Export limit exceeded: 15167 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15167 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28182 | 2 Acymailing Newsletter Team, Wordpress | 2 Acymailing Smtp Newsletter, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | ||||
| CVE-2026-28187 | 2 Echoplugins, Wordpress | 2 Knowledge Base For Documentation, Faqs With Ai Assistance, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | ||||
| CVE-2026-61969 | 2 Webilia Inc., Wordpress | 2 Listdom, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | ||||
| CVE-2026-61979 | 2 Miniorange, Wordpress | 2 Saml Sp Single Sign On, Wordpress | 2026-08-13 | 8.1 High |
| Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. | ||||
| CVE-2026-73344 | 2 Passionate Programmer Peter, Wordpress | 2 Wp Data Access, Wordpress | 2026-08-13 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | ||||
| CVE-2026-73401 | 2 Instawp, Wordpress | 2 Instawp Connect, Wordpress | 2026-08-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | ||||
| CVE-2026-28002 | 2 Arraytics, Wordpress | 2 Booktics, Wordpress | 2026-08-13 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | ||||
| CVE-2026-66698 | 2 Brainstorm Force, Wordpress | 2 Suredash, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | ||||
| CVE-2026-14332 | 2 Ecwid, Wordpress | 2 Ecwid By Lightspeed Ecommerce Shopping Cart, Wordpress | 2026-08-13 | 5.4 Medium |
| The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it. | ||||
| CVE-2026-73357 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-13 | 6.5 Medium |
| Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | ||||
| CVE-2026-73403 | 2 Wordpress, Wpeverest | 2 Wordpress, User Registration | 2026-08-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | ||||
| CVE-2026-66453 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-13 | 9.8 Critical |
| Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||||
| CVE-2026-66460 | 2 Aftership & Automizely, Wordpress | 2 Aftership Tracking, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions. | ||||
| CVE-2026-66432 | 2 Denishua, Wordpress | 2 Wpjam Basic, Wordpress | 2026-08-13 | 7.5 High |
| Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. | ||||
| CVE-2026-66449 | 2 Dylan Kuhn, Wordpress | 2 Geo Mashup, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. | ||||
| CVE-2026-66458 | 2 Thimpress, Wordpress | 2 Realpress, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | ||||
| CVE-2026-66478 | 2 Andymoyle, Wordpress | 2 Church Admin, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | ||||
| CVE-2026-66660 | 2 Scottpaterson, Wordpress | 2 Contact Form 7 – Paypal & Stripe Add-on, Wordpress | 2026-08-13 | 6.5 Medium |
| Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | ||||
| CVE-2026-66472 | 2 Everestthemes, Wordpress | 2 Everest Backup, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | ||||
| CVE-2026-66655 | 2 Multiparcels, Wordpress | 2 Multiparcels Shipping For Woocommerce, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. | ||||