Export limit exceeded: 400095 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400095 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94121 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. | ||||
| CVE-2026-94120 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. | ||||
| CVE-2026-94115 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | ||||
| CVE-2026-94082 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. | ||||
| CVE-2026-94081 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. | ||||
| CVE-2026-94078 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | ||||
| CVE-2026-94077 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. | ||||
| CVE-2026-94076 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. | ||||
| CVE-2026-94074 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | ||||
| CVE-2026-93771 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | ||||
| CVE-2026-93770 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | ||||
| CVE-2026-93651 | 2026-09-30 | 7.2 High | ||
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | ||||
| CVE-2026-93624 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | ||||
| CVE-2026-93621 | 2026-09-30 | 8.2 High | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | ||||
| CVE-2026-93580 | 2026-09-30 | 5.3 Medium | ||
| The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed. | ||||
| CVE-2026-93514 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | ||||
| CVE-2026-93512 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | ||||
| CVE-2026-92994 | 2026-09-30 | 8.8 High | ||
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | ||||
| CVE-2026-92424 | 2026-09-30 | 6.8 Medium | ||
| The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content. | ||||
| CVE-2026-91832 | 2026-09-30 | 7.1 High | ||
| The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting. | ||||