Export limit exceeded: 390708 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 390708 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 390708 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390708 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82846 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-09-07 | 6.8 Medium |
| The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. | ||||
| CVE-2026-84745 | 2 Theeventscalendar, Wordpress | 2 The Events Calendar, Wordpress | 2026-09-07 | 2.7 Low |
| The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'. | ||||
| CVE-2026-84931 | 2 Wordpress, Wpjoli | 2 Wordpress, Joli Table Of Contents | 2026-09-07 | 6.8 Medium |
| The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML. | ||||
| CVE-2026-84934 | 2 Jch Optimize Project, Wordpress | 2 Jch Optimize, Wordpress | 2026-09-07 | 8 High |
| The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site. | ||||
| CVE-2026-2670 | 1 Advantech | 14 Wise-6610, Wise-6610-cb, Wise-6610-eb and 11 more | 2026-09-07 | 7.2 High |
| A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data." | ||||
| CVE-2026-49509 | 1 Samsung Open Source | 1 Escargot | 2026-09-06 | 4.4 Medium |
| Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | ||||
| CVE-2026-86221 | 1 Sourcecodester | 1 Class And Exam Timetabling System | 2026-09-06 | 7.3 High |
| A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | ||||
| CVE-2026-81348 | 2026-09-06 | 3.7 Low | ||
| The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login. | ||||
| CVE-2026-78362 | 2026-09-06 | 9.8 Critical | ||
| The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state. | ||||
| CVE-2026-86250 | 1 H3js | 1 H3 | 2026-09-06 | 7.5 High |
| h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process. | ||||
| CVE-2026-84901 | 2 Eventin, Wordpress | 2 Eventin, Wordpress | 2026-09-06 | 4.9 Medium |
| The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage. | ||||
| CVE-2026-84926 | 2026-09-06 | 2.7 Low | ||
| The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role. | ||||
| CVE-2026-84927 | 2026-09-06 | 2.7 Low | ||
| The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site. | ||||
| CVE-2026-84936 | 2026-09-06 | 5.3 Medium | ||
| The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database. | ||||
| CVE-2026-85038 | 2026-09-06 | 5.3 Medium | ||
| The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration. | ||||
| CVE-2026-78149 | 2026-09-06 | 5.3 Medium | ||
| The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it. | ||||
| CVE-2026-78150 | 2026-09-06 | 2.7 Low | ||
| The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata. | ||||
| CVE-2026-82304 | 2 Musicstore, Wordpress | 2 Music Store, Wordpress | 2026-09-06 | 8.6 High |
| The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | ||||
| CVE-2026-13159 | 2026-09-06 | 4.3 Medium | ||
| The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate , those are activated as well. | ||||
| CVE-2026-80439 | 2 Redirection-for-contact-form7, Wordpress | 2 Redirection For Contact Form 7, Wordpress | 2026-09-06 | 4.8 Medium |
| The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output. | ||||