Export limit exceeded: 402502 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402502 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402502 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39776 | 2 Wordpress-extensions, Wpshopmart | 2 Tabs, Tabs | 2026-10-06 | 8 High |
| Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions. | ||||
| CVE-2026-39778 | 2 Themeansar, Wordpress-extensions | 2 Ansar Import – One Click Starter Sites – For Elementor & Themes, Ansar Import – One Click Starter Sites – For Elementor & Themes | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor & Themes <= 2.1.2 versions. | ||||
| CVE-2026-39780 | 2 Wordpress-extensions, Youzify | 2 Youzify, Youzify | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-39781 | 2 Dan Rossiter, Wordpress-extensions | 2 Document Gallery, Document Gallery | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | ||||
| CVE-2026-39784 | 2 Nicdark, Wordpress-extensions | 2 Hotel Booking, Hotel Booking | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. | ||||
| CVE-2026-39785 | 2 Serhii Pasiuk, Wordpress-extensions | 2 Gmedia Photo Gallery, Gmedia Photo Gallery | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. | ||||
| CVE-2026-39787 | 2 10web, Wordpress-extensions | 2 10web Social Post Feed, 10web Social Photo Feed | 2026-10-06 | 6.5 Medium |
| Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | ||||
| CVE-2026-39788 | 2 Shamimsplugins, Wordpress-extensions | 2 Front End Pm, Front End Pm | 2026-10-06 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions. | ||||
| CVE-2026-39790 | 2 E4jvikwp, Wordpress-extensions | 2 Vikrentcar, Vikrentcar | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. | ||||
| CVE-2026-39792 | 2 Mitchell Bennis, Wordpress-extensions | 2 Simple File List, Simple File List | 2026-10-06 | 8.6 High |
| Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions. | ||||
| CVE-2026-39793 | 2 Nicu Micle, Wordpress-extensions | 2 Simple Jwt Login, Simple Jwt Login | 2026-10-06 | 8.8 High |
| Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. | ||||
| CVE-2026-39794 | 2 Wclovers, Wordpress-extensions | 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | ||||
| CVE-2026-39795 | 2 Brewlabs, Wordpress-extensions | 2 Sendpress Newsletters, Sendpress Newsletters | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | ||||
| CVE-2026-39796 | 2 Flipper Code, Wordpress-extensions | 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | ||||
| CVE-2026-39797 | 2 Data443, Wordpress-extensions | 2 Gdpr Framework By Data443, Gdpr Framework By Data443 | 2026-10-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | ||||
| CVE-2026-39798 | 2 Themetechmount, Wordpress-extensions | 2 Truebooker, Truebooker | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | ||||
| CVE-2026-40806 | 2 Plugin-devs, Wordpress-extensions | 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | ||||
| CVE-2026-40807 | 2 Aman, Wordpress-extensions | 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. | ||||
| CVE-2026-41555 | 2 Weblizar, Wordpress-extensions | 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | ||||
| CVE-2026-41559 | 2 Pluginjoy, Wordpress-extensions | 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions. | ||||