Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-10656 |
|
Authorization Flaw in wordpress (CVE-2025-10656)
vulnerability in wordpress (CVE-2025-10656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13423 |
|
Code Injection in wordpress (CVE-2026-13423)
code injection in wordpress (CVE-2026-13423). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18072 |
|
Vulnerability in wordpress (CVE-2026-18072)
vulnerability in wordpress (CVE-2026-18072). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-15014 |
|
Vulnerability in wordpress (CVE-2026-15014)
vulnerability in wordpress (CVE-2026-15014). Successful exploitation can lead to full system takeover. Exploitable via ``billing_phone``.
|
| CVE-2026-14545 |
|
Privilege Escalation in wordpress (CVE-2026-14545)
vulnerability in wordpress (CVE-2026-14545). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59549 |
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
|
| CVE-2026-13597 |
|
Authentication Bypass in wordpress (CVE-2026-13597)
authentication bypass in wordpress (CVE-2026-13597). Confidential information can be exposed externally.
|
| CVE-2026-13714 |
|
Unrestricted File Upload in wordpress (CVE-2026-13714)
vulnerability in wordpress (CVE-2026-13714). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14289 |
|
Code Injection in wordpress (CVE-2026-14289)
code injection in wordpress (CVE-2026-14289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12394 |
|
Privilege Escalation in wordpress (CVE-2026-12394)
vulnerability in wordpress (CVE-2026-12394). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13332 |
|
Authentication Bypass in wordpress (CVE-2026-13332)
authentication bypass in wordpress (CVE-2026-13332). Confidential information can be exposed externally.
|
| CVE-2026-12877 |
|
Authentication Bypass in wordpress (CVE-2026-12877)
authentication bypass in wordpress (CVE-2026-12877). Confidential information can be exposed externally.
|
| CVE-2026-15981 |
|
Authentication Bypass in wordpress (CVE-2026-15981)
authentication bypass in wordpress (CVE-2026-15981). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15011 |
|
Code Injection in wordpress (CVE-2026-15011)
code injection in wordpress (CVE-2026-15011). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14282 |
|
Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15015 |
|
Vulnerability in wordpress (CVE-2026-15015)
vulnerability in wordpress (CVE-2026-15015). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65049 |
|
Authorization Flaw in wordpress (CVE-2026-65049)
vulnerability in wordpress (CVE-2026-65049). Data can be tampered with by attackers.
|
| CVE-2026-65048 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65048)
cross-site scripting in wordpress (CVE-2026-65048). Confidential information can be exposed externally.
|
| CVE-2026-13439 |
|
Privilege Escalation in wordpress (CVE-2026-13439)
vulnerability in wordpress (CVE-2026-13439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13147 |
|
Vulnerability in wordpress (CVE-2026-13147)
vulnerability in wordpress (CVE-2026-13147). Confidential information can be exposed externally.
|
| CVE-2026-63030 KEV |
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
| CVE-2026-9810 |
|
Privilege Escalation in wordpress (CVE-2026-9810)
vulnerability in wordpress (CVE-2026-9810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15982 |
|
Privilege Escalation in wordpress (CVE-2026-15982)
vulnerability in wordpress (CVE-2026-15982). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14956 |
|
Privilege Escalation in wordpress (CVE-2026-14956)
vulnerability in wordpress (CVE-2026-14956). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12492 |
|
Authentication Bypass in wordpress (CVE-2026-12492)
authentication bypass in wordpress (CVE-2026-12492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15013 |
|
Vulnerability in wordpress (CVE-2026-15013)
vulnerability in wordpress (CVE-2026-15013). Successful exploitation can lead to full system takeover. Exploitable via ``SignatureMethod``.
|
| CVE-2026-48356 |
|
Unrestricted File Upload in adobe (CVE-2026-48356)
vulnerability in adobe (CVE-2026-48356). Confidential information can be exposed externally.
|
| CVE-2026-48358 |
|
Vulnerability in adobe (CVE-2026-48358)
vulnerability in adobe (CVE-2026-48358). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13001 |
|
Vulnerability in wordpress (CVE-2026-13001)
vulnerability in wordpress (CVE-2026-13001). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11563 |
|
Vulnerability in wordpress (CVE-2026-11563)
vulnerability in wordpress (CVE-2026-11563). Data can be tampered with by attackers.
|
| CVE-2026-11964 |
|
Vulnerability in wordpress (CVE-2026-11964)
vulnerability in wordpress (CVE-2026-11964). Confidential information can be exposed externally.
|
| CVE-2026-15089 |
|
Authentication Bypass in drupal (CVE-2026-15089)
authentication bypass in drupal (CVE-2026-15089). Confidential information can be exposed externally.
|
| CVE-2026-12535 |
|
Vulnerability in drupal/formatter_field (CVE-2026-12535)
vulnerability in drupal/formatter_field (CVE-2026-12535). Successful exploitation can lead to full system takeover. Exploitable via ``formatter_field``. Mitigation: upgrade to `2.0.0` or later.
|
| CVE-2026-12761 |
|
Authentication Bypass in wordpress (CVE-2026-12761)
authentication bypass in wordpress (CVE-2026-12761). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15300 |
|
SQL Injection in wordpress (CVE-2026-15300)
SQL injection in wordpress (CVE-2026-15300). Data can be tampered with by attackers. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-15282 |
|
Unrestricted File Upload in wordpress (CVE-2026-15282)
vulnerability in wordpress (CVE-2026-15282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14894 |
|
Unrestricted File Upload in wordpress (CVE-2026-14894)
vulnerability in wordpress (CVE-2026-14894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15158 |
|
Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14245 |
|
Vulnerability in wordpress (CVE-2026-14245)
vulnerability in wordpress (CVE-2026-14245). Successful exploitation can lead to full system takeover. Exploitable via ``form_nonce``.
|
| CVE-2026-58480 |
|
Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12153 |
|
Vulnerability in wordpress (CVE-2026-12153)
vulnerability in wordpress (CVE-2026-12153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-4375 |
|
Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12375 |
|
Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6382 |
|
Vulnerability in wordpress (CVE-2026-6382)
vulnerability in wordpress (CVE-2026-6382). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11387 |
|
Authentication Bypass in wordpress (CVE-2026-11387)
authentication bypass in wordpress (CVE-2026-11387). Successful exploitation can lead to full system takeover.
|