Export limit exceeded: 399927 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399927 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399927 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102385 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||
| CVE-2026-102384 | 2026-09-30 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. | ||||
| CVE-2026-100513 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. | ||||
| CVE-2026-100508 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. | ||||
| CVE-2026-100507 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. | ||||
| CVE-2026-97289 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | ||||
| CVE-2026-97288 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | ||||
| CVE-2026-97287 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Event Tickets <= 5.29.5 versions. | ||||
| CVE-2026-97286 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions. | ||||
| CVE-2026-97285 | 2026-09-30 | 5.4 Medium | ||
| Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | ||||
| CVE-2026-97282 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | ||||
| CVE-2026-97279 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. | ||||
| CVE-2026-97274 | 2026-09-30 | 9.8 Critical | ||
| Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | ||||
| CVE-2026-97272 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. | ||||
| CVE-2026-97271 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-97250 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | ||||
| CVE-2026-91206 | 1 Apache | 1 Roller | 2026-09-30 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values. | ||||
| CVE-2026-91204 | 1 Apache | 1 Roller | 2026-09-30 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs. | ||||
| CVE-2026-82546 | 1 Apache | 1 Roller | 2026-09-30 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments. | ||||
| CVE-2026-40552 | 1 Binsoft | 1 Mpgabinet | 2026-09-30 | N/A |
| Multiple BinSoft products are vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote network resource. Alternatively, it is possible to use a previously uploaded file and change its reference. When the application processes the attachment, and a user tries to open it, the referenced resource is executed by the system. Critically, this vulnerability can be exploited by any unauthenticated attacker by chaining it with CVE-2026-40550 and CVE-2026-40551, which allows obtaining database access, and logging onto any account. The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual. | ||||