Export limit exceeded: 372108 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372108 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372108 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65522 | 2 Pixelacehq, Wordpress | 2 Manual - Documentation, Knowledge Base & Education Wordpress Theme, Wordpress | 2026-07-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | ||||
| CVE-2026-65524 | 2 Themefusion, Wordpress | 2 Avada Custom Branding, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | ||||
| CVE-2026-65525 | 2 Uxper, Wordpress | 2 Civi Framework, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | ||||
| CVE-2026-65534 | 2 Charlie Etienne, Wordpress | 2 Custom Links In Elementor Image Carousel, Wordpress | 2026-07-23 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | ||||
| CVE-2026-65535 | 2 Takayuki Miyauchi, Wordpress | 2 Tinymce Templates, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | ||||
| CVE-2026-65536 | 2 Mahdi Yousefi, Wordpress | 2 افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری), Wordpress | 2026-07-23 | 6.5 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | ||||
| CVE-2026-65537 | 2 Themeisle, Wordpress | 2 Cyr To Lat Reloaded – Transliteration Of Links And File Names, Wordpress | 2026-07-23 | 4.3 Medium |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | ||||
| CVE-2026-65538 | 2 Nilo Velez, Wordpress | 2 Machete, Wordpress | 2026-07-23 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | ||||
| CVE-2026-65539 | 2 Bimal Rekhadiya, Wordpress | 2 Kwayy Html Sitemap, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | ||||
| CVE-2026-65540 | 2 Metin Saraç, Wordpress | 2 Popup For Cf7 With Sweet Alert, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | ||||
| CVE-2026-65550 | 2 Wordpress, Wpshopmart | 2 Wordpress, Tabs | 2026-07-23 | 5.9 Medium |
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | ||||
| CVE-2026-61945 | 2 Multivendorx, Wordpress | 2 Woocommerce Product Stock Alert, Wordpress | 2026-07-23 | 6.5 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. | ||||
| CVE-2026-16733 | 1 Bahmutov | 1 Find-cypress-specs | 2026-07-23 | 5.3 Medium |
| A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-8287 | 1 Bizimhesap Information Systems Industry And Trade | 1 Online Pre-accounting Software | 2026-07-23 | 4.3 Medium |
| Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | ||||
| CVE-2026-65450 | 2 Romancode, Wordpress | 2 Mapsvg, Wordpress | 2026-07-23 | 8.5 High |
| Contributor SQL Injection in MapSVG <= 8.14.0 versions. | ||||
| CVE-2026-27403 | 2 Nerdpress, Wordpress | 2 Hubbub Lites, Wordpress | 2026-07-23 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3. | ||||
| CVE-2026-62210 | 1 Openclaw | 1 Openclaw | 2026-07-23 | 6.5 Medium |
| OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability. | ||||
| CVE-2026-62234 | 1 Getgrav | 1 Grav | 2026-07-23 | 8.1 High |
| Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via unrestricted protocol handlers. | ||||
| CVE-2026-62216 | 1 Openclaw | 1 Openclaw | 2026-07-23 | 5 Medium |
| OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path. | ||||
| CVE-2026-62386 | 1 Getgrav | 1 Grav | 2026-07-23 | 7.5 High |
| The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server access logs, leaked via the Referer header, stored in browser history, and captured by upstream proxy and CDN logs, exposing valid admin access tokens. A leaked token grants unauthorized API access, including reading configuration and user data, creating admin accounts, modifying system settings, and deleting pages. | ||||