Export limit exceeded: 48157 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (48157 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-28004 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
CVE-2026-61965 2 Ahmad, Wordpress 2 Geekybot, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-66426 2 Lesterchan, Wordpress 2 Wp-stats, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
CVE-2026-66429 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66456 2 Bestwebsoft, Wordpress 2 Profile Extra Fields, Wordpress 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
CVE-2026-66467 2 Wordpress, Wpmanageninja 2 Wordpress, Fluentcommunity 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-73340 2 Fifu, Wordpress 2 Featured Image From Url, Wordpress 2026-08-14 6.5 Medium
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
CVE-2026-72821 1 Getgrav 1 Grav 2026-08-14 5.4 Medium
Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.
CVE-2026-19794 2 Gamerz, Wordpress 2 Wp-stats, Wordpress 2026-08-14 7.2 High
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-18109 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-14 7.2 High
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step.
CVE-2026-65480 2 Codexthemes, Wordpress 2 Thegem, Wordpress 2026-08-14 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1.
CVE-2026-73648 1 Rubyonrails 1 Rails Html Sanitizers 2026-08-14 N/A
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.
CVE-2026-28003 2 Wordpress, Yonifre 2 Wordpress, Maspik – Spam Blacklist 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
CVE-2026-28158 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-65580 2 Bracketweb, Wordpress 2 Agrion, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-66468 2 Powerfulwp, Wordpress 2 Local Delivery Drivers For Woocommerce, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
CVE-2026-49864 1 Butlerx 1 Wetty 2026-08-14 N/A
wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`'d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\x1b[5i...:...\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim's SSH session. Version 3.0.4 fixes the issue.
CVE-2026-18164 2 Flow Neuroscience, Halo Neuroscience 2 Fl-100, Fl-100 2026-08-14 8.1 High
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.
CVE-2026-19744 1 Maalfer 1 Pentestify 2026-08-14 N/A
Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape quotes
CVE-2026-68419 1 Linux 1 Linux Kernel 2026-08-13 7.8 High
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a two step process is used where the buffer is allocated in userspace and explicitly registered with the normal reg_mr mechanism prior to creating the actual QP/CQ/SRQ object. These special registrations are indicated via an ABI field so the driver knows that they do not have a valid mkey and to skip the actual CQP command submission. Since these are real MR objects from the core's perspective, it is possible for a user application to invoke rereg_mr on them and cause a real CQP op to be emitted with the zero-initialized mkey value of 0. Fix this by preventing rereg_mr on these special regions.