Search

Search Results (386443 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-62043 2026-10-11 7.5 High
Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions.
CVE-2026-62039 2026-10-11 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.8.8.
CVE-2026-62037 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Document Embedder <= 2.4.0 versions.
CVE-2026-62034 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions.
CVE-2026-62032 2026-10-11 9.8 Critical
Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions.
CVE-2026-62031 2026-10-11 9.3 Critical
Unauthenticated SQL Injection in uListing <= 2.2.0 versions.
CVE-2026-62030 2026-10-11 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
CVE-2026-62027 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions.
CVE-2026-62020 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in TouchUp < 1.4 versions.
CVE-2026-57806 2026-10-11 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in drfuri Martfury - WooCommerce Marketplace WordPress Theme martfury allows Reflected XSS.This issue affects Martfury - WooCommerce Marketplace WordPress Theme: from n/a through 3.3.9.
CVE-2026-57742 1 Themerex Group 1 Kids Planet 2026-10-11 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a through 2.2.14.2.
CVE-2026-48194 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.
CVE-2026-48193 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in Uminex <= 1.0.9 versions.
CVE-2026-45440 2026-10-11 7.6 High
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
CVE-2026-42777 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
CVE-2026-42724 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.
CVE-2026-42723 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
CVE-2026-42722 2026-10-11 7.6 High
Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
CVE-2026-42718 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
CVE-2026-42717 2026-10-11 7.6 High
Administrator SQL Injection in Leyka <= 3.32.3 versions.