Export limit exceeded: 10902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 50187 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50187 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96816 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. | ||||
| CVE-2026-96814 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions. | ||||
| CVE-2026-96450 | 2026-09-30 | 5.4 Medium | ||
| Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions. | ||||
| CVE-2026-96352 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | ||||
| CVE-2026-96351 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. | ||||
| CVE-2026-96338 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | ||||
| CVE-2026-94674 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. | ||||
| CVE-2026-94081 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | ||||
| CVE-2026-94078 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | ||||
| CVE-2026-94077 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. | ||||
| CVE-2026-93770 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | ||||
| CVE-2026-93514 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | ||||
| CVE-2026-93512 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | ||||
| CVE-2026-92424 | 2026-09-30 | 6.8 Medium | ||
| The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content. | ||||
| CVE-2026-91832 | 2026-09-30 | 7.1 High | ||
| The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting. | ||||
| CVE-2026-89193 | 2026-09-30 | 7.5 High | ||
| The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators. | ||||
| CVE-2026-87777 | 2026-09-30 | 6.8 Medium | ||
| The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor. | ||||
| CVE-2026-85415 | 2026-09-30 | 6.8 Medium | ||
| The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post). | ||||
| CVE-2026-85001 | 2026-09-30 | 6.8 Medium | ||
| The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed. | ||||
| CVE-2026-7172 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-30 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||