Export limit exceeded: 15672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15672 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-10734 | 2 Infility, Wordpress | 2 Infility Global, Wordpress | 2026-08-18 | 7.2 High |
| The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The /cf7_records viewer is accessible to any authenticated user including those with Subscriber-level access, meaning the injected payload executes for any logged-in user who visits the records page. | ||||
| CVE-2026-73339 | 2 Webnus, Wordpress | 2 Modern Events Calendar, Wordpress | 2026-08-18 | 9.3 Critical |
| Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | ||||
| CVE-2026-32333 | 2 Teconcetheme, Wordpress | 2 Mayosis Core, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | ||||
| CVE-2026-73366 | 2 Supsystic, Wordpress | 2 Easy Google Maps, Wordpress | 2026-08-18 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | ||||
| CVE-2026-73383 | 2 Webappick, Wordpress | 2 Ctx Feed, Wordpress | 2026-08-18 | 4.9 Medium |
| Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. | ||||
| CVE-2026-74008 | 2 Averta, Wordpress | 2 Shortcodes And Extra Features For Phlox Theme, Wordpress | 2026-08-18 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. | ||||
| CVE-2026-66651 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions. | ||||
| CVE-2026-73355 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 9.3 Critical |
| Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73348 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | ||||
| CVE-2026-73351 | 2 Miniorange, Wordpress | 2 Wordpress Social Login And Register, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | ||||
| CVE-2026-73356 | 2 Cloudways, Wordpress | 2 Breeze, Wordpress | 2026-08-18 | 8.2 High |
| Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. | ||||
| CVE-2026-73361 | 2 Wordpress, Wpzoom | 2 Wordpress, Recipe Card Blocks For Gutenberg & Elementor | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | ||||
| CVE-2026-73362 | 2 Kaizencoders, Wordpress | 2 Url Shortify, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | ||||
| CVE-2026-73393 | 2 Wedevs, Wordpress | 2 Subscribe2, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | ||||
| CVE-2026-73400 | 2 Jetmonsters, Wordpress | 2 Restaurant Menu By Motopress, Wordpress | 2026-08-18 | 8.1 High |
| Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | ||||
| CVE-2026-66637 | 2 Alex, Wordpress | 2 Featured Video Plus, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66629 | 2 Themeum, Wordpress | 2 Kirki, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | ||||
| CVE-2026-32553 | 2 Brainstorm Force, Wordpress | 2 Ottokit, Wordpress | 2026-08-18 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | ||||
| CVE-2026-15748 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 2026-08-18 | 9.8 Critical |
| The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. | ||||
| CVE-2026-68565 | 2 Paolo, Wordpress | 2 Geodirectory, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. | ||||