Export limit exceeded: 11855 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (11855 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61948 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-02 | 9.3 Critical |
| Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | ||||
| CVE-2026-61981 | 2 Quantumcloud, Wordpress | 2 Simple Link Directory, Wordpress | 2026-08-02 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | ||||
| CVE-2026-65454 | 2 Expresstech, Wordpress | 2 Quiz And Survey Master, Wordpress | 2026-08-02 | 8.5 High |
| Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | ||||
| CVE-2026-65463 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | ||||
| CVE-2026-65465 | 2 Crocoblock, Wordpress | 2 Jetelements For Elementor, Wordpress | 2026-08-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. | ||||
| CVE-2026-65466 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetreviews, Wordpress | 2026-08-02 | 4.9 Medium |
| Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | ||||
| CVE-2026-65467 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetreviews, Wordpress | 2026-08-02 | 4.9 Medium |
| Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | ||||
| CVE-2026-65468 | 2 Crocoblock, Wordpress | 2 Jetbooking, Wordpress | 2026-08-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | ||||
| CVE-2026-65469 | 2 Strategy11, Wordpress | 2 Awp Classifieds, Wordpress | 2026-08-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | ||||
| CVE-2026-65478 | 2 Cridio, Wordpress | 2 Listingpro, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. | ||||
| CVE-2026-65482 | 2 La-studioweb, Wordpress | 2 Element Kit For Elementor, Wordpress | 2026-08-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65488 | 2 La-studioweb, Wordpress | 2 Element Kit For Elementor, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65493 | 2 Dokan, Wordpress | 2 Dokan, Wordpress | 2026-08-02 | 7.5 High |
| Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. | ||||
| CVE-2026-65494 | 2 Dokan, Wordpress | 2 Dokan, Wordpress | 2026-08-02 | 7.1 High |
| Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | ||||
| CVE-2026-65499 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-65506 | 2 Sonaar, Wordpress | 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress | 2026-08-02 | 5.3 Medium |
| Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | ||||
| CVE-2026-65510 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-65516 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-12497 | 2 Properfraction, Wordpress | 2 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profilepress, Wordpress | 2026-08-02 | 7.5 High |
| The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer. | ||||
| CVE-2026-16910 | 1 Redhat | 3 Openshift Update Service, Quay, Quay 3 | 2026-08-02 | 5.5 Medium |
| A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application. | ||||