Export limit exceeded: 399925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399925 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102385 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
CVE-2026-102384 2026-09-30 5.9 Medium
Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
CVE-2026-100513 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
CVE-2026-100508 2026-09-30 5.3 Medium
Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
CVE-2026-100507 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
CVE-2026-97289 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
CVE-2026-97288 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
CVE-2026-97287 2026-09-30 8.5 High
Contributor SQL Injection in Event Tickets <= 5.29.5 versions.
CVE-2026-97286 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.
CVE-2026-97285 2026-09-30 5.4 Medium
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
CVE-2026-97282 2026-09-30 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
CVE-2026-97279 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.
CVE-2026-97274 2026-09-30 9.8 Critical
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
CVE-2026-97272 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.
CVE-2026-97271 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-97250 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-91206 1 Apache 1 Roller 2026-09-30 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.
CVE-2026-91204 1 Apache 1 Roller 2026-09-30 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.
CVE-2026-82546 1 Apache 1 Roller 2026-09-30 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments.
CVE-2026-40552 1 Binsoft 1 Mpgabinet 2026-09-30 N/A
Multiple BinSoft products are vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote network resource. Alternatively, it is possible to use a previously uploaded file and change its reference. When the application processes the attachment, and a user tries to open it, the referenced resource is executed by the system. Critically, this vulnerability can be exploited by any unauthenticated attacker by chaining it with CVE-2026-40550 and CVE-2026-40551, which allows obtaining database access, and logging onto any account. The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual.