Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2026-64665 Authentication Bypass in statamic/cms (CVE-2026-64665)
authentication bypass in statamic/cms (CVE-2026-64665). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.74.1` or later.
CVE-2026-53977 Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
CVE-2026-3430 SQL Injection in wordpress (CVE-2026-3430)
SQL injection in wordpress (CVE-2026-3430). Confidential information can be exposed externally.
CVE-2026-66705 Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2026-34502 Vulnerability in apache (CVE-2026-34502)
vulnerability in apache (CVE-2026-34502). Risk of unauthorized operations or information disclosure.
CVE-2026-34501 Vulnerability in apache (CVE-2026-34501)
vulnerability in apache (CVE-2026-34501). Risk of unauthorized operations or information disclosure.
CVE-2025-49506 Vulnerability in apache (CVE-2025-49506)
vulnerability in apache (CVE-2025-49506). Confidential information can be exposed externally.
CVE-2026-68481 Vulnerability in apache (CVE-2026-68481)
vulnerability in apache (CVE-2026-68481). Confidential information can be exposed externally.
CVE-2026-57818 Vulnerability in apache (CVE-2026-57818)
vulnerability in apache (CVE-2026-57818). Successful exploitation can lead to full system takeover.
CVE-2025-15028 Cross-Site Scripting (XSS) in wordpress (CVE-2025-15028)
cross-site scripting in wordpress (CVE-2025-15028). Risk of unauthorized operations or information disclosure.
CVE-2026-65432 XXE (XML External Entity) in apache (CVE-2026-65432)
vulnerability in apache (CVE-2026-65432). Confidential information can be exposed externally.
CVE-2026-64958 Vulnerability in apache (CVE-2026-64958)
vulnerability in apache (CVE-2026-64958). Risk of unauthorized operations or information disclosure.
CVE-2026-57819 Vulnerability in apache (CVE-2026-57819)
vulnerability in apache (CVE-2026-57819). Risk of unauthorized operations or information disclosure.
CVE-2026-57817 Vulnerability in apache (CVE-2026-57817)
vulnerability in apache (CVE-2026-57817). Successful exploitation can lead to full system takeover. Exploitable via ``c_hash``.
CVE-2026-54225 Vulnerability in apache (CVE-2026-54225)
vulnerability in apache (CVE-2026-54225). Risk of unauthorized operations or information disclosure.
CVE-2026-18510 Cross-Site Scripting (XSS) in wordpress (CVE-2026-18510)
cross-site scripting in wordpress (CVE-2026-18510). Risk of unauthorized operations or information disclosure.
CVE-2026-16268 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16268)
SSRF in wordpress (CVE-2026-16268). Data can be tampered with by attackers.
CVE-2026-16734 Vulnerability in wordpress (CVE-2026-16734)
vulnerability in wordpress (CVE-2026-16734). Data can be tampered with by attackers.
CVE-2026-18050 Information Disclosure in wordpress (CVE-2026-18050)
vulnerability in wordpress (CVE-2026-18050). Confidential information can be exposed externally.
CVE-2026-13154 Information Disclosure in wordpress (CVE-2026-13154)
vulnerability in wordpress (CVE-2026-13154). Confidential information can be exposed externally.
CVE-2026-14829 Vulnerability in wordpress (CVE-2026-14829)
vulnerability in wordpress (CVE-2026-14829). Data can be tampered with by attackers.
CVE-2026-13153 Information Disclosure in wordpress (CVE-2026-13153)
vulnerability in wordpress (CVE-2026-13153). Confidential information can be exposed externally.
CVE-2026-15459 Authentication Bypass in wordpress (CVE-2026-15459)
authentication bypass in wordpress (CVE-2026-15459). Successful exploitation can lead to full system takeover.
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
CVE-2026-71321 Vulnerability in nuxt (CVE-2026-71321)
vulnerability in nuxt (CVE-2026-71321). Risk of unauthorized operations or information disclosure. Exploitable via `POST /__nuxt_island/`. Mitigation: upgrade to `3.21.10` or later.
CVE-2026-71320 Vulnerability in nuxt (CVE-2026-71320)
vulnerability in nuxt (CVE-2026-71320). Successful exploitation can lead to full system takeover. Exploitable via ``resolveDynamicComponent``. Mitigation: upgrade to `3.21.10` or later.
CVE-2026-71316 Vulnerability in nuxt (CVE-2026-71316)
vulnerability in nuxt (CVE-2026-71316). Confidential information can be exposed externally. Exploitable via ``routeRules``. Mitigation: upgrade to `4.5.1` or later.
CVE-2026-71315 Vulnerability in nuxt (CVE-2026-71315)
vulnerability in nuxt (CVE-2026-71315). Confidential information can be exposed externally. Exploitable via ``appMiddleware``. Mitigation: upgrade to `3.21.10` or later.
CVE-2026-71314 Vulnerability in nuxt (CVE-2026-71314)
vulnerability in nuxt (CVE-2026-71314). Risk of unauthorized operations or information disclosure. Exploitable via ``ssrRenderList``. Mitigation: upgrade to `3.21.10` or later.
CVE-2026-60023 Information Disclosure in apache (CVE-2026-60023)
vulnerability in apache (CVE-2026-60023). Confidential information can be exposed externally.
CVE-2026-48911 Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
CVE-2026-48834 Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
CVE-2026-7529 Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
CVE-2026-17506 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-71239 Vulnerability in django (CVE-2026-71239)
vulnerability in django (CVE-2026-71239). Confidential information can be exposed externally.
CVE-2026-71241 Vulnerability in flask (CVE-2026-71241)
vulnerability in flask (CVE-2026-71241). Confidential information can be exposed externally.
CVE-2026-71233 Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
CVE-2026-7693 Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6020 Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
CVE-2026-6079 Vulnerability in wordpress (CVE-2026-6079)
vulnerability in wordpress (CVE-2026-6079). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →