Export limit exceeded: 402635 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402635 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93617 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
CVE-2026-89289 2026-10-06 5.3 Medium
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id.
CVE-2026-86786 2026-10-06 5.3 Medium
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata.
CVE-2026-41563 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
CVE-2026-41558 2026-10-06 7.5 High
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
CVE-2026-39791 2026-10-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39760 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
CVE-2026-39757 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
CVE-2026-39756 2026-10-06 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
CVE-2026-39755 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVE-2026-39754 2026-10-06 6.5 Medium
Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions.
CVE-2026-39753 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
CVE-2026-39752 2026-10-06 7.7 High
Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions.
CVE-2026-39751 2026-10-06 7.5 High
Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-39750 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.
CVE-2026-39749 2026-10-06 6.5 Medium
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
CVE-2026-39748 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions.
CVE-2026-39747 2026-10-06 8.5 High
Subscriber SQL Injection in Woffice <= 5.4.35 versions.
CVE-2026-39746 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions.