Search
Search Results (400103 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97074 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | ||||
| CVE-2026-97067 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. | ||||
| CVE-2026-97066 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-97065 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | ||||
| CVE-2026-96886 | 2026-09-30 | 5.3 Medium | ||
| The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course. | ||||
| CVE-2026-96838 | 2026-09-30 | 8.8 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | ||||
| CVE-2026-96837 | 2026-09-30 | 8.8 High | ||
| Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions. | ||||
| CVE-2026-96836 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. | ||||
| CVE-2026-96835 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. | ||||
| CVE-2026-96834 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-96833 | 2026-09-30 | 7.2 High | ||
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | ||||
| CVE-2026-96832 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | ||||
| CVE-2026-96831 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | ||||
| CVE-2026-96830 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-96829 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions. | ||||
| CVE-2026-96828 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | ||||
| CVE-2026-96827 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | ||||
| CVE-2026-96825 | 2026-09-30 | 4.2 Medium | ||
| Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. | ||||
| CVE-2026-96824 | 2026-09-30 | 6.8 Medium | ||
| Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. | ||||
| CVE-2026-96823 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | ||||