 2 Qlstudio, Wordpress | 2 Export User Data, Wordpress | 2026-08-06 | 9.8 Critical |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | ||||
| CVE-2026-65508 | 2 Nsquared, Wordpress | 2 Simply Schedule Appointments, Wordpress | 2026-08-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | ||||
| CVE-2026-65565 | 2 Ays-pro, Wordpress | 2 Survey Maker, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | ||||
| CVE-2026-65569 | 2 Wordpress, Wpjobportal | 2 Wordpress, Wp Job Portal | 2026-08-06 | 8.5 High |
| Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | ||||
| CVE-2026-61964 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Ninja Tables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | ||||
| CVE-2026-18510 | 2 Cozmoslabs, Wordpress | 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress | 2026-08-06 | 7.2 High |
| The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified. | ||||
| CVE-2026-28169 | 2 Wordpress, Yithemes | 2 Wordpress, Yith Woocommerce Zoom Magnifier | 2026-08-06 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | ||||
| CVE-2026-11983 | 2 Spacetime, Wordpress | 2 Ad Inserter – Ad Manager & Adsense Ads, Wordpress | 2026-08-06 | 5.3 Medium |
| The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check in the `ai_ajax` function. This makes it possible for unauthenticated attackers to view the contents of ad blocks that an administrator has restricted to administrator-only visibility. | ||||
| CVE-2026-65551 | 2 Soflyy, Wordpress | 2 Breakdance, Wordpress | 2026-08-06 | 7.5 High |
| Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7. | ||||
| CVE-2025-15028 | 2 Wordpress, Wpwax | 2 Wordpress, Formgent – Next-gen Ai Form Builder For Wordpress With Multi-step, Quizzes, Payments & More | 2026-08-06 | 7.2 High |
| The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-65458 | 2 Chouby, Wordpress | 2 Polylang, Wordpress | 2026-08-06 | 4.3 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5. | ||||
| CVE-2026-24552 | 2 Mischiefmarmot, Wordpress | 2 Create By Mediavine, Wordpress | 2026-08-06 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3. | ||||
| CVE-2026-16605 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-08-05 | 7.2 High |
| The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace. | ||||
| CVE-2026-14195 | 2 Brizy, Wordpress | 2 Brizy, Wordpress | 2026-08-05 | 2.7 Low |
| The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts. | ||||
| CVE-2026-16573 | 2 Bit Form, Wordpress | 2 Bit Form, Wordpress | 2026-08-05 | 7.5 High |
| The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-8790 | 2 Antoineh, Wordpress | 2 Football Pool, Wordpress | 2026-08-05 | 6.1 Medium |
| The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `<textarea>` element using `printf('%s', ...)` with no HTML escaping. This makes it possible for unauthenticated attackers to execute arbitrary web scripts in the browser of an authenticated victim (Subscriber-level or higher) who is tricked into submitting a crafted POST request to a page that contains the Shoutbox widget. | ||||
| CVE-2026-17506 | 2 Bensibley, Wordpress | 2 Independent Analytics – Wordpress Analytics Plugin, Wordpress | 2026-08-05 | 7.2 High |
| The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstructed as raw markup, which wp_kses_post() does not strip because it retains img elements and data-* attributes, and because the public REST endpoint /iawp/search accepts unauthenticated requests as long as they carry a signature that is itself embedded in public page HTML. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-14840 | 2 Wordpress, Yop-poll | 2 Wordpress, Yop-poll | 2026-08-05 | 5.3 Medium |
| The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll. | ||||