Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-11977 |
|
SQL Injection in wordpress (CVE-2026-11977)
SQL injection in wordpress (CVE-2026-11977). Confidential information can be exposed externally.
|
| CVE-2026-15281 |
|
SQL Injection in wordpress (CVE-2026-15281)
SQL injection in wordpress (CVE-2026-15281). Confidential information can be exposed externally.
|
| CVE-2026-12000 |
|
Vulnerability in wordpress (CVE-2026-12000)
vulnerability in wordpress (CVE-2026-12000). Confidential information can be exposed externally.
|
| CVE-2026-11920 |
|
SQL Injection in wordpress (CVE-2026-11920)
SQL injection in wordpress (CVE-2026-11920). Confidential information can be exposed externally.
|
| CVE-2026-68075 |
|
Vulnerability in apache (CVE-2026-68075)
vulnerability in apache (CVE-2026-68075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68078 |
|
Vulnerability in apache (CVE-2026-68078)
vulnerability in apache (CVE-2026-68078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71201 |
|
Authorization Flaw in CVE-2026-71201 (CVE-2026-71201)
vulnerability in CVE-2026-71201 (CVE-2026-71201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68080 |
|
Vulnerability in apache (CVE-2026-68080)
vulnerability in apache (CVE-2026-68080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70374 |
|
OS Command Injection in CVE-2026-70374 (CVE-2026-70374)
OS command injection in CVE-2026-70374 (CVE-2026-70374). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/{project}/{environment}/media/new.`.
|
| CVE-2026-70375 |
|
OS Command Injection in CVE-2026-70375 (CVE-2026-70375)
OS command injection in CVE-2026-70375 (CVE-2026-70375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67553 |
|
Vulnerability in apache (CVE-2026-67553)
vulnerability in apache (CVE-2026-67553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67555 |
|
Vulnerability in apache (CVE-2026-67555)
vulnerability in apache (CVE-2026-67555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67591 |
|
Vulnerability in apache (CVE-2026-67591)
vulnerability in apache (CVE-2026-67591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67592 |
|
Vulnerability in apache (CVE-2026-67592)
vulnerability in apache (CVE-2026-67592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66275 |
|
Vulnerability in apache (CVE-2026-66275)
vulnerability in apache (CVE-2026-66275). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66277 |
|
Vulnerability in apache (CVE-2026-66277)
vulnerability in apache (CVE-2026-66277). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49004 |
|
SQL Injection in CVE-2026-49004 (CVE-2026-49004)
SQL injection in CVE-2026-49004 (CVE-2026-49004). Confidential information can be exposed externally.
|
| CVE-2026-16993 |
|
Information Disclosure in wordpress (CVE-2026-16993)
vulnerability in wordpress (CVE-2026-16993). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17515 |
|
Information Disclosure in wordpress (CVE-2026-17515)
vulnerability in wordpress (CVE-2026-17515). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16603 |
|
Information Disclosure in wordpress (CVE-2026-16603)
vulnerability in wordpress (CVE-2026-16603). Confidential information can be exposed externally.
|
| CVE-2026-16604 |
|
Information Disclosure in wordpress (CVE-2026-16604)
vulnerability in wordpress (CVE-2026-16604). Confidential information can be exposed externally.
|
| CVE-2026-16968 |
|
Information Disclosure in wordpress (CVE-2026-16968)
vulnerability in wordpress (CVE-2026-16968). Confidential information can be exposed externally.
|
| CVE-2026-16942 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16942)
cross-site scripting in wordpress (CVE-2026-16942). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16605 |
|
Vulnerability in wordpress (CVE-2026-16605)
vulnerability in wordpress (CVE-2026-16605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16940 |
|
Path Traversal in wordpress (CVE-2026-16940)
path traversal in wordpress (CVE-2026-16940). Data can be tampered with by attackers.
|
| CVE-2026-16736 |
|
Vulnerability in wordpress (CVE-2026-16736)
vulnerability in wordpress (CVE-2026-16736). Confidential information can be exposed externally.
|
| CVE-2026-16613 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16613)
vulnerability in wordpress (CVE-2026-16613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15360 |
|
SQL Injection in wordpress (CVE-2026-15360)
SQL injection in wordpress (CVE-2026-15360). Confidential information can be exposed externally.
|
| CVE-2026-16573 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16573)
cross-site scripting in wordpress (CVE-2026-16573). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16583 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16583)
cross-site scripting in wordpress (CVE-2026-16583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16602 |
|
Information Disclosure in wordpress (CVE-2026-16602)
vulnerability in wordpress (CVE-2026-16602). Confidential information can be exposed externally.
|
| CVE-2026-16561 |
|
Vulnerability in wordpress (CVE-2026-16561)
vulnerability in wordpress (CVE-2026-16561). Confidential information can be exposed externally.
|
| CVE-2026-15372 |
|
Authentication Bypass in wordpress (CVE-2026-15372)
authentication bypass in wordpress (CVE-2026-15372). Confidential information can be exposed externally.
|
| CVE-2026-16036 |
|
Authentication Bypass in wordpress (CVE-2026-16036)
authentication bypass in wordpress (CVE-2026-16036). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16055 |
|
Authentication Bypass in wordpress (CVE-2026-16055)
authentication bypass in wordpress (CVE-2026-16055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15230 |
|
Vulnerability in wordpress (CVE-2026-15230)
vulnerability in wordpress (CVE-2026-15230). Confidential information can be exposed externally.
|
| CVE-2026-15210 |
|
Authentication Bypass in wordpress (CVE-2026-15210)
authentication bypass in wordpress (CVE-2026-15210). Confidential information can be exposed externally.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2025-15677 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15677)
cross-site scripting in wordpress (CVE-2025-15677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8790 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8790)
cross-site scripting in wordpress (CVE-2026-8790). Risk of unauthorized operations or information disclosure. Exploitable via ``shouttext``.
|
| CVE-2026-8761 |
|
Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
|
| CVE-2026-7753 |
|
Vulnerability in wordpress (CVE-2026-7753)
vulnerability in wordpress (CVE-2026-7753). Confidential information can be exposed externally. Exploitable via ``ccb_export_nonce``.
|
| CVE-2026-71192 |
|
Authorization Flaw in CVE-2026-71192 (CVE-2026-71192)
vulnerability in CVE-2026-71192 (CVE-2026-71192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66257 |
|
Vulnerability in apache (CVE-2026-66257)
vulnerability in apache (CVE-2026-66257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67465 |
|
Vulnerability in apache (CVE-2026-67465)
vulnerability in apache (CVE-2026-67465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68060 |
|
Vulnerability in apache (CVE-2026-68060)
vulnerability in apache (CVE-2026-68060). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67588 |
|
Vulnerability in apache (CVE-2026-67588)
vulnerability in apache (CVE-2026-67588). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68074 |
|
Vulnerability in apache (CVE-2026-68074)
vulnerability in apache (CVE-2026-68074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71191 |
|
Authorization Flaw in CVE-2026-71191 (CVE-2026-71191)
vulnerability in CVE-2026-71191 (CVE-2026-71191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66344 |
|
Vulnerability in CVE-2026-66344 (CVE-2026-66344)
vulnerability in CVE-2026-66344 (CVE-2026-66344). Successful exploitation can lead to full system takeover.
|