Export limit exceeded: 400838 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 400838 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400838 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97256 2 Greg–siteorigin, Wordpress-extensions 2 Page Builder By Siteorigin, Page Builder By Siteorigin 2026-10-01 7.2 High
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
CVE-2026-97265 2 Crocoblock. Jetimpex Inc., Wordpress-extensions 2 Jetengine, Jetengine 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
CVE-2026-97290 2 Sayontan Sinha, Wordpress-extensions 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Photonic Gallery & Lightbox For Flickr, Smugmug & Others 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
CVE-2026-97291 2 Magazine3, Wordpress-extensions 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp 2026-10-01 8.8 High
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-100510 2 Boldgrid, Wordpress-extensions 2 Post And Page Builder, Post And Page Builder By Boldgrid 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
CVE-2026-100512 2 Hook & Filter, Wordpress-extensions 2 Nested Pages, Nested Pages 2026-10-01 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-102375 2 Optimole, Wordpress-extensions 2 Optimole, Optimole 2026-10-01 6.5 Medium
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
CVE-2026-102376 2 Wordpress-extensions, Wpmudev 2 Branda, Branda 2026-10-01 7.1 High
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
CVE-2026-102377 2 10web, Wordpress-extensions 2 Photo Gallery, Photo Gallery By 10web 2026-10-01 8.8 High
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-102391 2 Jetmonsters, Wordpress-extensions 2 Jetformbuilder, Jetformbuilder 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
CVE-2026-102392 2 Themehigh, Wordpress-extensions 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce 2026-10-01 7.2 High
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
CVE-2026-76142 1 Genians 2 Genian Nac, Genian Ztna 2026-10-01 N/A
Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
CVE-2026-76143 1 Genians 1 Genian Ssl Pns (frodo-core) 2026-10-01 N/A
A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter.
CVE-2026-76144 1 Genians 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) 2026-10-01 N/A
An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch
CVE-2026-76145 1 Genians 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) 2026-10-01 N/A
An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration
CVE-2026-76147 1 Genians 2 Genian Nac, Genian Ztna 2026-10-01 N/A
A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code
CVE-2026-85679 2 Extendify, Wordpress-extensions 2 Extendify, Extendify 2026-10-01 7.2 High
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because registerIncoming() is hooked on rest_request_before_callbacks and runs before WordPress evaluates the route's permission_callback, meaning any unauthenticated POST, PUT, or PATCH request to a /wp/v2/global-styles route can trigger the vulnerable code path.
CVE-2026-96813 2 10web, Wordpress-extensions 2 Form Maker, Form Maker By 10web 2026-10-01 7.2 High
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-89427 2 Spacetime, Wordpress-extensions 2 Ad Inserter, Ad Inserter 2026-10-01 6.1 Medium
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has configured at least one Ad Inserter block using the {title} or {short-title} placeholder with that block enabled for search pages, which is a standard, documented plugin feature.
CVE-2026-89424 2 Inisev, Wordpress-extensions 2 Duplicate Post, Duplicate Post 2026-10-01 6.4 Medium
The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires that the site owner has enabled the plugin's User Level Permissions for the Subscriber role, as this grants access to the i_saw_this_noti AJAX branch needed to deliver the payload.