Export limit exceeded: 400618 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400618 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94171 | 2 Villatheme, Wordpress-extensions | 2 Curcy, Curcy | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. | ||||
| CVE-2026-97256 | 2 Greg–siteorigin, Wordpress-extensions | 2 Page Builder By Siteorigin, Page Builder By Siteorigin | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | ||||
| CVE-2026-97265 | 2 Crocoblock. Jetimpex Inc., Wordpress-extensions | 2 Jetengine, Jetengine | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | ||||
| CVE-2026-97290 | 2 Sayontan Sinha, Wordpress-extensions | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Photonic Gallery & Lightbox For Flickr, Smugmug & Others | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | ||||
| CVE-2026-97291 | 2 Magazine3, Wordpress-extensions | 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | ||||
| CVE-2026-100510 | 2 Boldgrid, Wordpress-extensions | 2 Post And Page Builder, Post And Page Builder By Boldgrid | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | ||||
| CVE-2026-100512 | 2 Hook & Filter, Wordpress-extensions | 2 Nested Pages, Nested Pages | 2026-10-01 | 9.8 Critical |
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | ||||
| CVE-2026-102375 | 2 Optimole, Wordpress-extensions | 2 Optimole, Optimole | 2026-10-01 | 6.5 Medium |
| Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | ||||
| CVE-2026-102376 | 2 Wordpress-extensions, Wpmudev | 2 Branda, Branda | 2026-10-01 | 7.1 High |
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | ||||
| CVE-2026-102377 | 2 10web, Wordpress-extensions | 2 Photo Gallery, Photo Gallery By 10web | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | ||||
| CVE-2026-102391 | 2 Jetmonsters, Wordpress-extensions | 2 Jetformbuilder, Jetformbuilder | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | ||||
| CVE-2026-102392 | 2 Themehigh, Wordpress-extensions | 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce | 2026-10-01 | 7.2 High |
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | ||||
| CVE-2026-76142 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | ||||
| CVE-2026-76143 | 1 Genians | 1 Genian Ssl Pns (frodo-core) | 2026-10-01 | N/A |
| A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | ||||
| CVE-2026-76144 | 1 Genians | 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) | 2026-10-01 | N/A |
| An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch | ||||
| CVE-2026-76145 | 1 Genians | 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) | 2026-10-01 | N/A |
| An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration | ||||
| CVE-2026-76147 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | ||||
| CVE-2026-85679 | 2 Extendify, Wordpress-extensions | 2 Extendify, Extendify | 2026-10-01 | 7.2 High |
| The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because registerIncoming() is hooked on rest_request_before_callbacks and runs before WordPress evaluates the route's permission_callback, meaning any unauthenticated POST, PUT, or PATCH request to a /wp/v2/global-styles route can trigger the vulnerable code path. | ||||
| CVE-2026-96813 | 2 10web, Wordpress-extensions | 2 Form Maker, Form Maker By 10web | 2026-10-01 | 7.2 High |
| The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-89427 | 2 Spacetime, Wordpress-extensions | 2 Ad Inserter, Ad Inserter | 2026-10-01 | 6.1 Medium |
| The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature. | ||||