Search
Search Results (399943 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97240 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | ||||
| CVE-2026-97239 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | ||||
| CVE-2026-97238 | 2026-09-30 | 5.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | ||||
| CVE-2026-97237 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | ||||
| CVE-2026-97236 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | ||||
| CVE-2026-97235 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | ||||
| CVE-2026-97197 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | ||||
| CVE-2026-97079 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions. | ||||
| CVE-2026-97078 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions. | ||||
| CVE-2026-97077 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions. | ||||
| CVE-2026-97074 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | ||||
| CVE-2026-97067 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. | ||||
| CVE-2026-97066 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-97065 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | ||||
| CVE-2026-96886 | 2026-09-30 | 5.3 Medium | ||
| The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course. | ||||
| CVE-2026-96838 | 2026-09-30 | 8.8 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | ||||
| CVE-2026-96837 | 2026-09-30 | 8.8 High | ||
| Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions. | ||||
| CVE-2026-96836 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. | ||||
| CVE-2026-96835 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. | ||||
| CVE-2026-96834 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | ||||