Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15649 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15649)
cross-site scripting in wordpress (CVE-2026-15649). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15645 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15645)
cross-site scripting in wordpress (CVE-2026-15645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15644 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15644)
cross-site scripting in wordpress (CVE-2026-15644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15601 |
|
Path Traversal in wordpress (CVE-2026-15601)
path traversal in wordpress (CVE-2026-15601). Confidential information can be exposed externally.
|
| CVE-2026-15450 |
|
Path Traversal in wordpress (CVE-2026-15450)
path traversal in wordpress (CVE-2026-15450). Data can be tampered with by attackers.
|
| CVE-2026-15052 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15052)
cross-site scripting in wordpress (CVE-2026-15052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15018 |
|
SQL Injection in wordpress (CVE-2026-15018)
SQL injection in wordpress (CVE-2026-15018). Confidential information can be exposed externally.
|
| CVE-2026-13458 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13458)
cross-site scripting in wordpress (CVE-2026-13458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11995 |
|
Vulnerability in wordpress (CVE-2026-11995)
vulnerability in wordpress (CVE-2026-11995). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10782 |
|
Vulnerability in wordpress (CVE-2026-10782)
vulnerability in wordpress (CVE-2026-10782). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14073 |
|
Vulnerability in wordpress (CVE-2025-14073)
vulnerability in wordpress (CVE-2025-14073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15988 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15988)
vulnerability in wordpress (CVE-2026-15988). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14469 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2025-14469)
vulnerability in wordpress (CVE-2025-14469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2916 |
|
Information Disclosure in wordpress (CVE-2026-2916)
vulnerability in wordpress (CVE-2026-2916). Risk of unauthorized operations or information disclosure. Exploitable via ``JkitDashboardOption``.
|
| CVE-2026-15932 |
|
Path Traversal in wordpress (CVE-2026-15932)
path traversal in wordpress (CVE-2026-15932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15368 |
|
Privilege Escalation in wordpress (CVE-2026-15368)
vulnerability in wordpress (CVE-2026-15368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15262 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15262)
cross-site scripting in wordpress (CVE-2026-15262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15244 |
|
Path Traversal in c (CVE-2026-15244)
path traversal in c (CVE-2026-15244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15234 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15234)
cross-site scripting in wordpress (CVE-2026-15234). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14840 |
|
Vulnerability in wordpress (CVE-2026-14840)
vulnerability in wordpress (CVE-2026-14840). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14839 |
|
Information Disclosure in wordpress (CVE-2026-14839)
vulnerability in wordpress (CVE-2026-14839). Confidential information can be exposed externally.
|
| CVE-2026-14836 |
|
Authentication Bypass in wordpress (CVE-2026-14836)
authentication bypass in wordpress (CVE-2026-14836). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14823 |
|
Vulnerability in wordpress (CVE-2026-14823)
vulnerability in wordpress (CVE-2026-14823). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14822 |
|
Vulnerability in wordpress (CVE-2026-14822)
vulnerability in wordpress (CVE-2026-14822). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14596 |
|
Authentication Bypass in wordpress (CVE-2026-14596)
authentication bypass in wordpress (CVE-2026-14596). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14561 |
|
Authentication Bypass in wordpress (CVE-2026-14561)
authentication bypass in wordpress (CVE-2026-14561). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14315 |
|
Vulnerability in wordpress (CVE-2026-14315)
vulnerability in wordpress (CVE-2026-14315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14309 |
|
Authentication Bypass in wordpress (CVE-2026-14309)
authentication bypass in wordpress (CVE-2026-14309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14292 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14292)
cross-site scripting in wordpress (CVE-2026-14292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14214 |
|
Authentication Bypass in wordpress (CVE-2026-14214)
authentication bypass in wordpress (CVE-2026-14214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14197 |
|
Vulnerability in wordpress (CVE-2026-14197)
vulnerability in wordpress (CVE-2026-14197). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14195 |
|
Vulnerability in wordpress (CVE-2026-14195)
vulnerability in wordpress (CVE-2026-14195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13729 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-13729)
vulnerability in wordpress (CVE-2026-13729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13725 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13725)
cross-site scripting in wordpress (CVE-2026-13725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13604 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13604)
SSRF in wordpress (CVE-2026-13604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13596 |
|
SQL Injection in wordpress (CVE-2026-13596)
SQL injection in wordpress (CVE-2026-13596). Confidential information can be exposed externally.
|
| CVE-2026-13329 |
|
Vulnerability in wordpress (CVE-2026-13329)
vulnerability in wordpress (CVE-2026-13329). Data can be tampered with by attackers.
|
| CVE-2026-13158 |
|
Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13157 |
|
Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12966 |
|
Vulnerability in wordpress (CVE-2026-12966)
vulnerability in wordpress (CVE-2026-12966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12696 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12696)
cross-site scripting in wordpress (CVE-2026-12696). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11882 |
|
Vulnerability in wordpress (CVE-2026-11882)
vulnerability in wordpress (CVE-2026-11882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10827 |
|
Vulnerability in wordpress (CVE-2026-10827)
vulnerability in wordpress (CVE-2026-10827). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15669 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15669)
cross-site scripting in wordpress (CVE-2025-15669). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3141 |
|
Vulnerability in wordpress (CVE-2026-3141)
vulnerability in wordpress (CVE-2026-3141). Data can be tampered with by attackers.
|
| CVE-2026-7623 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7623)
cross-site scripting in wordpress (CVE-2026-7623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-15403 |
|
SQL Injection in wordpress (CVE-2026-15403)
SQL injection in wordpress (CVE-2026-15403). Confidential information can be exposed externally.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-13362 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13362)
cross-site scripting in wordpress (CVE-2026-13362). Risk of unauthorized operations or information disclosure.
|