Export limit exceeded: 400566 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400566 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102392 | 2 Themehigh, Wordpress-extensions | 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce | 2026-10-01 | 7.2 High |
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | ||||
| CVE-2026-76142 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | ||||
| CVE-2026-76143 | 1 Genians | 1 Genian Ssl Pns (frodo-core) | 2026-10-01 | N/A |
| A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | ||||
| CVE-2026-76144 | 1 Genians | 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) | 2026-10-01 | N/A |
| An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch | ||||
| CVE-2026-76145 | 1 Genians | 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) | 2026-10-01 | N/A |
| An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration | ||||
| CVE-2026-76147 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | ||||
| CVE-2026-85679 | 2 Extendify, Wordpress-extensions | 2 Extendify, Extendify | 2026-10-01 | 7.2 High |
| The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because registerIncoming() is hooked on rest_request_before_callbacks and runs before WordPress evaluates the route's permission_callback, meaning any unauthenticated POST, PUT, or PATCH request to a /wp/v2/global-styles route can trigger the vulnerable code path. | ||||
| CVE-2026-96813 | 2 10web, Wordpress-extensions | 2 Form Maker, Form Maker By 10web | 2026-10-01 | 7.2 High |
| The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-89427 | 2 Spacetime, Wordpress-extensions | 2 Ad Inserter, Ad Inserter | 2026-10-01 | 6.1 Medium |
| The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature. | ||||
| CVE-2026-89424 | 2 Inisev, Wordpress-extensions | 2 Duplicate Post, Duplicate Post | 2026-10-01 | 6.4 Medium |
| The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload. | ||||
| CVE-2026-97661 | 2 Scottpaterson, Wordpress-extensions | 2 Business Essentials For Contact Form 7, Business Essentials For Contact Form 7 | 2026-10-01 | 7.2 High |
| The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Payments module to be enabled and a form to be configured to accept both PayPal and Stripe as payment gateways. | ||||
| CVE-2026-103353 | 2 Wordpress-extensions, Wpmanageninja | 2 Fluentform, Fluent Forms | 2026-10-01 | 5.3 Medium |
| Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. | ||||
| CVE-2026-88789 | 1 Apache | 1 Camel Quarkus | 2026-10-01 | 8.6 High |
| Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document. The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error. Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves. Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue. | ||||
| CVE-2026-103679 | 1 Verdammelt | 1 Tnef | 2026-10-01 | 6.5 Medium |
| A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS). | ||||
| CVE-2026-103067 | 2 Memberful, Wordpress-extensions | 2 Memberful - Membership Plugin, Memberful | 2026-10-01 | 8 High |
| Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0. | ||||
| CVE-2026-103340 | 2 Geminilabs, Wordpress-extensions | 2 Site Reviews, Site Reviews | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | ||||
| CVE-2026-102381 | 2 Ahmad, Wordpress-extensions | 2 Majestic Support, Majestic Support | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | ||||
| CVE-2026-102390 | 2 Villatheme, Wordpress-extensions | 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9. | ||||
| CVE-2026-103063 | 2 Wordpress-extensions, Wpmet | 2 Elementskit Elementor Addons Lite, Elementskit Elementor Addons | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | ||||
| CVE-2026-102379 | 2 Villatheme, Wordpress-extensions | 2 Buildkit – Product Builder For Woocommerce – Custom Pc Builder, Buildkit-product Builder For Woocommerce-custom Pc Builder | 2026-10-01 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | ||||