Export limit exceeded: 15582 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15582 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-74001 | 2 Wordpress, Wpeverest | 2 Wordpress, User Registration & Membership | 2026-08-21 | 9.8 Critical |
| Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | ||||
| CVE-2026-11801 | 2 Gwin, Wordpress | 2 Wpadverts – Classifieds Plugin, Wordpress | 2026-08-21 | 7.5 High |
| The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys. | ||||
| CVE-2026-75091 | 2 Mdmag, Wordpress | 2 Quill Forms | Conversational Multi Step Forms, Surveys & Quizzes, Wordpress | 2026-08-21 | 7.2 High |
| The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-28567 | 2 Fahad Mahmood, Wordpress | 2 Wp Sort Order, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | ||||
| CVE-2026-28570 | 2 Spabrice, Wordpress | 2 Vavo Core, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | ||||
| CVE-2026-32444 | 2 Cwicly, Wordpress | 2 Cwicly, Wordpress | 2026-08-21 | 9.9 Critical |
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | ||||
| CVE-2026-32463 | 2 Kamlesh Parmar, Wordpress | 2 Sync Post With Other Site, Wordpress | 2026-08-21 | 9.9 Critical |
| Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | ||||
| CVE-2026-32464 | 2 Vladimir Prelovac, Wordpress | 2 Theme Test Drive, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | ||||
| CVE-2026-32466 | 2 Wordpress, Wpexperts | 2 Wordpress, Gravity Forms Bookings Premium | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | ||||
| CVE-2026-32467 | 2 Apoyl, Wordpress | 2 [aotuman] Grab Wechat Articles, Wordpress | 2026-08-21 | 6 Medium |
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | ||||
| CVE-2026-32472 | 2 Wbolt.com, Wordpress | 2 Online Contact Widget, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | ||||
| CVE-2026-32473 | 2 Deknows, Wordpress | 2 Pdf Smart Viewer For Elementor, Wordpress | 2026-08-21 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | ||||
| CVE-2026-32474 | 2 Wordpress, Wpwax | 2 Wordpress, Templatiq | 2026-08-21 | 9.9 Critical |
| Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | ||||
| CVE-2026-66620 | 2 Derek Herman, Wordpress | 2 Optiontree, Wordpress | 2026-08-21 | 7.2 High |
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | ||||
| CVE-2026-66627 | 2 Edge22 Studios Ltd., Wordpress | 2 Gp Premium, Wordpress | 2026-08-21 | 9.9 Critical |
| Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. | ||||
| CVE-2026-66633 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Forms Pro Add On Pack | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | ||||
| CVE-2026-66634 | 2 Pantherius, Wordpress | 2 Modal Survey, Wordpress | 2026-08-21 | 4.3 Medium |
| Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. | ||||
| CVE-2026-66639 | 2 Wordpress, Wpzoom | 2 Wordpress, Wpzoom Forms – Contact Form Plugin For Gutenberg | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | ||||
| CVE-2026-66640 | 2 Marcus (aka @msykes), Wordpress | 2 Login With Ajax, Wordpress | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | ||||
| CVE-2026-66643 | 2 Wordpress, Wronganswersonly | 2 Wordpress, Wufoo Shortcode | 2026-08-21 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. | ||||