Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66664 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
|
| CVE-2026-66440 |
|
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
|
| CVE-2026-66457 |
|
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
|
| CVE-2026-66663 |
|
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
|
| CVE-2026-66439 |
|
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
|
| CVE-2026-65560 |
|
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
|
| CVE-2026-65565 |
|
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
|
| CVE-2026-65569 |
|
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
|
| CVE-2026-65559 |
|
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
|
| CVE-2026-65544 |
|
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
|
| CVE-2026-65545 |
|
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
|
| CVE-2026-65547 |
|
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
|
| CVE-2026-65509 |
|
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
|
| CVE-2026-65513 |
|
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
|
| CVE-2026-65515 |
|
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
|
| CVE-2026-65517 |
|
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
|
| CVE-2026-61963 |
|
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
|
| CVE-2026-61964 |
|
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
|
| CVE-2026-61982 |
|
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
|
| CVE-2026-61961 |
|
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
|
| CVE-2026-28183 |
|
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
|
| CVE-2026-28177 |
|
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
|
| CVE-2026-28172 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
|
| CVE-2026-28141 |
|
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
|
| CVE-2026-28143 |
|
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
|
| CVE-2026-28111 |
|
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
|
| CVE-2026-28082 |
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
|
| CVE-2025-15028 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15028)
cross-site scripting in wordpress (CVE-2025-15028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64958 |
|
Vulnerability in apache (CVE-2026-64958)
vulnerability in apache (CVE-2026-64958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57819 |
|
Vulnerability in apache (CVE-2026-57819)
vulnerability in apache (CVE-2026-57819). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54225 |
|
Vulnerability in apache (CVE-2026-54225)
vulnerability in apache (CVE-2026-54225). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19021 |
|
Vulnerability in sqli (CVE-2026-19021)
vulnerability in sqli (CVE-2026-19021). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18597 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18597)
SSRF in ssrf (CVE-2026-18597). Confidential information can be exposed externally.
|
| CVE-2026-18649 |
|
Vulnerability in dos (CVE-2026-18649)
vulnerability in dos (CVE-2026-18649). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18510 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18510)
cross-site scripting in wordpress (CVE-2026-18510). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15459 |
|
Authentication Bypass in wordpress (CVE-2026-15459)
authentication bypass in wordpress (CVE-2026-15459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18325 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-16636 |
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
| CVE-2026-15991 |
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
| CVE-2026-18991 |
|
Path Traversal in path-traversal (CVE-2026-18991)
path traversal in path-traversal (CVE-2026-18991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67872 |
|
Vulnerability in dos (CVE-2026-67872)
vulnerability in dos (CVE-2026-67872). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18970 |
|
Vulnerability in sqli (CVE-2026-18970)
vulnerability in sqli (CVE-2026-18970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67871 |
|
Vulnerability in c (CVE-2026-67871)
vulnerability in c (CVE-2026-67871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67869 |
|
Vulnerability in dos (CVE-2026-67869)
vulnerability in dos (CVE-2026-67869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67863 |
|
Use-After-Free in dos (CVE-2026-67863)
vulnerability in dos (CVE-2026-67863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67867 |
|
Vulnerability in dos (CVE-2026-67867)
vulnerability in dos (CVE-2026-67867). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67866 |
|
Vulnerability in dos (CVE-2026-67866)
vulnerability in dos (CVE-2026-67866). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67864 |
|
Vulnerability in dos (CVE-2026-67864)
vulnerability in dos (CVE-2026-67864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67865 |
|
Out-of-Bounds Read in dos (CVE-2026-67865)
vulnerability in dos (CVE-2026-67865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15996 |
|
Vulnerability in dos (CVE-2026-15996)
vulnerability in dos (CVE-2026-15996). Risk of unauthorized operations or information disclosure.
|