Search
Search Results (402882 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39770 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat | 2026-10-06 | 10 Critical |
| Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. | ||||
| CVE-2026-39771 | 2 Mightynetworks Vs Buddyboss, Wordpress-extensions | 2 Buddyboss Platform, Buddyboss Platform | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | ||||
| CVE-2026-39772 | 2 Bestwebsoft, Wordpress-extensions | 2 Captcha By Bestwebsoft, Captcha By Bestwebsoft | 2026-10-06 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. | ||||
| CVE-2026-39773 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat Core | 2026-10-06 | 10 Critical |
| Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | ||||
| CVE-2026-39774 | 2 Tourfic Ai Studio, Wordpress-extensions | 2 Tourfic Pro, Tourfic Pro | 2026-10-06 | 8.8 High |
| Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions. | ||||
| CVE-2026-39775 | 2 Dexignzone, Wordpress-extensions | 2 Jobzilla - Job Board Wordpress Theme, Jobzilla | 2026-10-06 | 8.8 High |
| Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions. | ||||
| CVE-2026-39776 | 2 Wordpress-extensions, Wpshopmart | 2 Tabs, Tabs | 2026-10-06 | 8 High |
| Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions. | ||||
| CVE-2026-39778 | 2 Themeansar, Wordpress-extensions | 2 Ansar Import – One Click Starter Sites – For Elementor & Themes, Ansar Import – One Click Starter Sites – For Elementor & Themes | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor & Themes <= 2.1.2 versions. | ||||
| CVE-2026-39780 | 2 Wordpress-extensions, Youzify | 2 Youzify, Youzify | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-39781 | 2 Dan Rossiter, Wordpress-extensions | 2 Document Gallery, Document Gallery | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | ||||
| CVE-2026-39784 | 2 Nicdark, Wordpress-extensions | 2 Hotel Booking, Hotel Booking | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. | ||||
| CVE-2026-39785 | 2 Serhii Pasiuk, Wordpress-extensions | 2 Gmedia Photo Gallery, Gmedia Photo Gallery | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | ||||
| CVE-2026-39787 | 2 10web, Wordpress-extensions | 2 10web Social Post Feed, 10web Social Photo Feed | 2026-10-06 | 6.5 Medium |
| Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | ||||
| CVE-2026-39788 | 2 Shamimsplugins, Wordpress-extensions | 2 Front End Pm, Front End Pm | 2026-10-06 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions. | ||||
| CVE-2026-39790 | 2 E4jvikwp, Wordpress-extensions | 2 Vikrentcar, Vikrentcar | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. | ||||
| CVE-2026-39792 | 2 Mitchell Bennis, Wordpress-extensions | 2 Simple File List, Simple File List | 2026-10-06 | 8.6 High |
| Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions. | ||||
| CVE-2026-39793 | 2 Nicu Micle, Wordpress-extensions | 2 Simple Jwt Login, Simple Jwt Login | 2026-10-06 | 8.8 High |
| Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. | ||||
| CVE-2026-39794 | 2 Wclovers, Wordpress-extensions | 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | ||||
| CVE-2026-39795 | 2 Brewlabs, Wordpress-extensions | 2 Sendpress Newsletters, Sendpress Newsletters | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | ||||
| CVE-2026-39796 | 2 Flipper Code, Wordpress-extensions | 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | ||||