Search Results (50186 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96814 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
CVE-2026-96450 2026-09-30 5.4 Medium
Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
CVE-2026-96352 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
CVE-2026-96351 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
CVE-2026-96338 2026-09-30 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
CVE-2026-94674 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.
CVE-2026-94081 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94078 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94077 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2026-93770 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-93514 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93512 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-92424 2026-09-30 6.8 Medium
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.
CVE-2026-91832 2026-09-30 7.1 High
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
CVE-2026-89193 2026-09-30 7.5 High
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
CVE-2026-87777 2026-09-30 6.8 Medium
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
CVE-2026-85415 2026-09-30 6.8 Medium
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
CVE-2026-85001 2026-09-30 6.8 Medium
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
CVE-2026-7172 1 Tpvenlanube 1 Cloud Web Application 2026-09-30 N/A
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
CVE-2026-7171 1 Tpvenlanube 1 Cloud Web Application 2026-09-30 N/A
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.