Search

Search Results (400097 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-91051 2026-09-30 6.6 Medium
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .
CVE-2026-89193 2026-09-30 7.5 High
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
CVE-2026-88797 2026-09-30 7.1 High
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
CVE-2026-88791 2026-09-30 3.4 Low
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
CVE-2026-87777 2026-09-30 6.8 Medium
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.
CVE-2026-85415 2026-09-30 6.8 Medium
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).
CVE-2026-85001 2026-09-30 6.8 Medium
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
CVE-2026-83560 2026-09-30 5.3 Medium
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
CVE-2026-81867 1 Google 1 Application Integration 2026-09-30 N/A
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.
CVE-2026-80333 2026-09-30 5.3 Medium
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
CVE-2026-7172 1 Tpvenlanube 1 Cloud Web Application 2026-09-30 N/A
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
CVE-2026-7171 1 Tpvenlanube 1 Cloud Web Application 2026-09-30 N/A
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
CVE-2026-7170 1 Tpvenlanube 1 Cloud Web Application 2026-09-30 N/A
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint  '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
CVE-2026-62085 2026-09-30 7.6 High
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
CVE-2026-62083 2026-09-30 5.4 Medium
Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.
CVE-2026-62081 2026-09-30 5.4 Medium
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
CVE-2026-62080 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
CVE-2026-62079 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.
CVE-2026-62078 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
CVE-2026-27371 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.