Export limit exceeded: 16860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 16035 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16035 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62132 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-09-13 | 5.3 Medium |
| Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | ||||
| CVE-2026-87918 | 2 Wordpress, Wpbot | 2 Wordpress, Wpot | 2026-09-13 | 5.3 Medium |
| The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys. | ||||
| CVE-2026-89080 | 2 Really-simple-plugins, Wordpress | 2 Really Simple Security, Wordpress | 2026-09-13 | 7.5 High |
| The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | ||||
| CVE-2026-62105 | 2 Themerex, Wordpress | 2 Themerex Addons, Wordpress | 2026-09-13 | 9.8 Critical |
| Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. | ||||
| CVE-2026-62112 | 2 Melograno Venture Studio, Wordpress | 2 Amelia, Wordpress | 2026-09-13 | 7.6 High |
| Editor SQL Injection in Amelia <= 2.4.9 versions. | ||||
| CVE-2026-62103 | 2 Wordpress, Wpeverest | 2 Wordpress, Everest Forms | 2026-09-13 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | ||||
| CVE-2026-62109 | 2 Wordpress, Wowdevs | 2 Wordpress, Sky Addons For Elementor | 2026-09-13 | 7.6 High |
| Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | ||||
| CVE-2026-62135 | 2 Arraytics, Wordpress | 2 Booktics, Wordpress | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. | ||||
| CVE-2026-62133 | 2 Rometheme, Wordpress | 2 Rtmkit, Wordpress | 2026-09-12 | 5.4 Medium |
| Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions. | ||||
| CVE-2026-62134 | 2 Brainstormforce, Wordpress | 2 Starter Templates, Wordpress | 2026-09-12 | 4.3 Medium |
| Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | ||||
| CVE-2026-62137 | 2 John James Jacoby, Wordpress | 2 Bbpress, Wordpress | 2026-09-12 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | ||||
| CVE-2026-62138 | 2 Visualcomposer, Wordpress | 2 Visual Composer Website Builder, Wordpress | 2026-09-12 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | ||||
| CVE-2026-62139 | 2 Google, Wordpress | 2 Site Kit By Google, Wordpress | 2026-09-12 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. | ||||
| CVE-2026-62110 | 2 Bold-themes, Wordpress | 2 Bold Page Builder, Wordpress | 2026-09-12 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | ||||
| CVE-2026-62111 | 2 Ido Kobelkowsky, Wordpress | 2 Simple Payment, Wordpress | 2026-09-12 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. | ||||
| CVE-2026-62088 | 2 10up, Wordpress | 2 Elasticpress, Wordpress | 2026-09-12 | 5.3 Medium |
| Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4. | ||||
| CVE-2026-85645 | 2 10web, Wordpress | 2 Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder, Wordpress | 2026-09-11 | 6.1 Medium |
| The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | ||||
| CVE-2026-84816 | 2 Realmag777, Wordpress | 2 Wpcs, Wordpress | 2026-09-11 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. | ||||
| CVE-2026-81825 | 2 Specialk, Wordpress | 2 Simple Ajax Chat – Add A Fast, Secure Chat Box, Wordpress | 2026-09-11 | 7.2 High |
| The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce protecting chat message submission is publicly visible on the chat page, rendering it ineffective as an authentication barrier and allowing fully unauthenticated attackers to submit malicious messages that are stored persistently and rendered to all visitors on every page load. | ||||
| CVE-2026-81786 | 2 Villatheme, Wordpress | 2 Thank You Page Customizer For Woocommerce, Wordpress | 2026-09-11 | 7.5 High |
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | ||||