Export limit exceeded: 29340 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 29340 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (29340 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15646 | 2 Berocket, Wordpress | 2 Brands For Woocommerce, Wordpress | 2026-07-23 | 6.4 Medium |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-25424 | 2 Mediavine, Wordpress | 2 Mediavine Control Panel, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | ||||
| CVE-2026-57384 | 2 Membershipsoftware, Wordpress | 2 Wishlist Member X, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. | ||||
| CVE-2026-57735 | 2 Soflyy, Wordpress | 2 Breakdance, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | ||||
| CVE-2026-57809 | 2 Affiliatewp, Wordpress | 2 Affiliatewp, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | ||||
| CVE-2026-61950 | 2 Themetechmount, Wordpress | 2 Truebooker, Wordpress | 2026-07-23 | 9.3 Critical |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | ||||
| CVE-2026-65449 | 2 Romancode, Wordpress | 2 Mapsvg, Wordpress | 2026-07-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | ||||
| CVE-2026-65487 | 2 Themegoods, Wordpress | 2 Photography, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | ||||
| CVE-2026-65519 | 2 Gt3themes, Wordpress | 2 Photo Gallery, Wordpress | 2026-07-23 | 6.5 Medium |
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||||
| CVE-2026-15037 | 1 Qt | 1 Qt | 2026-07-23 | N/A |
| Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12. | ||||
| CVE-2026-65460 | 2 Wordpress, Zarinpal | 2 Wordpress, Zarinpal Gateway | 2026-07-23 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. | ||||
| CVE-2026-65453 | 2 Motovnet, Wordpress | 2 Ebook Store, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | ||||
| CVE-2026-64625 | 1 Wwbn | 1 Avideo | 2026-07-23 | 9.8 Critical |
| AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection. | ||||
| CVE-2026-54764 | 1 Traefik | 1 Traefik | 2026-07-23 | 5.8 Medium |
| Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6. | ||||
| CVE-2026-54763 | 1 Traefik | 1 Traefik | 2026-07-23 | 10.0 Critical |
| Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6. | ||||
| CVE-2026-27355 | 2 Metaphorcreations, Wordpress | 2 Ditty, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. | ||||
| CVE-2026-65528 | 2 Bannersky, Wordpress | 2 Bsk Pdf Manager, Wordpress | 2026-07-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | ||||
| CVE-2026-65530 | 2 Templatespare, Wordpress | 2 Templatespare, Wordpress | 2026-07-23 | 4.3 Medium |
| Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | ||||
| CVE-2026-16450 | 1 Zsadmin2025 | 1 Zs-admin | 2026-07-23 | 4.3 Medium |
| A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-59541 | 2 Hakan Ozevin, Wordpress | 2 Wp Base Booking, Wordpress | 2026-07-23 | 8.8 High |
| Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | ||||