Export limit exceeded: 14849 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14849 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-7232 | 2 Formcrafts, Wordpress | 2 Formcraft, Wordpress | 2026-08-02 | 7.2 High |
| The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit chain combines a server-side gap — where composite matrix sub-field keys such as field2_0 and field2_1 are never passed through the sanitization loop and are stored raw via $wpdb->insert() — with a client-side gap where DOMPurify is only invoked when typeof field.value === 'string', but matrix values arrive from the server as arrays, bypassing the check before being mapped to strings and injected into the DOM. Additionally, the same sink is reachable via a second attack vector: array-typed field values are passed through htmlentities() on submission but later reversed by html_entity_decode() at formcraft-main.php:2608 and :2122, restoring the malicious payload before storage and rendering. | ||||
| CVE-2026-24537 | 2 Alex Volkov, Wordpress | 2 Wp Accessibility Helper, Wordpress | 2026-08-02 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||||
| CVE-2026-27372 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-27391 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27392 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 4.3 Medium |
| Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27423 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-02 | 4.3 Medium |
| Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-57367 | 2 Wordpress, Wpbookingsystem | 2 Wordpress, Wp Booking System | 2026-08-02 | 7.1 High |
| Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | ||||
| CVE-2026-57701 | 2 Webcodingplace, Wordpress | 2 Real Estate Manager, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | ||||
| CVE-2026-57717 | 2 Knit Pay, Wordpress | 2 Knit Pay, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | ||||
| CVE-2026-57767 | 2 Codecabin, Wordpress | 2 Wp Google Maps, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | ||||
| CVE-2026-57784 | 2 Ninjaforms, Wordpress | 2 Ninja Forms File Uploads, Wordpress | 2026-08-02 | 9.6 Critical |
| Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||||
| CVE-2026-59513 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-02 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | ||||
| CVE-2026-59524 | 2 Sandhillsdev, Wordpress | 2 Easy Digital Downloads, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | ||||
| CVE-2026-59525 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-02 | 9.3 Critical |
| Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59540 | 2 Cozyvision, Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-08-02 | 9.8 Critical |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | ||||
| CVE-2026-59544 | 2 Thrivethemes, Wordpress | 2 Thrive Quiz Builder, Wordpress | 2026-08-02 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | ||||
| CVE-2026-59545 | 2 Miniorange, Wordpress | 2 Discord Integration, Wordpress | 2026-08-02 | 8.1 High |
| Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | ||||
| CVE-2026-59555 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-02 | 10 Critical |
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-61943 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-02 | 7.5 High |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. | ||||
| CVE-2026-61948 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-02 | 9.3 Critical |
| Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | ||||