Export limit exceeded: 373506 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373506 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28082 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetreviews, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | ||||
| CVE-2026-28111 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms | 2026-08-07 | 8.8 High |
| Contributor Privilege Escalation in Forminator <= 1.56.0 versions. | ||||
| CVE-2026-28139 | 2 Wordpress, Wp-dreams | 2 Wordpress, Ajax Search | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||||
| CVE-2025-13909 | 1 Wso2 | 7 Carbon Identity Application Authentication Framework, Email Otp Authenticator, Identity Server and 4 more | 2026-08-07 | 4.3 Medium |
| The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers. | ||||
| CVE-2026-18915 | 1 Tubitak Bilgem Software Technologies Research Institute | 1 Eta-otp-lock | 2026-08-07 | 5 Medium |
| Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4. | ||||
| CVE-2026-1728 | 1 Wso2 | 10 Api Control Plane, Api Manager, Traffic Manager and 7 more | 2026-08-07 | 9.8 Critical |
| Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it. | ||||
| CVE-2026-5158 | 2 Wordpress, Wpxpo | 2 Wordpress, Postx - Gutenberg Blocks For Post Grid | 2026-08-07 | 6.4 Medium |
| The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inputPlaceHolder' parameter in all versions up to, and including, 5.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-15599 | 1 Tubitak Bilgem Software Technologies Research Institute | 1 Pardus Domain Joiner | 2026-08-07 | 3.3 Low |
| Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain-joiner: before 0.5.5. | ||||
| CVE-2025-15674 | 2 Passster Project, Wordpress | 2 Passster, Wordpress | 2026-08-07 | 2.7 Low |
| The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password. | ||||
| CVE-2026-41861 | 1 Cloud Foundry | 1 Bosh | 2026-08-07 | 4.2 Medium |
| Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions"). | ||||
| CVE-2026-71436 | 1 Mermaid Project | 1 Mermaid | 2026-08-07 | 7.5 High |
| Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1. | ||||
| CVE-2026-63637 | 1 Dgraph | 1 Dgraph | 2026-08-07 | 8.6 High |
| Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators, disclose unintended nodes, or expand modification and deletion targets. This issue is fixed in version 25.3.8. | ||||
| CVE-2026-54717 | 1 Silverstripe | 1 Silverstripe | 2026-08-07 | 5.4 Medium |
| Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1. | ||||
| CVE-2026-62857 | 1 Fedify | 1 Fedify | 2026-08-07 | N/A |
| Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2. | ||||
| CVE-2026-16263 | 2 Wordpress, Wp Maps | 2 Wordpress, Wp Maps | 2026-08-07 | N/A |
| The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. | ||||
| CVE-2026-15215 | 2026-08-07 | N/A | ||
| The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution. | ||||
| CVE-2026-15245 | 2026-08-07 | N/A | ||
| The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content. | ||||
| CVE-2026-15361 | 2026-08-07 | N/A | ||
| The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks. | ||||
| CVE-2026-15386 | 2026-08-07 | N/A | ||
| The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery. | ||||
| CVE-2026-16262 | 2026-08-07 | N/A | ||
| The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker. | ||||