Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13114 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13114)
cross-site scripting in wordpress (CVE-2026-13114). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13353 |
|
Code Injection in wordpress (CVE-2026-13353)
code injection in wordpress (CVE-2026-13353). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13756 |
|
Privilege Escalation in wordpress (CVE-2026-13756)
vulnerability in wordpress (CVE-2026-13756). Successful exploitation can lead to full system takeover. Exploitable via ``wp_capabilities``.
|
| CVE-2026-55809 |
|
Vulnerability in drupal/flag_attendance_field (CVE-2026-55809)
vulnerability in drupal/flag_attendance_field (CVE-2026-55809). Confidential information can be exposed externally. Exploitable via ``flag_attendance_field``. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-55810 |
|
Vulnerability in drupal/plotly_js (CVE-2026-55810)
vulnerability in drupal/plotly_js (CVE-2026-55810). Confidential information can be exposed externally. Exploitable via ``plotly_js_graph``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-13244 |
|
Vulnerability in drupal/tealiumiq (CVE-2026-13244)
vulnerability in drupal/tealiumiq (CVE-2026-13244). Confidential information can be exposed externally. Exploitable via ``tealiumiq``. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-15081 |
|
SQL Injection in drupal (CVE-2026-15081)
SQL injection in drupal (CVE-2026-15081). Confidential information can be exposed externally.
|
| CVE-2026-1667 |
|
Vulnerability in wordpress (CVE-2026-1667)
vulnerability in wordpress (CVE-2026-1667). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12685 |
|
Vulnerability in wordpress (CVE-2026-12685)
vulnerability in wordpress (CVE-2026-12685). Data can be tampered with by attackers.
|
| CVE-2026-13347 |
|
Path Traversal in wordpress (CVE-2026-13347)
path traversal in wordpress (CVE-2026-13347). Confidential information can be exposed externally.
|
| CVE-2026-15298 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15298)
cross-site scripting in wordpress (CVE-2026-15298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15291 |
|
Vulnerability in wordpress (CVE-2026-15291)
vulnerability in wordpress (CVE-2026-15291). Confidential information can be exposed externally.
|
| CVE-2026-15293 |
|
Vulnerability in wordpress (CVE-2026-15293)
vulnerability in wordpress (CVE-2026-15293). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13430 |
|
Unrestricted File Upload in wordpress (CVE-2026-13430)
vulnerability in wordpress (CVE-2026-13430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15070 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15070)
vulnerability in wordpress (CVE-2026-15070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15290 |
|
SQL Injection in wordpress (CVE-2026-15290)
SQL injection in wordpress (CVE-2026-15290). Confidential information can be exposed externally.
|
| CVE-2026-15288 |
|
Vulnerability in wordpress (CVE-2026-15288)
vulnerability in wordpress (CVE-2026-15288). Data can be tampered with by attackers.
|
| CVE-2026-12595 |
|
Authentication Bypass in wordpress (CVE-2026-12595)
authentication bypass in wordpress (CVE-2026-12595). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12597 |
|
Authentication Bypass in wordpress (CVE-2026-12597)
authentication bypass in wordpress (CVE-2026-12597). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12598 |
|
Authentication Bypass in wordpress (CVE-2026-12598)
authentication bypass in wordpress (CVE-2026-12598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13492 |
|
Path Traversal in wordpress (CVE-2026-13492)
path traversal in wordpress (CVE-2026-13492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14372 |
|
Path Traversal in wordpress (CVE-2026-14372)
path traversal in wordpress (CVE-2026-14372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9253 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9253)
cross-site scripting in wordpress (CVE-2026-9253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4275 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-4275)
vulnerability in wordpress (CVE-2026-4275). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13441 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13441)
cross-site scripting in wordpress (CVE-2026-13441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15000 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15000)
cross-site scripting in wordpress (CVE-2026-15000). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8848 |
|
Vulnerability in wordpress (CVE-2026-8848)
vulnerability in wordpress (CVE-2026-8848). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11571 |
|
Vulnerability in wordpress (CVE-2026-11571)
vulnerability in wordpress (CVE-2026-11571). Confidential information can be exposed externally.
|
| CVE-2026-5523 |
|
Vulnerability in wordpress (CVE-2026-5523)
vulnerability in wordpress (CVE-2026-5523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6820 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6820)
cross-site scripting in wordpress (CVE-2026-6820). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5356 |
|
Vulnerability in wordpress (CVE-2026-5356)
vulnerability in wordpress (CVE-2026-5356). Data can be tampered with by attackers.
|
| CVE-2026-6854 |
|
SQL Injection in wordpress (CVE-2026-6854)
SQL injection in wordpress (CVE-2026-6854). Confidential information can be exposed externally.
|
| CVE-2026-6818 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6818)
cross-site scripting in wordpress (CVE-2026-6818). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6230 |
|
SQL Injection in wordpress (CVE-2026-6230)
SQL injection in wordpress (CVE-2026-6230). Confidential information can be exposed externally.
|
| CVE-2026-3688 |
|
Vulnerability in wordpress (CVE-2026-3688)
vulnerability in wordpress (CVE-2026-3688). Data can be tampered with by attackers.
|
| CVE-2026-12378 |
|
Vulnerability in wordpress (CVE-2026-12378)
vulnerability in wordpress (CVE-2026-12378). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9700 |
|
SQL Injection in wordpress (CVE-2026-9700)
SQL injection in wordpress (CVE-2026-9700). Confidential information can be exposed externally.
|
| CVE-2026-14495 |
|
Vulnerability in wordpress (CVE-2026-14495)
vulnerability in wordpress (CVE-2026-14495). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-14489 |
|
Unrestricted File Upload in wordpress (CVE-2026-14489)
vulnerability in wordpress (CVE-2026-14489). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9842 |
|
Privilege Escalation in wordpress (CVE-2026-9842)
vulnerability in wordpress (CVE-2026-9842). Data can be tampered with by attackers. Exploitable via ``manage_options``.
|
| CVE-2026-14158 |
|
Unrestricted File Upload in wordpress (CVE-2026-14158)
vulnerability in wordpress (CVE-2026-14158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14244 |
|
Path Traversal in wordpress (CVE-2026-14244)
path traversal in wordpress (CVE-2026-14244). Confidential information can be exposed externally.
|
| CVE-2026-14482 |
|
Privilege Escalation in wordpress (CVE-2026-14482)
vulnerability in wordpress (CVE-2026-14482). Successful exploitation can lead to full system takeover. Exploitable via ``update_option``.
|
| CVE-2026-48957 |
|
An improper access check allows unauthorized users to access com_privacy datasets.
An improper access check allows unauthorized users to access com_privacy datasets.
|
| CVE-2026-48958 |
|
Vulnerability in joomla (CVE-2026-48958)
vulnerability in joomla (CVE-2026-48958). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48948 |
|
Vulnerability in joomla (CVE-2026-48948)
vulnerability in joomla (CVE-2026-48948). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6101 |
|
Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12277 |
|
Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
|
| CVE-2026-11766 |
|
Vulnerability in wordpress (CVE-2026-11766)
vulnerability in wordpress (CVE-2026-11766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11855 |
|
Vulnerability in wordpress (CVE-2026-11855)
vulnerability in wordpress (CVE-2026-11855). Successful exploitation can lead to full system takeover.
|