Export limit exceeded: 399886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399886 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85573 | 2026-09-30 | 8.8 High | ||
| The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them. | ||||
| CVE-2026-85415 | 2026-09-30 | 6.8 Medium | ||
| The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post). | ||||
| CVE-2026-85001 | 2026-09-30 | 6.8 Medium | ||
| The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed. | ||||
| CVE-2026-83560 | 2026-09-30 | 5.3 Medium | ||
| The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users. | ||||
| CVE-2026-82127 | 2026-09-30 | 3.5 Low | ||
| The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability. | ||||
| CVE-2026-81867 | 1 Google | 1 Application Integration | 2026-09-30 | N/A |
| A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed. | ||||
| CVE-2026-80333 | 2026-09-30 | 5.3 Medium | ||
| The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve. | ||||
| CVE-2026-7172 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-30 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-7171 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-30 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-7170 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-30 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-75873 | 2026-09-30 | 9.8 Critical | ||
| The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution. | ||||
| CVE-2026-75824 | 2026-09-30 | 5.3 Medium | ||
| The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role. | ||||
| CVE-2026-75823 | 2026-09-30 | 7.4 High | ||
| The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way. | ||||
| CVE-2026-62085 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | ||||
| CVE-2026-62083 | 2026-09-30 | 5.4 Medium | ||
| Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions. | ||||
| CVE-2026-62081 | 2026-09-30 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions. | ||||
| CVE-2026-62080 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. | ||||
| CVE-2026-62079 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | ||||
| CVE-2026-62078 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | ||||
| CVE-2026-27371 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | ||||