Export limit exceeded: 382493 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (382493 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-82824 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 9.8 Critical
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-103592 1 Pecee 1 Simple-router 2026-10-01 6.5 Medium
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
CVE-2026-92537 2 Satollo, Wordpress-extensions 2 Newsletter – Send Awesome Emails From Wordpress, Newsletter 2026-10-01 5.3 Medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=<id>-<raw_token>` response header to the requester because the subscriber object loaded via `get_user()` lacks the `_trusted` property, causing `get_user_key()` to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (`?na=px`), rewrite the subscriber's stored profile (`?na=ps`), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (`?na=ocu`), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential.
CVE-2026-101887 1 Arkq 1 Bluez-alsa 2026-10-01 3.5 Low
BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can establish an A2DP source connection with an LC3plus session negotiated against a victim running bluealsad as an A2DP sink and transmit a non-fragmented LC3plus media header with a zero frame count to trigger a SIGFPE in the decoding thread, causing a denial of service on builds compiled with LC3plus support enabled.
CVE-2026-92245 2 Croixhaug, Wordpress-extensions 2 Simply Schedule Appointments, Simply Schedule Appointments 2026-10-01 7.5 High
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment public_token values. The leaked per-appointment public_token values also enable unauthenticated attackers to delete arbitrary appointments via the DELETE /wp-json/ssa/v1/appointments/{id} endpoint, which accepts the token as sole authorization.
CVE-2026-96561 2 Tigroumeow, Wordpress-extensions 2 Ai Engine – The Chatbot And Ai Framework For Wordpress, Ai Engine 2026-10-01 7.2 High
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser (MeowKit_MWAI_Helpers::php_error_logs), the Advisor task (Meow_MWAI_Modules_Advisor::run_advisor), and the Advisor dashboard widget (advisor_metabox): the server-parameter denylist in chat_submit strips only exact key names such as 'model' while convert_keys() later canonicalizes 'model_' back to 'model', allowing an unauthenticated caller to place an attacker-controlled string (including CR/LF) into $query->model; final_checks() throws an Exception whose message embeds that raw string, and the non-streaming, non-admin catch branch writes it to the PHP error log unmodified — creating a forged log line that the plugin's own parser subsequently returns as recent PHP-error content; run_advisor() then appends that content verbatim to the AI prompt (indirect prompt injection — CWE-1427), the returned JSON is stored in the mwai_advisor_data option with no schema validation or HTML sanitization, and advisor_metabox() concatenates the resulting 'title' and 'description' values directly into the WordPress dashboard widget without esc_html(), wp_kses(), or equivalent escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the WordPress dashboard.
CVE-2026-91109 2 Croixhaug, Wordpress-extensions 2 Simply Schedule Appointments, Simply Schedule Appointments 2026-10-01 6.5 Medium
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose every co-booker's private per-appointment id_token (exposed as public_token) alongside their PII (name and email address), then use each leaked token to read, overwrite arbitrary appointment meta on, or cancel the co-booker's appointment via the same REST controller. Exploitation requires the attacker to possess a valid id_token for any single appointment within the targeted group booking.
CVE-2026-92548 2 Hcabrera, Wordpress-extensions 2 Wp Popular Posts, Wp Popular Posts 2026-10-01 5.3 Medium
The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. This makes it possible for unauthenticated attackers to extract sensitive edit-context fields — including raw title, raw content body, password, meta, status, and guid — from non-public post objects such as wp_block synced patterns that WordPress core itself refuses to expose to unauthenticated callers. This is possible because the plugin's REST route is registered with a permission_callback of __return_true and passes the caller-supplied context parameter (e.g., context=edit) directly to WP_REST_Posts_Controller::prepare_item_for_response() without invoking get_item_permissions_check() or check_read_permission(), while the underlying query accepts an arbitrary post_type value without enforcing public or show_in_rest visibility flags.
CVE-2026-12241 2 Mihail-barinov, Wordpress-extensions 2 Advanced Woo Labels – Product Labels & Badges For Woocommerce, Advanced Woo Labels 2026-10-01 5.4 Medium
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly secure capability check on the 'save_meta_boxes' function in all versions up to, and including, 2.51. This makes it possible for authenticated attackers, with Contributor-level access and above, to create AWS labels that are rendered without proper escaping. The vulnerability was partially patched in version 2.46.
CVE-2026-92966 2 Latepoint, Wordpress-extensions 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Appointment Booking Plugin 2026-10-01 9.1 Critical
The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The payload is planted during the unauthenticated booking flow and triggered when the Customer Cabinet block rendered by render_customer_dashboard() outputs the stored name into the content stream, where WordPress core's do_shortcode filter at priority 11 re-parses and executes it.
CVE-2026-76146 1 Genians, Inc 1 Genian Ssl Pns (xenics Auther) 2026-10-01 N/A
An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely
CVE-2026-88999 2 Davidanderson, Wordpress-extensions 2 Redux Framework, Redux Framework 2026-10-01 4.3 Medium
The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary media library attachments, including administrator-owned files, from the affected site. This is exploitable by Subscribers when a Custom Fonts field is registered on the user profile page via Redux_Users::set_profile(), as doing so causes the required redux_custom_fonts nonce to be rendered into the Subscriber's wp-admin/profile.php page.
CVE-2026-80276 1 Comelit Group 1 1456b Multi-user Gateway 2026-10-01 7.5 High
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.
CVE-2026-80275 1 Comelit Group 1 1456b Multi-user Gateway 2026-10-01 8.8 High
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
CVE-2026-101147 1 Wordpress-extensions 2 Featured Image From Url (fifu) Free, Featured Image From Url (fifu) Premium 2026-10-01 8.8 High
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF attack.
CVE-2026-101148 1 Wordpress-extensions 1 Backup Sheep 2026-10-01 10.0 Critical
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.
CVE-2026-19253 1 Wordpress-extensions 1 Cache Enabler 2026-10-01 8.7 High
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.
CVE-2026-81739 2 Paytm, Wordpress-extensions 2 Payment Gateway, Paytm Payment Gateway 2026-10-01 7.5 High
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.
CVE-2026-81809 2 Paytm, Wordpress-extensions 2 Payment Gateway, Paytm Payment Gateway 2026-10-01 7.5 High
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-86610 1 Wordpress-extensions 1 Download Manager 2026-10-01 6.4 Medium
The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue, including administrators. Only sites running PHP below 8.1 are affected, as the sanitisation applied when the setting is saved does not neutralise single quotes there.