Export limit exceeded: 400749 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 10632 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 400749 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400749 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102772 2026-10-02 7.2 High
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The front-end save path requires only a CMB2 box nonce, which is emitted to all visitors including unauthenticated guests via a simple GET request, making the attack trivially reachable without any credentials on sites that expose a public CMB2 form writing a textarea_code field.
CVE-2026-95817 2026-10-02 7.2 High
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but does not prevent exploitation — once an administrator approves the visually innocuous comment, the stored payload executes in the browser of every subsequent visitor to the affected post.
CVE-2026-97336 2026-10-02 7.2 High
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integrating plugin or theme registers a file_list field on a publicly accessible front-end form or a user meta box, as CMB2 is a developer library and does not expose these fields by default.
CVE-2026-93880 2026-10-02 6.1 Medium
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This requires a site administrator to have configured an element block's Custom JS field to include a {{GET:...}} placeholder and for that JS to contain the token 'import', which routes the substituted value to the unescaped raw echo branch inside a &lt;script type="module"&gt; tag.
CVE-2026-96567 2026-10-02 7.2 High
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The CSRF gate protecting form submission (MW_WP_Form_Csrf) is bypassable by any unauthenticated visitor who first loads the public form page to obtain a valid double-submit cookie, leaving no effective barrier to storing malicious payloads.
CVE-2026-96578 2026-10-02 7.2 High
The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.22.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This mXSS-style transform bypasses WordPress comment kses sanitization because the payload is stored using only kses-allowed tags and attributes; the malicious event handlers and style fragments become active only when the plugin's output-buffer callback rewrites the rendered HTML at request time.
CVE-2026-97663 2026-10-02 7.2 High
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the image attachment feature (ivole_attach_image) to be enabled, which allows unauthenticated attackers to both submit a review with an entity-encoded malicious author name and upload an attached image via the publicly accessible wp_ajax_nopriv_cr_upload_local_images_frontend endpoint.
CVE-2026-90988 2026-10-02 N/A
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.
CVE-2026-91828 2026-10-02 N/A
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
CVE-2026-85016 2026-10-02 N/A
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.
CVE-2026-94298 2026-10-02 N/A
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.
CVE-2026-97317 2026-10-02 N/A
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
CVE-2026-97318 2026-10-02 N/A
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
CVE-2026-93698 2026-10-02 N/A
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
CVE-2026-93697 2026-10-02 N/A
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
CVE-2026-17508 2026-10-02 N/A
In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider (org.bouncycastle.jcajce.provider.symmetric.PBEPBKDF2); and the bcrypt round count read from an encrypted OpenSSH v1 private key's own kdfoptions. Each now bounds the parameter before deriving, in line with the caps already applied elsewhere in the tree, with the OpenSSH round count configurable through the new org.bouncycastle.openssh.max_rounds property. This completes the bounding begun in 1.85 for the PKCS#8 / PBES2 decryptors (CVE-2026-15055). This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).
CVE-2026-103604 2026-10-02 N/A
Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a certificate, CRL, certification request or other structure whose name contains a long attribute value made up of characters that must be escaped, such as commas, or of leading or trailing spaces, because each escaping backslash was inserted into the buffer being scanned, so the work grew quadratically with the length of the value. Applications are exposed when they convert such a name to a string, for example to log or display it, or compare it with IetfUtilities.RdnAreEqual, as PKIX path validation does for directoryName name constraints.
CVE-2026-103603 2026-10-02 N/A
Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker who can supply both an HSS public key and a signature to cause a denial of service through memory exhaustion via a public key encoding with an excessive level count, because the level count L read when parsing an HSS public key was not checked against the RFC 8554 maximum of 8, and signature parsing then allocated an array of L - 1 entries before reading any further signature data. A single verification can commit up to about 17 GB of memory or fail with an OutOfMemoryException.
CVE-2026-103602 2026-10-02 N/A
Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-constrained intermediate CA to have certificates accepted during PKIX certification path validation for email addresses, DNS names or URI hosts that lie within excluded subtrees applying to that CA, via an rfc822Name, dNSName or uniformResourceIdentifier name whose host ends with a dot, because names and constraints were compared without first removing the RFC 1034 root-label trailing dot, so a fully qualified host name did not match an excluded subtree for the same host written without the dot.
CVE-2026-103601 2026-10-02 N/A
Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to obtain decryptions of ciphertexts of their choosing via forged messages sent to an application that lets the output buffer of a failed decryption be observed, for example through buffer reuse or logging, because decryption wrote the recovered plaintext into the caller-supplied output buffer before checking the authentication tag and left it there when the check failed. Only decryption into a caller-supplied buffer is affected; methods that return a newly allocated array are not.