Export limit exceeded: 12896 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (12896 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65479 | 2 Mvp Themes, Wordpress | 2 Reviewer, Wordpress | 2026-07-23 | 5.4 Medium |
| Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-65485 | 2 Daniel Iser, Wordpress | 2 Content Control, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | ||||
| CVE-2026-65486 | 2 Bastien Ho, Wordpress | 2 Event Post, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | ||||
| CVE-2026-65500 | 2 Pixelacehq, Wordpress | 2 Manual - Documentation, Knowledge Base & Education Wordpress Theme, Wordpress | 2026-07-23 | 7.5 High |
| Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | ||||
| CVE-2026-65524 | 2 Themefusion, Wordpress | 2 Avada Custom Branding, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | ||||
| CVE-2026-65525 | 2 Uxper, Wordpress | 2 Civi Framework, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | ||||
| CVE-2026-65537 | 2 Themeisle, Wordpress | 2 Cyr To Lat Reloaded – Transliteration Of Links And File Names, Wordpress | 2026-07-23 | 4.3 Medium |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | ||||
| CVE-2026-65594 | 1 N8n | 1 N8n | 2026-07-23 | 6.5 Medium |
| n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user's workflow, and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, and the attacker can set tool inputs and read outputs (potentially including data from the owner's connected integrations), breaking user and project isolation. | ||||
| CVE-2026-13068 | 1 Mongodb | 2 Mongodb, Mongodb Server | 2026-07-23 | 4.2 Medium |
| An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not correctly scope privileges to the appropriate namespace. | ||||
| CVE-2026-13061 | 1 Mongodb | 2 Mongodb, Mongodb Server | 2026-07-23 | 4.3 Medium |
| An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps. | ||||
| CVE-2026-65050 | 2 Ninjaforms, Wordpress | 2 Ninja Forms, Wordpress | 2026-07-23 | 6.5 Medium |
| Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers. | ||||
| CVE-2026-65452 | 2 Motovnet, Wordpress | 2 Ebook Store, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | ||||
| CVE-2026-27418 | 2 Epsiloncool, Wordpress | 2 Wp Fast Total Search, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. | ||||
| CVE-2026-57808 | 2 Saad Iqbal, Wordpress | 2 Wp Easypay, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. | ||||
| CVE-2026-59522 | 2 Wedevs, Wordpress | 2 Wp Erp, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | ||||
| CVE-2026-65489 | 2 Lastudio, Wordpress | 2 La-studio Element Kit For Elementor, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65495 | 2 Dokan Multivendor Plugin, Wordpress | 2 Dokan Pro, Wordpress | 2026-07-23 | 7.5 High |
| Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. | ||||
| CVE-2026-65529 | 2 Iqonicdesign, Wordpress | 2 Graphina, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | ||||
| CVE-2026-65531 | 2 Themeum, Wordpress | 2 Qubely, Wordpress | 2026-07-23 | 4.8 Medium |
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | ||||
| CVE-2026-59547 | 2 Easy Payment, Wordpress | 2 Payment Gateway For Paypal On Woo Commerce, Wordpress | 2026-07-23 | 7.5 High |
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | ||||