Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cms Clear
ID Title
CVE-2026-16985 Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
CVE-2026-16257 Authentication Bypass in wordpress (CVE-2026-16257)
authentication bypass in wordpress (CVE-2026-16257). Data can be tampered with by attackers.
CVE-2026-14293 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14293)
cross-site scripting in wordpress (CVE-2026-14293). Successful exploitation can lead to full system takeover.
CVE-2026-14237 Privilege Escalation in wordpress (CVE-2026-14237)
vulnerability in wordpress (CVE-2026-14237). Successful exploitation can lead to full system takeover.
CVE-2026-14206 Information Disclosure in wordpress (CVE-2026-14206)
vulnerability in wordpress (CVE-2026-14206). Confidential information can be exposed externally.
CVE-2026-13600 Authentication Bypass in wordpress (CVE-2026-13600)
authentication bypass in wordpress (CVE-2026-13600). Successful exploitation can lead to full system takeover.
CVE-2026-13170 Path Traversal in wordpress (CVE-2026-13170)
path traversal in wordpress (CVE-2026-13170). Successful exploitation can lead to full system takeover.
CVE-2026-18464 Vulnerability in wordpress (CVE-2026-18464)
vulnerability in wordpress (CVE-2026-18464). Risk of unauthorized operations or information disclosure.
CVE-2026-18357 Information Disclosure in wordpress (CVE-2026-18357)
vulnerability in wordpress (CVE-2026-18357). Confidential information can be exposed externally.
CVE-2026-17017 SQL Injection in wordpress (CVE-2026-17017)
SQL injection in wordpress (CVE-2026-17017). Confidential information can be exposed externally.
CVE-2026-16988 Information Disclosure in wordpress (CVE-2026-16988)
vulnerability in wordpress (CVE-2026-16988). Confidential information can be exposed externally.
CVE-2026-18032 Information Disclosure in wordpress (CVE-2026-18032)
vulnerability in wordpress (CVE-2026-18032). Confidential information can be exposed externally.
CVE-2026-17044 SQL Injection in wordpress (CVE-2026-17044)
SQL injection in wordpress (CVE-2026-17044). Confidential information can be exposed externally.
CVE-2026-16948 Vulnerability in wordpress (CVE-2026-16948)
vulnerability in wordpress (CVE-2026-16948). Data can be tampered with by attackers.
CVE-2026-16594 Information Disclosure in wordpress (CVE-2026-16594)
vulnerability in wordpress (CVE-2026-16594). Confidential information can be exposed externally.
CVE-2026-16589 SQL Injection in wordpress (CVE-2026-16589)
SQL injection in wordpress (CVE-2026-16589). Confidential information can be exposed externally.
CVE-2026-16578 Information Disclosure in wordpress (CVE-2026-16578)
vulnerability in wordpress (CVE-2026-16578). Confidential information can be exposed externally.
CVE-2026-16267 Unsafe Deserialization in wordpress (CVE-2026-16267)
vulnerability in wordpress (CVE-2026-16267). Successful exploitation can lead to full system takeover.
CVE-2026-16262 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16262)
vulnerability in wordpress (CVE-2026-16262). Risk of unauthorized operations or information disclosure.
CVE-2026-16263 Path Traversal in wordpress (CVE-2026-16263)
path traversal in wordpress (CVE-2026-16263). Successful exploitation can lead to full system takeover.
CVE-2026-15361 SQL Injection in wordpress (CVE-2026-15361)
SQL injection in wordpress (CVE-2026-15361). Confidential information can be exposed externally.
CVE-2026-14943 Information Disclosure in wordpress (CVE-2026-14943)
vulnerability in wordpress (CVE-2026-14943). Confidential information can be exposed externally. Mitigation: upgrade to `2.6.7` or later.
CVE-2026-16041 Vulnerability in wordpress (CVE-2026-16041)
vulnerability in wordpress (CVE-2026-16041). Data can be tampered with by attackers.
CVE-2026-15215 Privilege Escalation in wordpress (CVE-2026-15215)
vulnerability in wordpress (CVE-2026-15215). Successful exploitation can lead to full system takeover.
CVE-2026-16030 Authentication Bypass in wordpress (CVE-2026-16030)
authentication bypass in wordpress (CVE-2026-16030). Successful exploitation can lead to full system takeover.
CVE-2026-16620 Vulnerability in wordpress (CVE-2026-16620)
vulnerability in wordpress (CVE-2026-16620). Data can be tampered with by attackers.
CVE-2026-16619 Vulnerability in wordpress (CVE-2026-16619)
vulnerability in wordpress (CVE-2026-16619). Successful exploitation can lead to full system takeover.
CVE-2026-13399 Vulnerability in wordpress (CVE-2026-13399)
vulnerability in wordpress (CVE-2026-13399). Data can be tampered with by attackers.
CVE-2026-12584 Vulnerability in wordpress (CVE-2026-12584)
vulnerability in wordpress (CVE-2026-12584). Data can be tampered with by attackers.
CVE-2026-10599 Vulnerability in wordpress (CVE-2026-10599)
vulnerability in wordpress (CVE-2026-10599). Data can be tampered with by attackers.
CVE-2026-10524 Vulnerability in wordpress (CVE-2026-10524)
vulnerability in wordpress (CVE-2026-10524). Data can be tampered with by attackers.
CVE-2026-3430 SQL Injection in wordpress (CVE-2026-3430)
SQL injection in wordpress (CVE-2026-3430). Confidential information can be exposed externally.
CVE-2026-66705 Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2025-15028 Cross-Site Scripting (XSS) in wordpress (CVE-2025-15028)
cross-site scripting in wordpress (CVE-2025-15028). Risk of unauthorized operations or information disclosure.
CVE-2026-18510 Cross-Site Scripting (XSS) in wordpress (CVE-2026-18510)
cross-site scripting in wordpress (CVE-2026-18510). Risk of unauthorized operations or information disclosure.
CVE-2026-16268 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16268)
SSRF in wordpress (CVE-2026-16268). Data can be tampered with by attackers.
CVE-2026-18050 Information Disclosure in wordpress (CVE-2026-18050)
vulnerability in wordpress (CVE-2026-18050). Confidential information can be exposed externally.
CVE-2026-16734 Vulnerability in wordpress (CVE-2026-16734)
vulnerability in wordpress (CVE-2026-16734). Data can be tampered with by attackers.
CVE-2026-13154 Information Disclosure in wordpress (CVE-2026-13154)
vulnerability in wordpress (CVE-2026-13154). Confidential information can be exposed externally.
CVE-2026-13153 Information Disclosure in wordpress (CVE-2026-13153)
vulnerability in wordpress (CVE-2026-13153). Confidential information can be exposed externally.
CVE-2026-14829 Vulnerability in wordpress (CVE-2026-14829)
vulnerability in wordpress (CVE-2026-14829). Data can be tampered with by attackers.
CVE-2026-15459 Authentication Bypass in wordpress (CVE-2026-15459)
authentication bypass in wordpress (CVE-2026-15459). Successful exploitation can lead to full system takeover.
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
CVE-2026-7529 Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
CVE-2026-17506 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →