Export limit exceeded: 404311 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404311 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-42631 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions.
CVE-2026-42630 2026-10-11 7.5 High
Unauthenticated Sensitive Data Exposure in Web Plura Backup &amp; Restore Manager <= 0.2.25 versions.
CVE-2026-42419 2026-10-11 5.9 Medium
Unauthenticated Sensitive Data Exposure in Swish Migrate and Backup <= 1.4.0 versions.
CVE-2026-40803 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Jotform &#8211; AI Chatbot <= 3.8.2 versions.
CVE-2026-40800 2026-10-11 9.3 Critical
Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions.
CVE-2026-39800 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce <= 1.24 versions.
CVE-2026-39799 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP File Download <= 6.3.6 versions.
CVE-2026-27350 1 Builderius.io 1 Builderius 2026-10-11 7.2 High
Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery. This issue affects Builderius: from 1.4 through 1.4-beta.
CVE-2026-14854 2026-10-11 7.5 High
The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request.
CVE-2026-12980 2026-10-11 6.8 Medium
The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed.
CVE-2026-107694 2026-10-11 2.7 Low
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors.
CVE-2026-106029 2026-10-11 7.5 High
The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide.
CVE-2026-105889 2026-10-11 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
CVE-2026-105870 2026-10-11 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Delight Star Inc. WP Associate Post R2 wp-associate-post-r2 allows Reflected XSS.This issue affects WP Associate Post R2: from n/a through 5.0.1.
CVE-2026-104682 2026-10-11 2.7 Low
The Envira Gallery WordPress plugin before 1.16.2 does not correctly check authorization on its gallery-conversion feature, verifying that the requester can edit an arbitrary post they name rather than that they are allowed to create the Envira Gallery WordPress plugin before 1.16.2's own gallery content, allowing users with contributor-level access to create and publish gallery posts that the Envira Gallery WordPress plugin before 1.16.2's settings otherwise withhold from them.
CVE-2026-104681 2026-10-11 2.7 Low
The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them.
CVE-2026-104680 2026-10-11 7.2 High
The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing Envira Gallery WordPress plugin before 1.16.2 code before processing its setup-wizard Envira Gallery WordPress plugin before 1.16.2-installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published Envira Gallery WordPress plugin before 1.16.2 into the network-shared Envira Gallery WordPress plugin before 1.16.2 directory, a privilege Multisite reserves for the network Super Admin.
CVE-2026-103695 2026-10-11 8.6 High
The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-103305 2026-10-11 8.8 High
The Prenotazioni WordPress plugin through 1.7.5 does not have authorisation and CSRF checks when saving its settings, and does not escape some of them when outputting them, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors.
CVE-2026-102388 2026-10-11 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.57.3.