Export limit exceeded: 386304 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386304 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84261 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin. | ||||
| CVE-2026-84260 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin. | ||||
| CVE-2026-84259 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin. | ||||
| CVE-2026-84258 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin. | ||||
| CVE-2026-84254 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site. | ||||
| CVE-2026-84253 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site. | ||||
| CVE-2026-84252 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to WPForms WordPress plugin through 1.0.3 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to WPForms WordPress plugin through 1.0.3. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site. | ||||
| CVE-2026-84251 | 2026-10-11 | N/A | ||
| The click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the click5 CRM add-on to Ninja Forms WordPress plugin through 1.0.1. As a result, unauthenticated attackers could change arbitrary blog options, allowing them to create a new administrator account and take over the site. | ||||
| CVE-2026-81649 | 2026-10-11 | N/A | ||
| The Fundiin cho WooCommerce WordPress plugin through 3.4.0 does not have proper authorisation on several of its REST API routes, relying instead on a credential that is identical on every installation, allowing unauthenticated attackers to disclose the store's payment credentials and customer order data, overwrite the payment gateway configuration so that payments are credited elsewhere, and mark unpaid orders as paid. The same missing authorisation also allows arbitrary script to be stored in a field which is output unescaped on the classic checkout, leading to unauthenticated stored XSS on stores that do not use the block-based checkout. | ||||
| CVE-2026-81420 | 2026-10-11 | N/A | ||
| The Tcard WP WordPress plugin through 1.8.0 does not sanitise and escape a parameter before using it in a SQL statement in one of its unauthenticated AJAX actions, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-108606 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis. | ||||
| CVE-2026-81156 | 2026-10-11 | N/A | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing. | ||||
| CVE-2026-81155 | 2026-10-11 | N/A | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators. | ||||
| CVE-2026-81154 | 2026-10-11 | N/A | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators. | ||||
| CVE-2026-81153 | 2026-10-11 | N/A | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the gallery, including administrators, even where the unfiltered_html capability is disallowed such as on multisite. | ||||
| CVE-2026-14854 | 2026-10-11 | N/A | ||
| The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request. | ||||
| CVE-2026-107694 | 2026-10-11 | N/A | ||
| The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors. | ||||
| CVE-2026-107507 | 2026-10-11 | N/A | ||
| The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings and date of a sport they are assigned to. | ||||
| CVE-2026-106029 | 2026-10-11 | N/A | ||
| The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide. | ||||
| CVE-2026-104684 | 2026-10-11 | N/A | ||
| The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public gallery metadata to unauthenticated visitors. | ||||