Export limit exceeded: 15560 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15560 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66587 | 2 Wordpress, Wpcafe | 2 Wordpress, Wp Cafe Pro | 2026-08-24 | 9.8 Critical |
| Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. | ||||
| CVE-2026-66648 | 2 Mvpthemes, Wordpress | 2 Jawn, Wordpress | 2026-08-24 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. | ||||
| CVE-2026-66670 | 2 Elated-themes, Wordpress | 2 Måne, Wordpress | 2026-08-24 | 8.1 High |
| Unauthenticated Local File Inclusion in Måne <= 1.7 versions. | ||||
| CVE-2026-28192 | 2 Piotnet, Wordpress | 2 Piotnet Addons For Elementor, Wordpress | 2026-08-24 | 9.6 Critical |
| Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | ||||
| CVE-2026-28568 | 2 Mdmag, Wordpress | 2 Quill Forms, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | ||||
| CVE-2026-28569 | 2 Sslzen, Wordpress | 2 Ssl Zen, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | ||||
| CVE-2026-32468 | 2 Duitku, Wordpress | 2 Duitku Payment Gateway, Wordpress | 2026-08-24 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | ||||
| CVE-2026-32547 | 2 Wordplus, Wordpress | 2 Better Messages, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | ||||
| CVE-2026-66635 | 2 10web, Wordpress | 2 Sliderby10web, Wordpress | 2026-08-24 | 7.4 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | ||||
| CVE-2026-66638 | 2 Shabti, Wordpress | 2 Frontend Admin By Dynamapps, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-68568 | 2 Stylemixthemes, Wordpress | 2 Masterstudy Lms, Wordpress | 2026-08-24 | 6.3 Medium |
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73190 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-73378 | 2 Supsysticcom, Wordpress | 2 Contact Form By Supsystic, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73379 | 2 Supsysticcom, Wordpress | 2 Contact Form By Supsystic, Wordpress | 2026-08-24 | 6.5 Medium |
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73395 | 2 Wordpress, Wpdevart | 3 Wordpress, Booking Calendar, Booking Calendar, Appointment Booking System | 2026-08-24 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | ||||
| CVE-2026-18027 | 2 Webtoffee, Wordpress | 2 Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels, Wordpress | 2026-08-24 | 6.5 Medium |
| The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key. | ||||
| CVE-2026-66584 | 2 Code4recovery, Wordpress | 2 12 Step Meeting List, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | ||||
| CVE-2026-78258 | 2 Magepeople, Wordpress | 2 Booking & Rental Manager, Wordpress | 2026-08-24 | 5.3 Medium |
| Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | ||||
| CVE-2026-78270 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentcrm | 2026-08-24 | 7.6 High |
| Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. | ||||
| CVE-2026-78272 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Support | 2026-08-24 | 5.4 Medium |
| Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions. | ||||